Razani, Muhammad Fawwaz (2026) Pencarian Kerentanan pada Aplikasi VLC dan Mpc-hc Berbasis Snapshot-based dan Coverage-guided Fuzzing dengan What The Fuzz. Other thesis, Institut Teknologi Sepuluh Nopember.
|
Text
5026221079-Undergraduate_Thesis.pdf - Accepted Version Restricted to Repository staff only Download (7MB) | Request a copy |
Abstract
Perangkat lunak modern memiliki kompleksitas yang semakin tinggi sehingga berpotensi menyimpan kerentanan keamanan yang sulit ditemukan melalui pengujian manual. Salah satu pendekatan yang banyak digunakan untuk menemukan kerentanan tersebut adalah fuzzing, yaitu teknik pengujian otomatis dengan memberikan berbagai variasi masukan kepada program target untuk mengamati kemungkinan terjadinya perilaku tidak normal. Penelitian ini membahas penerapan snapshot-based fuzzing dan coverage-guided fuzzing menggunakan What The Fuzz pada aplikasi pemutar media di lingkungan Windows. Pendekatan snapshot digunakan untuk mempercepat proses pengujian dengan menyimpan kondisi awal program, sedangkan pendekatan coverage-guided digunakan untuk membantu eksplorasi jalur eksekusi program secara lebih terarah. Penelitian dilakukan melalui perancangan lingkungan pengujian, penyusunan harness, pengambilan snapshot, pelaksanaan fuzzing campaign, serta analisis terhadap hasil pengujian. Berdasarkan hasil penelitian, skema fuzzing berhasil diterapkan pada aplikasi target, namun tidak ditemukan kerentanan yang dapat direproduksi hingga aplikasi akhir. Hasil tersebut menunjukkan bahwa snapshot-based fuzzing dapat digunakan sebagai pendekatan pengujian keamanan, tetapi efektivitasnya sangat dipengaruhi oleh karakteristik target, kestabilan snapshot, kualitas harness, dan kompleksitas dependensi aplikasi. Pada target yang besar, modular, dan memiliki banyak komponen pihak ketiga, pendekatan ini dapat menghasilkan tantangan tambahan dalam menjaga kestabilan eksekusi. Oleh karena itu, penelitian ini memberikan evaluasi terhadap penerapan What The Fuzz pada aplikasi pemutar media serta menjadi dasar pertimbangan dalam memilih pendekatan fuzzing yang sesuai dengan karakteristik perangkat lunak yang diuji.
===============================================================================================================================
Modern software has become increasingly complex, which may introduce security vulnerabilities that are difficult to identify through manual testing. One commonly used approach for discovering such vulnerabilities is fuzzing, an automated testing technique that provides various inputs to a target program in order to observe potential abnormal behavior. This research discusses the application of snapshot-based fuzzing and coverage-guided fuzzing using What The Fuzz on media player applications in a Windows environment. The snapshot approach is used to improve testing efficiency by preserving an initial program state, while the coverage-guided approach helps direct the exploration of program execution paths. The research includes the design of the testing environment, harness development, snapshot creation, fuzzing campaign execution, and analysis of the testing results. Based on the results, the fuzzing scheme was successfully applied to the target applications, but no vulnerability could be reproduced in the final applications. These results show that snapshot-based fuzzing can be used as a security testing approach, but its effectiveness is strongly influenced by target characteristics, snapshot stability, harness quality, and application dependency complexity. For large and modular targets with many third-party components, this approach may introduce additional challenges in maintaining stable execution. Therefore, this research provides an evaluation of applying What The Fuzz to media player applications and serves as a reference for selecting a fuzzing approach that aligns with the characteristics of the software being tested.
| Item Type: | Thesis (Other) |
|---|---|
| Uncontrolled Keywords: | fuzzing, snapshot-based fuzzing, coverage-guided fuzzing, What The Fuzz, keamanan perangkat lunak. fuzzing, snapshot-based fuzzing, coverage-guided fuzzing, What The Fuzz, software security. |
| Subjects: | Q Science > QA Mathematics > QA76.9.A25 Computer security. Digital forensic. Data encryption (Computer science) |
| Divisions: | Faculty of Intelligent Electrical and Informatics Technology (ELECTICS) > Information System > 57201-(S1) Undergraduate Thesis |
| Depositing User: | Muhammad Fawwaz Razani |
| Date Deposited: | 28 Jul 2026 03:48 |
| Last Modified: | 28 Jul 2026 03:50 |
| URI: | http://repository.its.ac.id/id/eprint/138406 |
Actions (login required)
![]() |
View Item |
