Security vulnerability is one of the root causes of cyber-security threats.To discover vulnerabilities and fix them in advance,researchers have proposed several techniques,among which fuzzing is the most widely used o...Security vulnerability is one of the root causes of cyber-security threats.To discover vulnerabilities and fix them in advance,researchers have proposed several techniques,among which fuzzing is the most widely used one.In recent years,fuzzing solutions,like AFL,have made great improvements in vulnerability discovery.This paper presents a summary of the recent advances,analyzes how they improve the fuzzing process,and sheds light on future work in fuzzing.Firstly,we discuss the reason why fuzzing is popular,by comparing different commonly used vulnerability discovery techniques.Then we present an overview of fuzzing solutions,and discuss in detail one of the most popular type of fuzzing,i.e.,coverage-based fuzzing.Then we present other techniques that could make fuzzing process smarter and more efficient.Finally,we show some applications of fuzzing,and discuss new trends of fuzzing and potential future directions.展开更多
根据安全网络的要求,利用先进的网络安全技术与设备,针对大连市气象局局域网在网络结构、网络安全方面存在的问题及隐患,提出网络系统改造方案及加强网络安全的措施:网络改造方案中采用子网划分技术重新规划网络结构,实现子网划分;针对...根据安全网络的要求,利用先进的网络安全技术与设备,针对大连市气象局局域网在网络结构、网络安全方面存在的问题及隐患,提出网络系统改造方案及加强网络安全的措施:网络改造方案中采用子网划分技术重新规划网络结构,实现子网划分;针对可能存在的内、外部网络攻击,部署了多层次防线,对边界防毒和应用服务器防毒及客户端防毒均作了相应的部署。采用虚拟专用网络(virtual private network,VPN)技术、虚拟局域网(virtual local area network,VLAN)技术、网络版病毒防护软件、网关防毒产品、防火墙技术和物理隔离等多种专业网络安全产品,构建整体安全网络系统。实施后表明:网络安全得到保障,网络通信质量显著提高,达到了建设安全、畅通、高速局域网络的目的。展开更多
基金supported in part by the National Natural Science Foundation of China(Grant No.6177230861472209,and U1736209)Young Elite Scientists Spon-sorship Program by CAST(Grant No.2016QNRC001)award from Tsinghua Information Science And Technology National Laboratory.
文摘Security vulnerability is one of the root causes of cyber-security threats.To discover vulnerabilities and fix them in advance,researchers have proposed several techniques,among which fuzzing is the most widely used one.In recent years,fuzzing solutions,like AFL,have made great improvements in vulnerability discovery.This paper presents a summary of the recent advances,analyzes how they improve the fuzzing process,and sheds light on future work in fuzzing.Firstly,we discuss the reason why fuzzing is popular,by comparing different commonly used vulnerability discovery techniques.Then we present an overview of fuzzing solutions,and discuss in detail one of the most popular type of fuzzing,i.e.,coverage-based fuzzing.Then we present other techniques that could make fuzzing process smarter and more efficient.Finally,we show some applications of fuzzing,and discuss new trends of fuzzing and potential future directions.
文摘根据安全网络的要求,利用先进的网络安全技术与设备,针对大连市气象局局域网在网络结构、网络安全方面存在的问题及隐患,提出网络系统改造方案及加强网络安全的措施:网络改造方案中采用子网划分技术重新规划网络结构,实现子网划分;针对可能存在的内、外部网络攻击,部署了多层次防线,对边界防毒和应用服务器防毒及客户端防毒均作了相应的部署。采用虚拟专用网络(virtual private network,VPN)技术、虚拟局域网(virtual local area network,VLAN)技术、网络版病毒防护软件、网关防毒产品、防火墙技术和物理隔离等多种专业网络安全产品,构建整体安全网络系统。实施后表明:网络安全得到保障,网络通信质量显著提高,达到了建设安全、畅通、高速局域网络的目的。