Welcome to Journal of University of Chinese Academy of Sciences,Today is

›› 2013, Vol. 30 ›› Issue (2): 278-284.DOI: 10.7523/j.issn.1002-1175.2013.02.021

Previous Articles     Next Articles

Automatic network protocol analysis and vulnerability discovery based on symbolic expression

LUO Cheng, ZHANG Yu-Qing, WANG Long, LIU Qi-Xu   

  1. National Computer Network Intrusion Protection Center, Graduate University, Chinese Academy of Sciences, Beijing 100049, China
  • Received:2011-12-01 Revised:2012-04-13 Online:2013-03-15

Abstract:

Fuzzing is an efficient method for ensuring software security. However, when one tests network-based software using this method, one may obtain unsatisfied results because of lacking the protocol format. To solve this problem, we propose a new protocol analysis technique based on symbolic expression. We use this technique to translate the crucial code into symbolic expressions and accelerate protocol analysis. In addition, we develop a translation framework which contains the function of automatic protocol format analysis and could export the protocol format to Peach platform. Finally, we apply our framework to analyze one target (eyou client) and obtain good results.

Key words: unknown protocol, Fuzzing, symbolic expression, vulnerability discovery

CLC Number: