Umeå University's logo

umu.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Investigating the Effectiveness of Forward-Porting Bugs
Umeå University, Faculty of Science and Technology, Department of Computing Science. (Programvaruteknik och säkerhet)
2023 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

This research investigates the effectiveness of the forward-porting approach employed in the Magma framework as a fault injection technique for evaluating fuzzers. The study aims to assess the use of Proof-of-Concepts in reproducing crashes in CVEs and evaluate the feasibility of forward-porting vulnerabilities into later software versions. An experiment was conducted using three selected open-source libraries to explore whether vulnerabilities could be triggered or reached in the latest versions through the forward-porting approach. The findings suggest that the forward-porting approach may not be the most effective method for injecting vulnerabilities into software systems. Out of the 22 chosen CVEs for analysis, only one could be triggered and two could be reached using the forward-porting approach. This indicates that many of the injected vulnerabilities become obsolete or have unsatisfiable trigger conditions in later versions. Additionally, manual verification of these vulnerabilities have been found to be time-consuming and challenging. Further research is necessary to provide a comprehensive evaluation of the effectiveness of the forward-porting approach in vulnerability injection.

Place, publisher, year, edition, pages
2023. , p. 17
Series
UMNAD ; 1386
Keywords [en]
Fuzzing, Fuzz testing, Forward-porting, Fault injection, Magma, Umeå University
National Category
Software Engineering
Identifiers
URN: urn:nbn:se:umu:diva-209652OAI: oai:DiVA.org:umu-209652DiVA, id: diva2:1766289
Educational program
Bachelor of Science Programme in Computing Science
Supervisors
Examiners
Available from: 2023-06-13 Created: 2023-06-12 Last updated: 2023-06-13Bibliographically approved

Open Access in DiVA

Investigating the Effectiveness of Forward-Porting Bugs(281 kB)135 downloads
File information
File name FULLTEXT01.pdfFile size 281 kBChecksum SHA-512
d12151b25d8684af2426775fa4c736ca96feece156e95d1e4bfe369b6eebbce568cef6675add723c1d4543d4f4990ef6cecfb953a0b1258147816222638e447c
Type fulltextMimetype application/pdf

By organisation
Department of Computing Science
Software Engineering

Search outside of DiVA

GoogleGoogle Scholar
Total: 135 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 261 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf