Define-Use Guided Path Exploration for Better Forced Execution
Dongnan He, Dongchen Xie, Yujie Wang, Wei You, Bin Liang, Jianjun Huang, Wenchang Shi, Zhuo Zhang, Xiangyu Zhang
Abstract
The evolution of recent malware, characterized by the escalating use of cloaking techniques, poses a signi cant challenge in the analysis of malware behaviors. Researchers proposed forced execution to penetrate malware's self-protection mechanisms and expose hidden behaviors, by forcefully setting certain branch outcomes. Existing studies focus on enhancing the forced executor to provide light-weight crash-free execution models. However, insu cient attention has been directed toward the path exploration strategy, an aspect equally crucial to the e ectiveness. Linear search employed in state-of-the-art forced execution tools exhibits inherent limitations that lead to unnecessary path exploration and incomplete behavior exposure. In this paper, we propose a novel and practical path exploration strategy that focuses on the coverage of de neuse relations in the subject binary. We develop a fuzzing approach for exploring these de ne-use relations in a progressive and selfsupervised way. Our experimental results show that the proposed solution outperforms the existing forced execution tools in both memory dependence coverage and malware behavior exposure. CCS CONCEPTS • Security and privacy → Malware and its mitigation; • Software and its engineering;
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b10818c9-7f23-4f8d-aaf6-9df0b93e2765Builds on6
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- Malton: Towards On-Device Non-Invasive Mobile Malware Analysis for ARTLei Xue, Yajin Zhou, Ting Chen, Xiapu Luo et al.USENIX Security 2017 · 81 citations
- DEEPVSA: Facilitating Value-set Analysis with Deep Learning for Postmortem Program AnalysisWenbo Guo, Dongliang Mu, Xinyu Xing, Min Du et al.USENIX Security 2019 · 67 citations
- PMP: Cost-effective Forced Execution with Probabilistic Memory Pre-planningWei You, Zhuo Zhang, Yonghwi Kwon, Yousra Aafer et al.S&P 2020 · 29 citations
- NeuDep: neural binary memory dependence analysisKexin Pei, Dongdong She, Michael Wang, Scott Geng et al.FSE 2022 · 8 citations
Related papers
- Tumbling Down the Rabbit Hole: How do Assisting Exploration Strategies Facilitate Grey-Box Fuzzing?Mingyuan Wu, Jiahong Xiang, Kunqiu Chen, Peng Di et al.ICSE 2025 · 1 citation
- Evaluating and Improving Hybrid FuzzingLing Jiang, Hengchen Yuan, Mingyuan Wu, Lingming Zhang et al.ICSE 2023 · 29 citations
- DDGF: Dynamic Directed Greybox Fuzzing with Path ProfilingHaoran Fang, Kaikai Zhang, Donghui Yu, Yuanyuan ZhangISSTA 2024 · 10 citations
- Pangolin: Incremental Hybrid Fuzzing with Polyhedral Path AbstractionHeqing Huang, Peisen Yao, Rongxin Wu, Qingkai Shi et al.S&P 2020 · 94 citations
- Toward Unbiased Multiple-Target Fuzzing with Path DiversityHuanyao Rong, Wei You, Xiaofeng Wang, Tianhao MaoUSENIX Security 2024 · 12 citations
