首页 | 本学科首页   官方微博 | 高级检索  
     

RFCcertDT:SSL/TLS中证书验证的测试工具
引用本文:陈矗.RFCcertDT:SSL/TLS中证书验证的测试工具[J].西安电子科技大学学报,2019,46(3):20-25.
作者姓名:陈矗
作者单位:西安电子科技大学 计算机科学与技术学院,陕西 西安 710071
基金项目:国家自然科学基金(61732013)
摘    要:为解决现有工具对安全套接层或传输层安全协议实现中证书验证模块的检测效率低等问题,研发了对证书验证模块进行差异测试的新工具RFCcertDT。首先,RFCcertDT基于因特网工程任务组制定的请求评议进行证书规则的自动提取、更新、分类和表示,基于动态符号执行技术生成证书作为测试用例;然后,使用生成的证书和令牌环式测试实现对单个或多个证书验证模块的差异测试并生成软件错误报告。实验结果表明,RFCcertDT的检测效率优于现有工具。RFCcertDT对证书验证模块实现了高效的检测,有助于加强安全套接层或传输层安全协议的软件安全。

关 键 词:安全套接层协议  传输层安全协议  请求评议  证书验证  差异测试  动态符号执行  
收稿时间:2019-03-01

RFCcertDT: a testing tool for certificate validation in SSL/TLS
CHEN Chu.RFCcertDT: a testing tool for certificate validation in SSL/TLS[J].Journal of Xidian University,2019,46(3):20-25.
Authors:CHEN Chu
Affiliation:School of Computer Science and Technology, Xidian Univ., Xi’an 710071, China
Abstract:To solve the problems such as low efficiency of existing tools which are used to check certificate validation modules in the implementation of Secure Sockets Layer or Transport Layer Security protocol, a novel tool named RFCcertDT for differential testing of certificate validation modules is designed and developed. First, rules of certificates are automatically extracted, updated, classified and expressed based on the Request for Comments specified by the Internet Engineering Task Force, and certificates which act as test cases are generated based on the dynamic symbolic execution technique. Second, the generated certificates and the token-ring testing are used to conduct differential testing of a single or multiple certificate validation modules and generate bug reports. Experimental results show that the RFCcertDT is more efficient than existing tools. In summary, the RFCcertDT tests certificate validation modules with high efficiency and is helpful to reinforcing the software security of the Secure Sockets Layer or Transport Layer Security protocol.
Keywords:secure sockets layer  transport layer security  request for comments  certificate validation  differential testing  dynamic symbolic execution  
点击此处可从《西安电子科技大学学报》浏览原始摘要信息
点击此处可从《西安电子科技大学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号