Program Environment Fuzzing
Ruijie Meng, Gregory J. Duck, Abhik Roychoudhury
Abstract
Computer programs are not executed in isolation, but rather interact with the execution environment which drives the program behaviors. Software validation methods thus need to capture the effect of possibly complex environmental interactions. Program environments may come from files, databases, configurations, network sockets, human-user interactions, and more. Conventional approaches for environment capture in symbolic execution and model checking employ environment modeling, which involves manual effort. In this paper, we take a different approach based on an extension of greybox fuzzing. Given a program, we first record all observed environmental interactions at the kernel/usermode boundary in the form of system calls. Next, we replay the program under the original recorded interactions, but this time with selective mutations applied, in order to get the effect of different program environments-all without environment modeling. Via repeated (feedback-driven) mutations over a fuzzing campaign, we can search for program environments that induce crashing behaviors. Our Efuzz tool found 33 previously unknown bugs in well-known real-world protocol implementations and GUI applications. Many of these are security vulnerabilities and 16 CVEs were assigned. CCS CONCEPTS • Security and privacy → Software security engineering.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 64f14d7c-e5bb-41c0-9b8c-33794001f6ddCited by top-tier papers3
- Large Language Model Powered Symbolic ExecutionYihe Li, Ruijie Meng, Gregory J. DuckOOPSLA 2025 · 12 citations
- NCFuzz: Configuration-Guided Network Service FuzzingXuesong Bai, Hengkai Ye, Shenghan Zheng, Fenglu Zhang et al.ISSTA 2026
- GUIFuzz++: Unleashing Grey-box Fuzzing on Desktop Graphical User Interfacing ApplicationsDillon Otto, Tanner Rowlett, Stefan NagyASE 2025
Builds on14
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- Ijon: Exploring Deep State Spaces via FuzzingCornelius Aschermann, Sergej Schumilo, Ali Abbasi, Thorsten HolzS&P 2020 · 146 citations
- Snipuzz: Black-box Fuzzing of IoT Firmware via Message Snippet InferenceXiaotao Feng, Ruoxi Sun, Xiaogang Zhu, Minhui Xue et al.CCS 2021 · 146 citations
- On the Reliability of Coverage-Based Fuzzer BenchmarkingMarcel Böhme, László Szekeres, Jonathan MetzmanICSE 2022 · 91 citations
Related papers
- Variability-Aware FuzzingMeah Tahmeed Ahmed, Arnab Dev, Shiyi WeiICSE 2026
- Linear-time Temporal Logic guided Greybox FuzzingRuijie Meng, Zhen Dong, Jialin Li, Ivan Beschastnikh et al.ICSE 2022 · 29 citations
- DevFuzz: Automatic Device Model-Guided Device Driver FuzzingYilun Wu, Tong Zhang, Changhee Jung, Dongyoon LeeS&P 2023
- EnclaveFuzz: Finding Vulnerabilities in SGX ApplicationsLiheng Chen, Zheming Li, Zheyu Ma, Yuan Li et al.NDSS 2024
- Fuzzing Guided by Bayesian Program AnalysisYifan Zhang, Xin ZhangPOPL 2026 · 2 citations
