USENIX Security2021Top-tier venue
Token-Level Fuzzing
Christopher Salls, Chani Jindal, Jake Corina, Christopher Kruegel, Giovanni Vigna
Abstract
Fuzzing has become a commonly used approach to identifying bugs in complex, real-world programs. However, interpreters are notoriously difficult to fuzz effectively, as they expect highly structured inputs, which are rarely produced by most fuzzing mutations. For this class of programs, grammar-based fuzzing has been shown to be effective. Tools based on this approach can find bugs in the code that is executed after parsing the interpreter inputs, by following language-specific rules when generating and mutating test cases. Unfortunately, grammar-based fuzzing is often unable to discover subtle bugs associated with the parsing and handling of the language syntax. Additionally, if the grammar provided to the fuzzer is incomplete, or does not match the implementation completely, the fuzzer will fail to exercise important parts of the available functionality. In this paper, we propose a new fuzzing technique, called Token-Level Fuzzing. Instead of applying mutations either at the byte level or at the grammar level, Token-Level Fuzzing applies mutations at the token level. Evolutionary fuzzers can leverage this technique to both generate inputs that are parsed successfully and generate inputs that do not conform strictly to the grammar. As a result, the proposed approach can find bugs that neither byte-level fuzzing nor grammar-based fuzzing can find. We evaluated Token-Level Fuzzing by modifying AFL and fuzzing four popular JavaScript engines, finding 29 previously unknown bugs, several of which could not be found with state-of-the-art byte-level and grammar-based fuzzers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4ebac6df-df33-4cc5-a9c7-b00facc9f420Cited by top-tier papers16
- LibAFL: A Framework to Build Modular and Reusable FuzzersAndrea Fioraldi, Dominik Christian Maier, Dongjia Zhang, Davide BalzarottiCCS 2022 · 71 citations
- SoK: Prudent Evaluation Practices for FuzzingMoritz Schloegel, Nils Bars, Nico Schiller, Lukas Bernhard et al.S&P 2024 · 69 citations
- JIT-Picking: Differential Fuzzing of JavaScript EnginesLukas Bernhard, Tobias Scharnowski, Moritz Schloegel, Tim Blazytko et al.CCS 2022 · 42 citations
- Minerva: browser API fuzzing with dynamic mod-ref analysisChijin Zhou, Quan Zhang, Mingzhe Wang, Lihua Guo et al.FSE 2022 · 20 citations
- MultiFuzz: A Multi-Stream Fuzzer For Testing Monolithic FirmwareMichael Chesser, Surya Nepal, Damith C. RanasingheUSENIX Security 2024 · 13 citations
Builds on15
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 836 citations
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- VUzzer: Application-aware Evolutionary FuzzingSanjay Rawat, Vivek Jain, Ashish Kumar, Lucian Cojocar et al.NDSS 2017 · 700 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
Related papers
- BCFuzz: Bytecode-Driven Fuzzing for JavaScript EnginesJiming Wang, Chenggang Wu, Jikai Ren, Yuhao Hu et al.ASE 2025 · 1 citation
- NAUTILUS: Fishing for Deep Bugs with GrammarsCornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig et al.NDSS 2019 · 291 citations
- Fuzzing JavaScript Interpreters with Coverage-Guided Reinforcement Learning for LLM-Based MutationJueon Eom, Seyeon Jeong, Taekyoung KwonISSTA 2024 · 26 citations
- SoFi: Reflection-Augmented Fuzzing for JavaScript EnginesXiaoyu He, Xiaofei Xie, Yuekang Li, Jianwen Sun et al.CCS 2021 · 34 citations
- FuzzJIT: Oracle-Enhanced Fuzzing for JavaScript Engine JIT CompilerJunjie Wang, Zhiyi Zhang, Shuang Liu, Xiaoning Du et al.USENIX Security 2023
