USENIX Security2021Top-tier venue
APICraft: Fuzz Driver Generation for Closed-source SDK Libraries
Cen Zhang, Xingwei Lin, Yuekang Li, Yinxing Xue, Jundong Xie, Hongxu Chen, Xinlei Ying, Jiashui Wang, Yang Liu
Abstract
Fuzz drivers are needed for fuzzing libraries. A fuzz driver is a program which can execute library functions by feeding them with inputs provided by the fuzzer. In practice, fuzz drivers are written by security experts and the drivers' quality depends on the skill of their authors. To relieve manual efforts and ensure test quality, different techniques have been proposed to automatically generate fuzz drivers. However, existing techniques mostly rely on static analysis of source code, leaving the fuzz driver generation for closed-source SDK libraries an open problem. Fuzz driver generation for closed-source libraries is faced with two major challenges: 1) only limited information can be extracted from the library; 2) the semantic relations among API functions are complex yet their correctness needs to be ensured. To address these challenges, we propose APICRAFT, an automated fuzz driver generation technique. The core strategy of APICRAFT is collectcombine. First, APICRAFT leverages both static and dynamic information (headers, binaries, and traces) to collect control and data dependencies for API functions in a practical manner. Then, it uses a multi-objective genetic algorithm to combine the collected dependencies and build high-quality fuzz drivers. We implemented APICRAFT as a fuzz driver generation framework and evaluated it with five attack surfaces from the macOS SDK. In the evaluation, the fuzz drivers generated by APICRAFT demonstrate superior code coverage than the manually written ones, with an improvement of 64% on average. We further carried out a long-term fuzzing campaign with the fuzz drivers generated by APICRAFT. After around eight month's fuzzing, we've so far discovered 142 vulnerabilities with 54 assigned CVEs in macOS SDK, which can affect popular Apple products such as Safari, Messages, Preview and so on.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8f1c1ae4-d46d-4575-a1ec-e0ea2620b7b5Cited by top-tier papers28
- Windranger: A Directed Greybox Fuzzer driven by Deviation Basic BlocksZhengjie Du, Yuekang Li, Yang Liu, Bing MaoICSE 2022 · 64 citations
- Efficient greybox fuzzing of applications in Linux-based IoT devices via enhanced user-mode emulationYaowen Zheng, Yuekang Li, Cen Zhang, Hongsong Zhu et al.ISSTA 2022 · 34 citations
- How Effective Are They? Exploring Large Language Model Based Fuzz Driver GenerationCen Zhang, Yaowen Zheng, Mingqiang Bai, Yeting Li et al.ISSTA 2024 · 27 citations
- Hopper: Interpretative Fuzzing for LibrariesPeng Chen, Yuxuan Xie, Yunlong Lyu, Yuxiao Wang et al.CCS 2023 · 23 citations
- Prompt Fuzzing for Fuzz Driver GenerationYunlong Lyu, Yuxuan Xie, Peng Chen, Hao ChenCCS 2024 · 21 citations
Builds on17
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- Skyfire: Data-Driven Seed Generation for FuzzingJunjie Wang, Bihuan Chen, Lei Wei, Yang LiuS&P 2017 · 382 citations
- Hawkeye: Towards a Desired Directed Grey-box FuzzerHongxu Chen, Yinxing Xue, Yuekang Li, Bihuan Chen et al.CCS 2018 · 335 citations
Related papers
- FuzzGen: Automatic Fuzzer GenerationKyriakos K. Ispoglou, Daniel Austin, Vishwath Mohan, Mathias PayerUSENIX Security 2020
- SyzGen: Automated Generation of Syscall Specification of Closed-Source macOS DriversWeiteng Chen, Yu Wang, Zheng Zhang, Zhiyun QianCCS 2021 · 25 citations
- KextFuzz: Fuzzing macOS Kernel EXTensions on Apple Silicon via Exploiting MitigationsTingting Yin, Zicong Gao, Zhenghang Xiao, Zheyu Ma et al.USENIX Security 2023
- RULF: Rust Library Fuzzing via API Dependency Graph TraversalJianfeng Jiang, Hui Xu, Yangfan ZhouASE 2021 · 44 citations
- AFGen: Whole-Function Fuzzing for Applications and LibrariesYuwei Liu, Yanhao Wang, Xiangkun Jia, Zheng Zhang et al.S&P 2024 · 15 citations
