USENIX Security2023Top-tier venue
CarpetFuzz: Automatic Program Option Constraint Extraction from Documentation for Fuzzing
Dawei Wang, Ying Li, Zhiyu Zhang, Kai Chen
Abstract
The large-scale code in software supports the rich and diverse functionalities, and at the same time contains potential vulnerabilities. Fuzzing, as one of the most popular vulnerability detection methods, continues evolving in both industry and academy, aiming to find more vulnerabilities by covering more code. However, we find that even with the state-ofthe-art fuzzers, there is still some unexplored code that can only be triggered using a specific combination of program options. Simply mutating the options may generate many invalid combinations due to the lack of consideration of constraints (or called relationships) among options. In this paper, we leverage natural language processing (NLP) to automatically extract option descriptions from program documents and analyze the relationship (e.g., conflicts, dependencies) among the options before filtering out invalid combinations and only leaving the valid ones for fuzzing. We implemented a tool called CarpetFuzz and evaluated its performance. The results show that CarpetFuzz accurately extracts the relationships from documents with 96.10% precision and 88.85% recall. Based on these relationships, CarpetFuzz reduced the 67.91% option combinations to be tested. It helps AFL find 45.97% more paths that other fuzzers cannot discover. After analyzing 20 popular open-source programs, CarpetFuzz discovered 57 vulnerabilities, including 43 undisclosed ones. We also successfully obtained CVE IDs for 30 vulnerabilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f5431219-37e7-41f2-866a-7672df64f1f4Cited by top-tier papers5
- Fuzzing BusyBox: Leveraging LLM and Crash Reuse for Embedded Bug UnearthingAsmita, Yaroslav Oliinyk, Michael Scott, Ryan Tsang et al.USENIX Security 2024 · 56 citations
- ProphetFuzz: Fully Automated Prediction and Fuzzing of High-Risk Option Combinations with Only Documentation via Large Language ModelDawei Wang, Geng Zhou, Li Chen, Dan Li et al.CCS 2024 · 9 citations
- PILOT: Command-Line Interface Fuzzing Via Path-Guided, Iterative Large Language Model PromptingMomoko Shiraishi, Yinzhi Cao, Takahiro ShinagawaS&P 2026 · 1 citation
- MUTATO: Enhancing Fuzz Drivers with Adaptive API Option MutationShuangxiang Kan, Xiao Cheng, Yuekang LiNDSS 2026
- Variability-Aware FuzzingMeah Tahmeed Ahmed, Arnab Dev, Shiyi WeiICSE 2026
Builds on15
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- CollAFL: Path Sensitive FuzzingShuitao Gan, Chao Zhang, Xiaojun Qin, Xuwen Tu et al.S&P 2018 · 426 citations
- Send Hardest Problems My Way: Probabilistic Path Prioritization for Hybrid FuzzingLei Zhao, Yue Duan, Heng Yin, Jifeng XuanNDSS 2019 · 157 citations
Related papers
- OSmart: Whitebox Program Option FuzzingKelin Wang, Mengda Chen, Liang He, Purui Su et al.CCS 2024 · 2 citations
- SemFuzz: Semantics-based Automatic Generation of Proof-of-Concept ExploitsWei You, Peiyuan Zong, Kai Chen, XiaoFeng Wang et al.CCS 2017 · 148 citations
- PolyFuzz: Holistic Greybox Fuzzing of Multi-Language SystemsWen Li, Jinyang Ruan, Guangbei Yi, Long Cheng et al.USENIX Security 2023
- It Takes Two: Option-Aware Directed Greybox Fuzzing for Vulnerability PoC GenerationSusheng Wu, Xin Hu, Yiheng Cao, Zhuotong Zhou et al.FSE 2026
- SelectFuzz: Efficient Directed Fuzzing with Selective Path ExplorationChanghua Luo, Wei Meng, Penghui LiS&P 2023
