Fuzzing技术是一项有效的动态漏洞挖掘技术,但是当前对多维Fuzzing技术的研究还不多见。把多维Fuzzing技术面临的问题归纳为组合爆炸、覆盖脆弱语句和触发潜在漏洞三个问题,对存在的多种多维Fuzzing技术进行了研究和比较,并总结出多维Fuzzing技术的三个基本步骤:定位脆弱语句、查找影响脆弱语句的输入元素和多维Fuzzing测试挖掘脆弱语句中的漏洞。最后,给出了多维Fuzzing技术的进一步发展方向。
Fuzzing is an effective dynamic vulnerability mining technology,however,there is not too much research on multidimensional Fuzzing. This paper concluded that the problems of multi-dimensional Fuzzing included combinational explosion, covering vulnerable statements and triggering suspend vulnerabilities. Gave a research and a comparison on existing multi-dimensional Fuzzing technologies and got that they could be divided into three basic steps: locating vulnerable statements,finding input elements which influenced corresponding vulnerable statements and finding the vulnerabilities with multi-dimensional Fuzzing technology. At last,gave its further improvement directions.