BEACON: Directed Grey-Box Fuzzing with Provable Path Pruning
Heqing Huang, Yiyuan Guo, Qingkai Shi, Peisen Yao, Rongxin Wu, Charles Zhang
Abstract
Unlike coverage-based fuzzing that gives equal attention to every part of a code, directed fuzzing aims to direct a fuzzer to a specific target in the code, e.g., the code with potential vulnerabilities. Despite much progress, we observe that existing directed fuzzers are still not efficient as they often symbolically or concretely execute a lot of program paths that cannot reach the target code. They thus waste a lot of computational resources. This paper presents BEACON, which can effectively direct a greybox fuzzer in the sea of paths in a provable manner. That is, assisted by a lightweight static analysis that computes abstracted preconditions for reaching the target, we can prune 82.94% of the executing paths at runtime with negligible analysis overhead (ă5h) but with the guarantee that the pruned paths must be spurious with respect to the target. We have implemented our approach, BEACON, and compared it to five state-of-the-art (directed) fuzzers in the application scenario of vulnerability reproduction. The evaluation results demonstrate that BEACON is 11.50x faster on average than existing directed grey-box fuzzers and it can also improve the speed of the conventional coverage-guided fuzzers, AFL, AFL++, and Mopt, to reproduce specific bugs with 6.31x ,11.86x, and 10.92x speedup, respectively. More interestingly, when used to test the vulnerability patches, BEACON found 14 incomplete fixes of existing CVE-identified vulnerabilities and 8 new bugs while 10 of them are exploitable with new CVE ids assigned.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a25ff090-f10a-405a-b46f-2532320f251cCited by top-tier papers47
- SoK: Prudent Evaluation Practices for FuzzingMoritz Schloegel, Nils Bars, Nico Schiller, Lukas Bernhard et al.S&P 2024 · 69 citations
- Titan : Efficient Multi-target Directed Greybox FuzzingHeqing Huang, Peisen Yao, Hung-Chun Chiu, Yiyuan Guo et al.S&P 2024 · 28 citations
- SyzDirect: Directed Greybox Fuzzing for Linux KernelXin Tan, Yuan Zhang, Jiadong Lu, Xin Xiong et al.CCS 2023 · 25 citations
- SDFuzz: Target States Driven Directed FuzzingPenghui Li, Wei Meng, Chao ZhangUSENIX Security 2024 · 16 citations
- Unleashing the Power of Type-Based Call Graph Construction by Using Regional Pointer InformationYuandao Cai, Yibo Jin, Charles ZhangUSENIX Security 2024 · 16 citations
Builds on12
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 836 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang et al.USENIX Security 2018 · 537 citations
- Hawkeye: Towards a Desired Directed Grey-box FuzzerHongxu Chen, Yinxing Xue, Yuekang Li, Bihuan Chen et al.CCS 2018 · 335 citations
Related papers
- SelectFuzz: Efficient Directed Fuzzing with Selective Path ExplorationChanghua Luo, Wei Meng, Penghui LiS&P 2023
- DAFL: Directed Grey-box Fuzzing guided by Data DependencyTae Eun Kim, Jaeseung Choi, Kihong Heo, Sang Kil ChaUSENIX Security 2023
- Predecessor-aware Directed Greybox FuzzingYujian Zhang, Yaokun Liu, Jinyu Xu, Yanhao WangS&P 2024 · 8 citations
- CollAFL: Path Sensitive FuzzingShuitao Gan, Chao Zhang, Xiaojun Qin, Xuwen Tu et al.S&P 2018 · 426 citations
- FISHFUZZ: Catch Deeper Bugs by Throwing Larger NetsHan Zheng, Jiayuan Zhang, Yuhang Huang, Zezhong Ren et al.USENIX Security 2023
