USENIX Security2024Top-tier venue
SymFit: Making the Common (Concrete) Case Fast for Binary-Code Concolic Execution
Zhenxiao Qi, Jie Hu, Zhaoqi Xiao, Heng Yin
Abstract
Concolic execution is a powerful technique in software testing, as it can systematically explore the code paths and is capable of traversing complex branches. It combines concrete execution for environment modeling and symbolic execution for path exploration. While significant research efforts in concolic execution have been directed toward the improvement of symbolic execution and constraint solving, our study pivots toward the often overlooked yet most common aspect: concrete execution. Our analysis shows that state-of-the-art binary concolic executors have largely overlooked the overhead in the execution of concrete instructions. In light of this observation, we propose optimizations to make the common (concrete) case fast. To validate this idea, we develop the prototype, SYMFIT, and evaluate it on standard benchmarks and realworld applications. The results showed that the performance of pure concrete execution is much faster than the baseline SYMQEMU, and is comparable to the vanilla QEMU. Moreover, we showed that the fast symbolic tracing capability of SYMFIT can significantly improve the efficiency of crash deduplication.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3f97c473-28b5-4d5a-bcf0-dd67cf705e8eCited by top-tier papers5
- Agentic Concolic ExecutionZhengxiong Luo, Huan Zhao, Dylan Wolff, Cristian Cadar et al.S&P 2026 · 17 citations
- No More Translation at Runtime: LLM-Empowered Static Binary TranslationZhibo Liu, Huaijin Wang, Wai Kin Wong, Daoyuan Wu et al.EuroSys 2026 · 1 citation
- SACK: Systematic Generation of Function Substitution Attacks Against Control-Flow IntegrityZhechang Zhang, Hengkai Ye, Song Liu, Hong HuNDSS 2026 · 1 citation
- Firmenstein: Scaling Dynamic Analysis for Linux-Based Firmware Services via API-Centric Intervention Code SynthesisYanzhong Wang, Wenhui Zhang, Ruigang Liang, Kai Chen et al.USENIX Security 2026
- Binvariants: Enhancing Fuzzing of Closed-Source Binary Executables via Register-Level Likely InvariantsZao Yang, Stefan NagyFSE 2026
Builds on9
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang et al.USENIX Security 2018 · 537 citations
- FIRM-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process EmulationYaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song et al.USENIX Security 2019 · 279 citations
- UNIFUZZ: A Holistic and Pragmatic Metrics-Driven Platform for Evaluating FuzzersYuwei Li, Shouling Ji, Yuan Chen, Sizhuang Liang et al.USENIX Security 2021 · 142 citations
- JIGSAW: Efficient and Scalable Path Constraints FuzzingJu Chen, Jinghan Wang, Chengyu Song, Heng YinS&P 2022 · 25 citations
Related papers
- SymQEMU: Compilation-based symbolic execution for binariesSebastian Poeplau, Aurélien FrancillonNDSS 2021
- SYMSAN: Time and Space Efficient Concolic Execution via Dynamic Data-flow AnalysisJu Chen, Wookhyun Han, Mingjun Yin, Haochen Zeng et al.USENIX Security 2022
- Symbolic execution with SymCC: Don't interpret, compile!Sebastian Poeplau, Aurélien FrancillonUSENIX Security 2020
- SymFusion: Hybrid Instrumentation for Concolic ExecutionEmilio Coppa, Heng Yin, Camil DemetrescuASE 2022 · 7 citations
- Marco: A Stochastic Asynchronous Concolic ExplorerJie Hu, Yue Duan, Heng YinICSE 2024 · 6 citations
