Default: Mutual Information-based Crash Triage for Massive Crashes
Xing Zhang, Jiongyi Chen, Chao Feng, Ruilin Li, Wenrui Diao, Kehuan Zhang, Jing Lei, Chaojing Tang
Abstract
With the considerable success achieved by modern fuzzing infrastructures, more crashes are produced than ever before. To dig out the root cause, rapid and faithful crash triage for large numbers of crashes has always been attractive. However, hindered by the practical difficulty of reducing analysis imprecision without compromising efficiency, this goal has not been accomplished. In this paper, we present an end-to-end crash triage solution DeFault, for accurately and quickly pinpointing unique root cause from large numbers of crashes. In particular, we quantify the "crash relevance" of program entities based on mutual information, which serves as the criterion of unique crash bucketing and allows us to bucket massive crashes without pre-analyzing their root cause. The quantification of "crash relevance" is also used in the shortening of long crashing traces. On this basis, we use the interpretability of neural networks to precisely pinpoint the root cause in the shortened traces by evaluating each basic block's impact on the crash label. Evaluated with 20 programs with 22216 crashes in total, DeFault demonstrates remarkable accuracy and performance, which is way beyond what the state-of-the-art techniques can achieve: crash de-duplication was achieved at a super-fast processing speed -0.017 seconds per crashing trace, without missing any unique bugs. After that, it identifies the root cause of 43 unique crashes with no false negatives and an average false positive rate of 9.2%. CCS CONCEPTS • Security and privacy → Software security engineering.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7950f27f-ea89-435c-979f-594935debd99Cited by top-tier papers5
- Racing on the Negative Force: Efficient Vulnerability Root-Cause Analysis through Reinforcement Learning on CounterexamplesDandan Xu, Di Tang, Yi Chen, XiaoFeng Wang et al.USENIX Security 2024 · 16 citations
- Firmrca: Towards Post-Fuzzing Analysis on ARM Embedded Firmware with Efficient Event-Based Fault LocalizationBoyu Chang, Binbin Zhao, Qiao Zhang, Peiyu Liu et al.S&P 2025
- No Linux, No Problem: Fast and Correct Windows Binary Fuzzing via Target-embedded SnapshottingLeo Stone, Rishi Ranjan, Stefan Nagy, Matthew HicksUSENIX Security 2023
- GPTrace: Effective Crash Deduplication Using LLM EmbeddingsPatrick Herter, Vincent Ahlrichs, Ridvan Açilan, Julian HorschICSE 2026
- KernelRCA: Facilitating Root Cause Analysis of Memory Corruptions in Linux Kernel with Contextual Causality ChainKangzheng Gu, Yifan Zhang, Yuan Zhang, Min YangUSENIX Security 2026
Builds on2
- Scaffle: bug localization on millions of filesMichael Pradel, Vijayaraghavan Murali, Rebecca Qian, Mateusz Machalica et al.ISSTA 2020 · 34 citations
- AURORA: Statistical Crash Analysis for Automated Root Cause ExplanationTim Blazytko, Moritz Schlögel, Cornelius Aschermann, Ali Abbasi et al.USENIX Security 2020
Related papers
- Reducing Test Cases with Attention Mechanism of Neural NetworksXing Zhang, Jiongyi Chen, Chao Feng, Ruilin Li et al.USENIX Security 2021 · 2 citations
- Igor: Crash Deduplication Through Root-Cause ClusteringZhiyuan Jiang, Xiyue Jiang, Ahmad Hazimeh, Chaojing Tang et al.CCS 2021 · 20 citations
- FuzzerAid: Grouping Fuzzed Crashes Based On Fault SignaturesAshwin Kallingal Joshy, Wei LeASE 2022 · 6 citations
- NEUZZ: Efficient Fuzzing with Neural Program SmoothingDongdong She, Kexin Pei, Dave Epstein, Junfeng Yang et al.S&P 2019 · 220 citations
- DeepAnalyze: Learning to Localize Crashes at ScaleManish Shetty, Chetan Bansal, Suman Nath, Sean Bowles et al.ICSE 2022 · 2 citations
