Regular price
23.500 KD
inc. VAT
Couldn't load pickup availability
Table of contents
- Cover
- Contentsvii
- Chapter 1: Introduction to Vulnerability Research1
- Statement of Scope2
- Off-by-One Errors3
- Programming Language Use Errors5
- Integer Overflows5
- Bugs and Vulnerabilities7
- The Vaunted Buffer Overflow7
- Finding Bugs and Vulnerabilities7
- Source Code Review9
- Black Box Testing10
- Glass Box Testing10
- Chapter 2: Fuzzing-What's That?11
- Introduction12
- Introduction to Fuzzing12
- Milestones in Fuzzing14
- Fuzzing Technology16
- Traffic Sniffing18
- Prepared Template19
- Second-Generation Fuzzing19
- File Fuzzing22
- Host-side Monitoring22
- Vulnerability Scanners as Fuzzers22
- Uses of Fuzzing23
- Open Source Fuzzers24
- Commercial-Grade Fuzzers24
- What Comes Next25
- The Software Development Life Cycle25
- Chapter 3: Building a Fuzzing Environment27
- Introduction28
- Knowing What to Ask...28
- Basic Tools and Setup34
- Data Points34
- Crash Dumps34
- Fuzzer Output36
- Debuggers37
- Recon Tools40
- Linux41
- OSX42
- Summary44
- Chapter 4: Open Source Fuzzing Tools45
- Introduction46
- Frameworks46
- Special-Purpose Tools48
- General-Purpose Tools52
- Chapter 5: Commercial Fuzzing Solutions55
- Introduction56
- beSTORM (by Beyond Security)56
- BPS-1000 (by BreakingPoint Systems)58
- Codenomicon59
- Mu-4000 Security Analyzer (by Mu Security)63
- Chapter 6: Build Your Own Fuzzer67
- Hold Your Horses68
- Fuzzer Building Blocks70
- One or More Valid Data Sets70
- Understanding What Each Bytein the Data Set Means71
- Change the Values of the Data Sets While Maintaining the Integrity ofthe Data Being Sent72
- Recreate the Same Malformed DataSet Time and Time Again72
- An Arsenal of Malformed Values, or the Abilityto Create a Variety of Malformed Outputs73
- Maintain a Form of a State Machine74
- Summarize75
- Down to Business75
- Simplest Fuzz Testing Find Issues88
- Chapter 7: Integration of Fuzzing in the Development Cycle91
- Introduction92
- Why Is Fuzzing Important to Include in a Software Development Cycle?93
- Security Testing Workload93
- Setting Expectations for Fuzzers in a Software Development Lifecycle101
- Fuzzing as a Panacea101
- Fuzzing Tools versus ...103
- Setting the Plan for Implementing Fuzzers into a Software Development Lifecycle103
- Setting Goals104
- Building and Executing on the Plan111
- Understanding How to Increase Effectiveness of Fuzzers, and Avoiding Any Big Gotchas115
- Hidden Costs116
- Finding More Vulnerabilities119
- Summary126
- Solutions Fast Track126
- Frequently Asked Questions130
- Chapter 8: Standardization and Certification133
- Fuzzing and the Corporate Environment134
- Software Security Testing, the Challenges134
- Testing for Security135
- Fuzzing as a Viable Option137
- Business Pressure138
- Software Security Certification139
- Meeting Standards and Compliance139
- Tester Certification140
- Industry Pressure140
- Antivirus Product Testing and Certification140
- Chapter 9: What Is a File?143
- Introduction144
- Are File Fuzzers Special?145
- Analyzing and Building Files149
- Textual Files150
- Binary Files151
- Running the Test156
- Monitoring the Application with the Test Cases161
- Chapter 10: Code Coverage and Fuzzing163
- Introduction164
- Code Coverage164
- Obtaining Code Coverage167
- Instrumenting the Binary167
- Monitoring a Closed Source Application169
- Improving Fuzzing with Code Coverage171
- Manual Improvements174
- Dynamically Generating Code Coverage Improvements181
- Statically Generating Code Coverage185
- Weaknesses of Code Coverage188
- Summary190
- Solutions Fast Track190
- Frequently Asked Questions192
- Index193
Book details
- Vendor Elsevier S & T
- SKU 9781597491952
- ISBN-13 9780080555614
- Author Rathaus, Noam; Evron, Gadi
- Category Computers
- Subject Computer Science
Do you have questions about this book?
Fuzzing is often described as a “black box software testing technique. It works by automatically feeding a program multiple input iterations in an attempt to trigger an internal error indicative of a bug, and potentially crash it. Such program errors and crashes are indicative of the existence of a security vulnerability, which can later be researched and fixed.
Fuzz testing is now making a transition from a hacker-grown tool to a commercial-grade product. There are many different types of applications that can be fuzzed, many different ways they can be fuzzed, and a variety of different problems that can be uncovered. There are also problems that arise during fuzzing; when is enough enough? These issues and many others are fully explored.
* Fuzzing is a fast-growing field with increasing commercial interest (7 vendors unveiled fuzzing products last year).
* Vendors today are looking for solutions to the ever increasing threat of vulnerabilities. Fuzzing looks for these vulnerabilities automatically, before they are known, and eliminates them before release.
* Software developers face an increasing demand to produce secure applications---and they are looking for any information to help them do that.
Fuzz testing is now making a transition from a hacker-grown tool to a commercial-grade product. There are many different types of applications that can be fuzzed, many different ways they can be fuzzed, and a variety of different problems that can be uncovered. There are also problems that arise during fuzzing; when is enough enough? These issues and many others are fully explored.
* Fuzzing is a fast-growing field with increasing commercial interest (7 vendors unveiled fuzzing products last year).
* Vendors today are looking for solutions to the ever increasing threat of vulnerabilities. Fuzzing looks for these vulnerabilities automatically, before they are known, and eliminates them before release.
* Software developers face an increasing demand to produce secure applications---and they are looking for any information to help them do that.
Instant delivery by email
Your access email arrives within minutes of checkout, with a sign-in link for each book — no shipping, no waiting.
Read on any device
Books open in VitalSource Bookshelf on your phone, tablet, or computer, online or offline. Your library is always available at aafaq.vitalsource.com — just log in with the email you used at checkout.
Lost the email?
Resend it to yourself in seconds from My eBook orders, or email cs@aafaqeducation.com and we'll help.