FuzzCache: Optimizing Web Application Fuzzing Through Software-Based Data Cache
Penghui Li, Mingxue Zhang
Abstract
Fuzzing has shown great promise in detecting vulnerabilities in server-side web applications. In this work, we introduce an innovative software-based data cache mechanism that complements and improves all existing web application fuzzing tools. Our key observation is that a great proportion of execution time (e.g., 50%) of web applications is spent on fetching data from two major sources: database and network; our in-depth investigation reveals that the same data is often repeatedly fetched across fuzzing trials. We thus design a new solution, FuzzCache, that stores the data into softwarebased caches, mitigating the need for repeated and expensive data fetches. FuzzCache exposes the cached data across fuzzing trials through inter-process shared memory segments. It also, as the first work, incorporates just-in-time compilation to avoid the performance overhead associated with interpreting PHP code in real time, thereby enhancing execution efficiency.
We demonstrate that FuzzCache significantly enhances web application fuzzing performance. In our experiments, we integrated FuzzCache with both a black-box fuzzer (Black-Widow) and a greybox fuzzer (WebFuzz). The results illustrate that FuzzCache accelerates both black-box and grey-box fuzzing, achieving a throughput increase of 3× to 4×. FuzzCache substantially improves code coverage by an average of 25%. Consequently, FuzzCache enables faster vulnerability detection, leading to the discovery of a greater number of vulnerabilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8171663e-6938-430b-ae74-bf157caa5724Cited by top-tier papers2
- ZendDiff: Differential Testing of PHP InterpreterYuancheng Jiang, Jianing Wang, Qiange Liu, Yeqi Fu et al.ASE 2025 · 1 citation
- Predator: Directed Web Application Fuzzing for Efficient Vulnerability ValidationChenlin Wang, Wei Meng, Changhua Luo, Penghui LiS&P 2025
Builds on16
- RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and SanitizationSushant Dinesh, Nathan Burow, Dongyan Xu, Mathias PayerS&P 2020 · 187 citations
- Full-Speed Fuzzing: Reducing Fuzzing Overhead through Coverage-Guided TracingStefan Nagy, Matthew HicksS&P 2019 · 156 citations
- BEACON: Directed Grey-Box Fuzzing with Provable Path PruningHeqing Huang, Yiyuan Guo, Qingkai Shi, Peisen Yao et al.S&P 2022 · 139 citations
- Designing New Operating Primitives to Improve Fuzzing PerformanceWen Xu, Sanidhya Kashyap, Changwoo Min, Taesoo KimCCS 2017 · 139 citations
- Nyx: Greybox Hypervisor Fuzzing using Fast Snapshots and Affine TypesSergej Schumilo, Cornelius Aschermann, Ali Abbasi, Simon Wörner et al.USENIX Security 2021 · 102 citations
Related papers
- Holistic Concolic Execution for Dynamic Web Applications via Symbolic Interpreter AnalysisPenghui Li, Wei Meng, Mingxue Zhang, Chenlin Wang et al.S&P 2024 · 6 citations
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars et al.USENIX Security 2024 · 45 citations
- Racedb: Detecting Request Race Vulnerabilities in Database-Backed Web ApplicationsAn Chen, Yonghwi Kwon, Kyu Hyung LeeS&P 2025
- Where URLs Become Weapons: Automated Discovery of SSRF Vulnerabilities in Web ApplicationsEnze Wang, Jianjun Chen, Wei Xie, Chuhan Wang et al.S&P 2024 · 15 citations
- PHPBench: Automated Generation of Verifiable and Hierarchical Benchmarks for PHP Web FuzzingYoukun Shi, Yuan Zhang, Lei Zhang, Jiarun Dai et al.CCS 2026
