USENIX Security2024Top-tier venue
Towards Generic Database Management System Fuzzing
Yupeng Yang, Yongheng Chen, Rui Zhong, Jizhou Chen, Wenke Lee
Abstract
Database Management Systems play an indispensable role in modern cyberspace. While multiple fuzzing frameworks have been proposed in recent years to test relational (SQL) DBMSs to improve their security, non-relational (NoSQL) DBMSs have yet to experience the same scrutiny and lack an effective testing solution in general. In this work, we identify three limitations of existing approaches when extended to fuzz the DBMSs effectively in general: being non-generic, using static constraints, and generating loose data dependencies. Then, we propose effective solutions to address these limitations. We implement our solutions into an end-to-end fuzzing framework, BUZZBEE, which can effectively fuzz both relational and non-relational DBMSs. BUZZBEE successfully discovered 40 vulnerabilities in eight DBMSs of four different data models, of which 25 have been fixed with 4 new CVEs assigned. In our evaluation, BUZZBEE outperforms state-of-theart generic fuzzers by up to 177% in terms of code coverage and discovers 30x more bugs than the second-best fuzzer for non-relational DBMSs, while achieving comparable results with specialized SQL fuzzers for the relational counterpart.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a3ff0ee3-5414-4f8c-bac8-e50d90ace344Cited by top-tier papers6
- Bin2Wrong: a Unified Fuzzing Framework for Uncovering Semantic Errors in Binary-to-C DecompilersZao Yang, Stefan NagyUSENIX ATC 2025 · 6 citations
- Scaling Automated Database System TestingSuyang Zhong, Manuel RiggerASPLOS 2026 · 4 citations
- Testing Computation Pushdown in Distributed Database SystemsJinsheng Ba, Zuming Jiang, Zhendong SuISSTA 2026
- VDBFuzz: Understanding and Detecting Crash Bugs in Vector Database Management SystemsShenao Wang, Zhao Liu, Yanjie Zhao, Quanchen Zou et al.ICSE 2026
- Hybrid Language Processor Fuzzing via LLM-Based Constraint SolvingYupeng Yang, Shenglong Yao, Jizhou Chen, Wenke LeeUSENIX Security 2025
Builds on22
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang et al.USENIX Security 2018 · 537 citations
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik et al.NDSS 2019 · 413 citations
- NAUTILUS: Fishing for Deep Bugs with GrammarsCornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig et al.NDSS 2019 · 291 citations
- CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript EnginesHyungSeok Han, DongHyeon Oh, Sang Kil ChaNDSS 2019 · 178 citations
Related papers
- SQUIRREL: Testing Database Management Systems with Language Validity and Coverage FeedbackRui Zhong, Yongheng Chen, Hong Hu, Hangfan Zhang et al.CCS 2020 · 5 citations
- DynSQL: Stateful Fuzzing for Database Management Systems with Complex and Valid SQL Query GenerationZu-Ming Jiang, Jia-Ju Bai, Zhendong SuUSENIX Security 2023
- Systematically Cover SQL Syntactic Structures via 𝑘-SequenceHongtao Zhou, Yingying Zheng, Yu Gao, Jiansen Song et al.ISSTA 2026 · 1 citation
- Fucci: Database Transaction Fuzzing via Random Conflict Construction and Multilevel Constraint SolvingXiyue Gao, Zhuang Liu, Yiran Shen, Hui Li et al.VLDB 2025 · 2 citations
- VIREO: Human-in-the-Loop DBMS Fuzzing with Visualization and LLM SupportJie Liang, Zhiyong Wu, Jingzhou Fu, Chi Zhang et al.ICDE 2026
