Vulnerability-Oriented Fuzz Testing for Connected Autonomous Vehicle Systems

模糊测试 计算机科学 软件安全保证 安全性测试 攻击面 白盒测试 代码覆盖率 测试用例 计算机安全 漏洞管理 稳健性测试 软件 测试策略 软件可靠性测试 嵌入式系统 可靠性工程 软件质量 脆弱性评估 软件系统 工程类 软件建设 软件开发 保安服务 信息安全 操作系统 云安全计算 机器学习 安全信息和事件管理 云计算 心理弹性 心理治疗师 心理学 回归分析
作者
Lama J. Moukahal,Mohammad Zulkernine,Martin Soukup
出处
期刊:IEEE Transactions on Reliability [Institute of Electrical and Electronics Engineers]
卷期号:70 (4): 1422-1437 被引量:15
标识
DOI:10.1109/tr.2021.3112538
摘要

In an era of connectivity and automation, the vehicle industry is adopting numerous technologies to transform driver-centric vehicles into intelligent mechanical devices driven by software components. Software integration and network connectivity inherit numerous security issues that open the door for malicious attacks. Software security testing is a scalable and practical approach to identify systems’ weaknesses and vulnerabilities at an early stage and throughout their life-cycle. Security specialists recommend fuzz testing to identify vulnerabilities within vehicle software systems. Nevertheless, the randomness and blindness of fuzzing hinder it from becoming a reliable security tool. This article presents a vulnerability-oriented fuzz (VulFuzz) testing framework that utilizes security vulnerability metrics designed particularly for connected and autonomous vehicles to direct and prioritize the fuzz testing toward the most vulnerable components. While most gray-box fuzzing techniques aim solely to expand code coverage, the proposed approach assigns weights to ensure a thorough examination of the most vulnerable components. Moreover, we employ an input structure-aware mutation technique that can bypass vehicle software systems’ input formats to boost test performance and avoid dropped test cases. Such a testing technique will contribute to the quality assurance of vehicle software engineering. We implemented the proposed approach on OpenPilot, a driver assistance system, and compared our results to American fuzzy lop (AFL) and an unguided mutation-based fuzzer. Within 16.8 h, VulFuzz exposed 335 crashes, 41 times more than AFL and two times more than an unguided mutation-based fuzzer. VulFuzz is explicitly efficient for automotive systems, reaching the same code coverage as AFL but with more exposed crashes and fewer dropped messages.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
长衫造纸农完成签到,获得积分10
3秒前
CRT完成签到,获得积分20
5秒前
7秒前
7秒前
与尔完成签到 ,获得积分10
8秒前
佛四魁儿完成签到,获得积分20
8秒前
GAW完成签到,获得积分10
9秒前
10秒前
CRT发布了新的文献求助10
12秒前
12秒前
16秒前
充电宝应助阔达月饼采纳,获得10
17秒前
axiao发布了新的文献求助10
17秒前
18秒前
18秒前
宋江他大表哥完成签到,获得积分10
19秒前
lllyq完成签到 ,获得积分10
20秒前
Allen发布了新的文献求助10
21秒前
宁万三发布了新的文献求助10
22秒前
ccm发布了新的文献求助10
22秒前
24秒前
Di关闭了Di文献求助
25秒前
25秒前
852应助GG小丁同学采纳,获得10
26秒前
jiowtyp169完成签到,获得积分20
27秒前
28秒前
28秒前
29秒前
赘婿应助axiao采纳,获得10
31秒前
31秒前
mls驳回了情怀应助
31秒前
31秒前
GG小丁同学完成签到,获得积分10
31秒前
叫我益达完成签到,获得积分10
32秒前
34秒前
34秒前
阿瓜发布了新的文献求助10
36秒前
樱桃小王子完成签到,获得积分10
36秒前
大芳儿发布了新的文献求助10
37秒前
38秒前
高分求助中
Evolution 10000
ISSN 2159-8274 EISSN 2159-8290 1000
Becoming: An Introduction to Jung's Concept of Individuation 600
Ore genesis in the Zambian Copperbelt with particular reference to the northern sector of the Chambishi basin 500
A new species of Coccus (Homoptera: Coccoidea) from Malawi 500
A new species of Velataspis (Hemiptera Coccoidea Diaspididae) from tea in Assam 500
PraxisRatgeber: Mantiden: Faszinierende Lauerjäger 500
热门求助领域 (近24小时)
化学 医学 生物 材料科学 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 基因 遗传学 催化作用 物理化学 免疫学 量子力学 细胞生物学
热门帖子
关注 科研通微信公众号,转发送积分 3161703
求助须知:如何正确求助?哪些是违规求助? 2813001
关于积分的说明 7898208
捐赠科研通 2471974
什么是DOI,文献DOI怎么找? 1316269
科研通“疑难数据库(出版商)”最低求助积分说明 631278
版权声明 602129