Context-Free Property Oriented Fuzzing
Jiaqiang Yao, Meixi Liu, Zhenbang Chen, Yongchao Xing, Jinjian Luo, Yunlai Luo, Guofeng Zhang, Yufeng Zhang, Ji Wang
Abstract
Fuzzing is effective for finding software bugs. However, the bugs specified in context-free properties are difficult for the existing fuzzers. These bugs are triggered when the program execution contains specific sequences of operations, e.g., push and pop operations on the stack, and locking and unlocking operations on the lock. As far as we know, existing approaches do not support fuzzing for non-regular context-free properties, which are more expressive and can be used to specify bugs in many scenarios.
This paper proposes a general runtime monitoring-based fuzzing framework for the bugs expressed as context-free properties. We propose two algorithms to improve fuzzing's effectiveness and efficiency with respect to the context-free property. The algorithm for preserving input mutants leverages the state transition information of the property's monitors. The other algorithm for mutating the input seed combines control flow information with state transition information to prioritize the different parts of the input. We have implemented our framework CFPOFuzz for C/C++ programs. The results of the extensive experiments on real-world C/C++ programs indicate our method's effectiveness and efficiency. Compared with coverage-oriented fuzzing, our method achieves 3.83x speedups for
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7b864df2-1b70-4936-bc87-73b7dc0f0b17Builds on7
- MemLock: memory usage guided fuzzingCheng Wen, Haijun Wang, Yuekang Li, Shengchao Qin et al.ICSE 2020 · 116 citations
- Typestate-guided fuzzer for discovering use-after-free vulnerabilitiesHaijun Wang, Xiaofei Xie, Yi Li, Cheng Wen et al.ICSE 2020 · 107 citations
- Constraint-guided Directed Greybox FuzzingGwangmu Lee, Woochul Shim, Byoungyoung LeeUSENIX Security 2021 · 99 citations
- Linear-time Temporal Logic guided Greybox FuzzingRuijie Meng, Zhen Dong, Jialin Li, Ivan Beschastnikh et al.ICSE 2022 · 29 citations
- MC2: Rigorous and Efficient Directed Greybox FuzzingAbhishek Shah, Dongdong She, Samanway Sadhu, Krish Singal et al.CCS 2022 · 15 citations
Related papers
- NAUTILUS: Fishing for Deep Bugs with GrammarsCornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig et al.NDSS 2019 · 291 citations
- Critical Variable State-Aware Directed Greybox FuzzingXu Chen, Ningning Cui, Zhe Pan, Liwei Chen et al.ICSE 2025 · 3 citations
- Context-Sensitive and Directional Concurrency Fuzzing for Data-Race DetectionZu-Ming Jiang, Jia-Ju Bai, Kangjie Lu, Shi-Min HuNDSS 2022
- Fuzzing Error Handling Code using Context-Sensitive Software Fault InjectionZu-Ming Jiang, Jia-Ju Bai, Kangjie Lu, Shi-Min HuUSENIX Security 2020
- JITfuzz: Coverage-guided Fuzzing for JVM Just-in-Time CompilersMingyuan Wu, Minghai Lu, Heming Cui, Junjie Chen et al.ICSE 2023 · 36 citations
