跳到主要导航 跳到搜索 跳到主要内容

FinFuzzer: One Step Further in Fuzzing Fintech Systems

  • Qingshun Wang
  • , Lihua Xu
  • , Jun Xiao
  • , Qi Guo
  • , Haotian Zhang
  • , Liang Dou
  • , Liang He
  • , Tao Xie

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Comprehensive testing is of high importance to ensure the reliability of software systems, especially for systems with high stakes such as FinTech systems. In this paper, we share our observations of the Ant Group's status quo in testing their financial services, specifically on the importance of properly transforming relevant external environment settings and prioritizing input object fields for mutation during automated fuzzing. Based on these observations, we propose FinFuzzer, an automated fuzz testing framework that detects and transforms relevant environmental settings into system inputs, prioritizes input object fields, and mutates system inputs on both environment settings and high-priority object fields. Our evaluation of FinFuzzer against four FinTech systems developed by the Ant Group shows that FinFuzzer can outperform a state-of-the-art approach in terms of line coverage in much shorter time.

源语言英语
主期刊名Proceedings - 2021 36th IEEE/ACM International Conference on Automated Software Engineering, ASE 2021
出版商Institute of Electrical and Electronics Engineers Inc.
1111-1115
页数5
ISBN(电子版)9781665403375
DOI
出版状态已出版 - 2021
活动36th IEEE/ACM International Conference on Automated Software Engineering, ASE 2021 - Virtual, Online, 澳大利亚
期限: 15 11月 202119 11月 2021

出版系列

姓名Proceedings - 2021 36th IEEE/ACM International Conference on Automated Software Engineering, ASE 2021

会议

会议36th IEEE/ACM International Conference on Automated Software Engineering, ASE 2021
国家/地区澳大利亚
Virtual, Online
时期15/11/2119/11/21

指纹

探究 'FinFuzzer: One Step Further in Fuzzing Fintech Systems' 的科研主题。它们共同构成独一无二的指纹。

引用此