USENIX Security2023Top-tier venue
DynSQL: Stateful Fuzzing for Database Management Systems with Complex and Valid SQL Query Generation
Zu-Ming Jiang, Jia-Ju Bai, Zhendong Su
Abstract
Database management systems (DBMSs) are essential parts of modern software. To ensure the security of DBMSs, recent approaches apply fuzzing to testing DBMSs by automatically generating SQL queries. However, existing DBMS fuzzers are limited in generating complex and valid queries, as they heavily rely on their predefined grammar models and fixed knowledge about DBMSs, but do not capture DBMS-specific state information. As a result, these approaches miss many deep bugs in DBMSs. In this paper, we propose a novel stateful fuzzing approach to effectively test DBMSs and find deep bugs. Our basic idea is that after DBMSs process each SQL statement, there is useful state information that can be dynamically collected to facilitate later query generation. Based on this idea, our approach performs dynamic query interaction to incrementally generate complex and valid SQL queries, using the captured state information. To further improve the validity of generated queries, our approach uses the error status of query processing to filter out invalid test cases. We implement our approach as a fully automatic fuzzing framework, DynSQL. DynSQL is evaluated on 6 widely-used DBMSs (including SQLite, MySQL, MariaDB, PostgreSQL, MonetDB, and ClickHouse) and finds 40 unique bugs. Among these bugs, 38 have been confirmed, 21 have been fixed, and 19 have been assigned with CVE IDs. In our evaluation, DynSQL outperforms other state-of-the-art DBMS fuzzers, achieving 41% higher code coverage and finding many bugs missed by other fuzzers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext aac589ff-5813-4e37-bf99-0eafdd43f3a5Cited by top-tier papers33
- Testing Database Engines via Query Plan GuidanceJinsheng Ba, Manuel RiggerICSE 2023 · 39 citations
- Detecting Transactional Bugs in Database Engines via Graph-Based Oracle ConstructionZu-Ming Jiang, Si Liu, Manuel Rigger, Zhendong SuOSDI 2023 · 28 citations
- Testing Database Systems via Differential Query ExecutionJiansen Song, Wensheng Dou, Ziyu Cui, Qianwang Dai et al.ICSE 2023 · 26 citations
- Keep It Simple: Testing Databases via Differential Query PlansJinsheng Ba, Manuel RiggerSIGMOD 2024 · 23 citations
- Detecting Logic Bugs in Database Engines via Equivalent Expression TransformationZu-Ming Jiang, Zhendong SuOSDI 2024 · 22 citations
Builds on13
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang et al.USENIX Security 2018 · 537 citations
- Testing Database Engines via Pivoted Query SynthesisManuel Rigger, Zhendong SuOSDI 2020 · 150 citations
Related papers
- SQUIRREL: Testing Database Management Systems with Language Validity and Coverage FeedbackRui Zhong, Yongheng Chen, Hong Hu, Hangfan Zhang et al.CCS 2020 · 5 citations
- Mozi: Discovering DBMS Bugs via Configuration-Based Equivalent TransformationJie Liang, Zhiyong Wu, Jingzhou Fu, Mingzhe Wang et al.ICSE 2024 · 18 citations
- Griffin : Grammar-Free DBMS FuzzingJingzhou Fu, Jie Liang, Zhiyong Wu, Mingzhe Wang et al.ASE 2022 · 44 citations
- Efficiently Detecting DBMS Bugs through Bottom-up Syntax-based SQL GenerationYu Liang, Peng LiuNDSS 2026
- Towards Generic Database Management System FuzzingYupeng Yang, Yongheng Chen, Rui Zhong, Jizhou Chen et al.USENIX Security 2024 · 8 citations
