USENIX Security2023Top-tier venue
AIFORE: Smart Fuzzing Based on Automatic Input Format Reverse Engineering
Ji Shi, Zhun Wang, Zhiyao Feng, Yang Lan, Shisong Qin, Wei You, Wei Zou, Mathias Payer, Chao Zhang
Abstract
Knowledge of a program's input format is essential for effective input generation in fuzzing. Automated input format reverse engineering represents an attractive but challenging approach to learning the format. In this paper, we address several challenges of automated input format reverse engineering, and present a smart fuzzing solution AIFORE which makes full use of the reversed format and benefits from it. The structures and semantics of input fields are determined by the basic blocks (BBs) that process them rather than the input specification. Therefore, we first utilize byte-level taint analysis to recognize the input bytes processed by each BB, then identify indivisible input fields that are always processed together with a minimum cluster algorithm, and learn their types with a neural network model that characterizes the behavior of BBs. Lastly, we design a new power scheduling algorithm based on the inferred format knowledge to guide smart fuzzing. We implement a prototype of AIFORE and evaluate both the accuracy of format inference and the performance of fuzzing against state-of-the-art (SOTA) format reversing solutions and fuzzers. AIFORE significantly outperforms SOTA baselines on the accuracy of field boundary and type recognition. With AIFORE, we uncovered 20 bugs in 15 programs that were missed by other fuzzers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9ba664bb-0d0d-46a2-bc9d-d0ebd87196f9Cited by top-tier papers5
- SoK: Prudent Evaluation Practices for FuzzingMoritz Schloegel, Nils Bars, Nico Schiller, Lukas Bernhard et al.S&P 2024 · 69 citations
- FOX: Coverage-guided Fuzzing as Online Stochastic ControlDongdong She, Adam Storek, Yuchong Xie, Seoyoung Kweon et al.CCS 2024 · 5 citations
- IDFuzz: Intelligent Directed Grey-box FuzzingYiyang Chen, Chao Zhang, Long Wang, Wenyu Zhu et al.USENIX Security 2025
- FrameShift: Resizing Fuzzer Inputs Without Breaking ThemHarrison Green, Claire Le Goues, Fraser BrownICSE 2026
- HouseFuzz: Service-Aware Grey-Box Fuzzing for Vulnerability Detection in Linux-Based FirmwareHaoyu Xiao, Ziqi Wei, Jiarun Dai, Bowen Li et al.S&P 2025
Builds on15
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- VUzzer: Application-aware Evolutionary FuzzingSanjay Rawat, Vivek Jain, Ashish Kumar, Lucian Cojocar et al.NDSS 2017 · 700 citations
- Neural Network-based Graph Embedding for Cross-Platform Binary Code Similarity DetectionXiaojun Xu, Chang Liu, Qian Feng, Heng Yin et al.CCS 2017 · 682 citations
- Order Matters: Semantic-Aware Neural Networks for Binary Code Similarity DetectionZeping Yu, Rui Cao, Qiyi Tang, Sen Nie et al.AAAI 2020 · 265 citations
Related papers
- WEIZZ: automatic grey-box fuzzing for structured binary formatsAndrea Fioraldi, Daniele Cono D'Elia, Emilio CoppaISSTA 2020 · 65 citations
- ConFuzz: Towards Large Scale Fuzz Testing of Smart Contracts in EthereumTaiyu Wong, Chao Zhang, Yuandong Ni, Mingsen Luo et al.INFOCOM 2024 · 10 citations
- ProFuzzer: On-the-fly Input Type Probing for Better Zero-Day Vulnerability DiscoveryWei You, Xueqiang Wang, Shiqing Ma, Jianjun Huang et al.S&P 2019 · 130 citations
- Intriguer: Field-Level Constraint Solving for Hybrid FuzzingMingi Cho, Seoyoung Kim, Taekyoung KwonCCS 2019 · 54 citations
- NestFuzz: Enhancing Fuzzing with Comprehensive Understanding of Input Processing LogicPeng Deng, Zhemin Yang, Lei Zhang, Guangliang Yang et al.CCS 2023 · 5 citations
