Skip to main navigation Skip to search Skip to main content

Survey of software vulnerability detection techniques

  • Zhou Jun Li*
  • , Jun Xian Zhang
  • , Xiang Ke Liao
  • , Jin Xin Ma
  • *Corresponding author for this work
  • Beihang University
  • National University of Defense Technology

Research output: Contribution to journalArticlepeer-review

Abstract

Software vulnerability detection is one of the most important methods to improve software quality and is the key to insuring software security, which leads grant concerns from researcher and industry. Its main content includes software testing, program analysis, model checking and symbolic execution etc. In recent decade years, how to utilize various classic methods synthetically to detect software vulnerability holes is becoming a new hot research direction. This paper reviews the basic concepts, key challenges and some classic solutions of software vulnerability detection, and beyond this, it tries to introduce some new promising improvement in this research area, including lightweight dynamic symbolic execution, automatic white-box fuzz testing, their implementation technologies and corresponding tools. At last, it provides a survey of some key challenges and new research trends in future research work.

Original languageEnglish
Pages (from-to)717-732
Number of pages16
JournalJisuanji Xuebao/Chinese Journal of Computers
Volume38
Issue number4
DOIs
StatePublished - 1 Apr 2015

Keywords

  • Dynamic analysis
  • Software vulnerability
  • Static analysis
  • Symbolic execution
  • White box testing

Fingerprint

Dive into the research topics of 'Survey of software vulnerability detection techniques'. Together they form a unique fingerprint.

Cite this