USENIX Security2025Top-tier venue
Robust, Efficient, and Widely Available Greybox Fuzzing for COTS Binaries with System Call Pattern Feedback
Jifan Xiao, Peng Jiang, Zixi Zhao, Ruizhe Huang, Junlin Liu, Ding Li
Abstract
Currently, greybox fuzzing is a crucial technique for identifying software bugs. However, applying greybox fuzzing to Commercial-Off-the-Shelf ( COTS ) binaries is still a difficult task because gathering code coverage data is challenging. Existing methods for collecting code coverage in COTS binaries often lead to program crashes, notable performance reductions, and limited compatibility with various hardware platforms. As a result, none of the current approaches can effectively handle all COTS binaries. This paper introduces a new feedback mechanism called system call pattern coverage, which is designed to support binaries that cannot be handled by existing approaches. Unlike other methods, system call pattern coverage does not involve rewriting binaries, using emulators, or relying on hardware such as Intel-PT. As a result, it enables fuzzing of binaries without the risk of breaking target applications, slow performance, or the need for specific hardware. To demonstrate the effectiveness of this mechanism, we developed fuzzers called SPFuzz and SPFuzz++ and conducted an evaluation using 29 real-world benchmarks. The results of our evaluation show that SPFuzz and SPFuzz++ perform comparably to conventional code coverage guidance and are capable of identifying new bugs even without access to the source code. In fact, we discovered six new CVEs in commercial applications like CUDA using SPFuzz.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on12
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and SanitizationSushant Dinesh, Nathan Burow, Dongyan Xu, Mathias PayerS&P 2020 · 187 citations
- Full-Speed Fuzzing: Reducing Fuzzing Overhead through Coverage-Guided TracingStefan Nagy, Matthew HicksS&P 2019 · 156 citations
- SAQL: A Stream-based Query System for Real-Time Abnormal System Behavior DetectionPeng Gao, Xusheng Xiao, Ding Li, Zhichun Li et al.USENIX Security 2018 · 122 citations
- Breaking Through Binaries: Compiler-quality Instrumentation for Better Binary-only FuzzingStefan Nagy, Anh Nguyen-Tuong, Jason D. Hiser, Jack W. Davidson et al.USENIX Security 2021 · 65 citations
Related papers
- Leveraging Binary Coverage for Effective Generation Guidance in Kernel FuzzingJianzhong Liu, Yuheng Shen, Yiru Xu, Yu JiangCCS 2024 · 4 citations
- The Use of Likely Invariants as Feedback for FuzzersAndrea Fioraldi, Daniele Cono D'Elia, Davide BalzarottiUSENIX Security 2021 · 67 citations
- SGXFuzz: Efficiently Synthesizing Nested Structures for SGX Enclave FuzzingTobias Cloosters, Johannes Willbold, Thorsten Holz, Lucas DaviUSENIX Security 2022
- StateFuzz: System Call-Based State-Aware Linux Driver FuzzingBodong Zhao, Zheming Li, Shisong Qin, Zheyu Ma et al.USENIX Security 2022
- When Control Flows Deviate: Directed Grey-box Fuzzing with Probabilistic Reachability AnalysisPeihong Lin, Pengfei Wang, Xu Zhou, Wei Xie et al.ASE 2025
