USENIX Security2023Top-tier venue
No Linux, No Problem: Fast and Correct Windows Binary Fuzzing via Target-embedded Snapshotting
Leo Stone, Rishi Ranjan, Stefan Nagy, Matthew Hicks
Abstract
Coverage-guided fuzzing remains today's most successful approach for exposing software security vulnerabilities. Speed is paramount in fuzzing, as maintaining a high test case throughput enables more expeditious exploration of programs-leading to faster vulnerability discovery. Highperformance fuzzers exploit the Linux kernel's customizability to implement process snapshotting: fuzzing-oriented execution primitives that dramatically increase fuzzing throughput. Unfortunately, such speeds remain elusive on Windows. The closed-source nature of its kernel prevents current kernel-based snapshotting techniques from being ported-severely limiting fuzzing's effectiveness on Windows programs. Thus, accelerating vetting of the Windows software ecosystem demands a fast, correct, and kernel-agnostic fuzzing execution mechanism. We propose making state snapshotting an applicationlevel concern as opposed to a kernel-level concern via targetembedded snapshotting. Target-embedded-snapshotting combines binary-and library-level hooking to allow applications to snapshot themselves-while leaving both their source code and the Windows kernel untouched. Our evaluation on 10 realworld Windows binaries shows that target-embedded snapshotting overcomes the speed, correctness, and compatibility challenges of previous Windows fuzzing execution mechanisms (i.e., process creation, forkserver-based cloning, and persistent mode). The result is 7-182x increased performance.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3f558256-bd63-447b-8b49-a6095684c4d5Cited by top-tier papers7
- A Little Goes a Long Way: Tuning Configuration Selection for Continuous Kernel FuzzingSanan Hasanov, Stefan Nagy, Paul GazzilloICSE 2025 · 6 citations
- Death by a Thousand Drips: Uncovering Critical Resource Leaks in the Windows EcosystemFeng Dong, Jianting Gao, Yunpeng Tian, Weifeng Yuan et al.USENIX Security 2026
- Signal Breaker: Fuzzing Digital Signal ProcessorsCameron Santiago Garcia, Matthew HicksASPLOS 2026
- Sheep's Clothing, Wolf's Data: Detecting Server-Induced Client Vulnerabilities in Windows Remote IPCFangming Gu, Qingli Guo, Jie Lu, Qinghe Xie et al.NDSS 2025
- Error Messages to Fuzzing: Detecting XPS Parsing Vulnerabilities in Windows Printing ComponentsYunpeng Tian, Feng Dong, Junhai Wang, Mu Zhang et al.CCS 2025
Builds on17
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- CollAFL: Path Sensitive FuzzingShuitao Gan, Chao Zhang, Xiaojun Qin, Xuwen Tu et al.S&P 2018 · 426 citations
- NAUTILUS: Fishing for Deep Bugs with GrammarsCornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig et al.NDSS 2019 · 291 citations
- RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and SanitizationSushant Dinesh, Nathan Burow, Dongyan Xu, Mathias PayerS&P 2020 · 187 citations
- Full-Speed Fuzzing: Reducing Fuzzing Overhead through Coverage-Guided TracingStefan Nagy, Matthew HicksS&P 2019 · 156 citations
Related papers
- Hardware Support to Improve Fuzzing Performance and PrecisionRen Ding, Yonghae Kim, Fan Sang, Wen Xu et al.CCS 2021 · 9 citations
- Breaking Through Binaries: Compiler-quality Instrumentation for Better Binary-only FuzzingStefan Nagy, Anh Nguyen-Tuong, Jason D. Hiser, Jack W. Davidson et al.USENIX Security 2021 · 65 citations
- Effective On-Hardware Fuzzing of Embedded Operating SystemsYuheng Shen, Jianzhong Liu, Qiming Guo, Yifei Chu et al.EuroSys 2026
- Same Coverage, Less Bloat: Accelerating Binary-only Fuzzing with Coverage-preserving Coverage-guided TracingStefan Nagy, Anh Nguyen-Tuong, Jason D. Hiser, Jack W. Davidson et al.CCS 2021 · 21 citations
- WINNIE : Fuzzing Windows Applications with Harness Synthesis and Fast CloningJinho Jung, Stephen Tong, Hong Hu, Jungwon Lim et al.NDSS 2021
