On Understanding and Forecasting Fuzzers Performance with Static Analysis
Dongjia Zhang, Andrea Fioraldi, Davide Balzarotti
Abstract
Fuzz testing, a technique for detecting critical software vulnerabilities, combines various methodologies from previous research to improve its effectiveness. For fuzzing practitioners, it is imperative to comprehend the effects of distinct techniques and select the ideal configuration customized to the program they need to test. However, evaluating the individual contributions of these techniques is often very difficult. Prior research compared assembled fuzzers and studied their affinity with different programs. Nevertheless, assembled fuzzers cannot be easily broken down into independent components, and therefore, the evaluation does not clarify which technique explains the performance of the fuzzer. Without understanding the potential impact of integrating different fuzzing techniques, it becomes even more challenging to adjust the fuzzer configuration for different programs under test. Our research tackles this challenge by introducing a novel approach that correlates static analysis features extracted at compile time with the performance results of various fuzzing techniques. Our method uses diverse metrics to uncover the relationship between the static attributes of a program and the dynamic runtime performance of fuzzers. The correlation analysis performed on 23 target applications reveals interesting relationships, such as power schedulers performing better with larger programs and contextsensitive feedback struggling with a large number of inputs. This approach not only enhances our analytical understanding of fuzzing techniques, but also enables predictive capabilities. We show how a simple machine learning model can propose a fuzzer configuration customized for a particular program using information collected through static analysis. In 11 of our benchmark programs, fuzzers using the suggested configuration achieved the best improvement over the baseline compared to AFLplusplus, LibFuzzer and Honggfuzz. CCS Concepts • Security and privacy → Software security engineering.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3e5061e9-a3fb-4845-b5f5-d3e2fae82cb0Builds on15
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik et al.NDSS 2019 · 413 citations
- NAUTILUS: Fishing for Deep Bugs with GrammarsCornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig et al.NDSS 2019 · 291 citations
Related papers
- Program Feature-Based Benchmarking for Fuzz TestingMiao Miao, Sriteja Kummita, Eric Bodden, Shiyi WeiISSTA 2025
- autofz: Automated Fuzzer Composition at RuntimeYu-Fu Fu, Jae-Hyuk Lee, Taesoo KimUSENIX Security 2023
- Variability-Aware FuzzingMeah Tahmeed Ahmed, Arnab Dev, Shiyi WeiICSE 2026
- Liberating Libraries through Automated Fuzz Driver Generation: Striking a Balance without Consumer CodeFlavio Toffalini, Nicolas Badoux, Zurab Tsinadze, Mathias PayerFSE 2025
- xFUZZ: A Flexible Framework for Fine-Grained, Runtime-Adaptive Fuzzing Strategy CompositionDongsong Yu, Yiyi Wang, Chao Zhang, Yang Lan et al.ISSTA 2025
