WingFuzz: Implementing Continuous Fuzzing for DBMSs
Jie Liang, Zhiyong Wu, Jingzhou Fu, Yiyuan Bai, Qiang Zhang, Yu Jiang
Abstract
Database management systems (DBMSs) are critical components within software ecosystems, and their security and stability are paramount. In recent years, fuzzing has emerged as a prominent automated testing technique, effectively identifying vulnerabilities in various DBMSs. Nevertheless, many of these fuzzers require specific adaptation for a DBMS with a particular version. Employing these techniques to test enterprise-level DBMSs continuously poses challenges due to the diverse specifications of DBMSs and the code changes in their rapid version evolution.
In this paper, we present the industry practice of implementing continuous DBMS fuzzing on enterprise-level DBMSs like ClickHouse. We summarize three main obstacles in implementing, namely the diverse SQL grammar in test case generation, the ongoing evolution of codebase in continuous testing, and the disturbance of noises during anomaly analysis. We propose WINGFUZZ, which utilizes specification-based mutator generation, corpus-driven evolving code fuzzing, and noise-resilient anomaly assessment to address them. By working with the engineers in continuous DBMS fuzzing, we have found a total of 236 previously undiscovered bugs in 12 widely-used enterprise-level DBMSs including ClickHouse, DamengDB, and TenDB. Due to its favorable test results, our efforts received recognition and cooperation invitations from some DBMS vendors. For example, ClickHouse's CTO praised: "Which tool did you use to find this test case? We need to integrate it into our CI." and WINGFUZZ has been successfully integrated into its development process.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers7
- Understanding and Detecting SQL Function Bugs: Using Simple Boundary Arguments to Trigger Hundreds of DBMS BugsJingzhou Fu, Jie Liang, Zhiyong Wu, Yanyang Zhao et al.EuroSys 2025 · 6 citations
- Scaling Automated Database System TestingSuyang Zhong, Manuel RiggerASPLOS 2026 · 4 citations
- Towards More Complete Constraints for Deep Learning Library Testing via Complementary Set Guided RefinementGwihwan Go, Chijin Zhou, Quan Zhang, Xiazijian Zou et al.ISSTA 2024 · 2 citations
- Coni: Detecting Database Connector Bugs via State-Aware Test Case GenerationWenqian Deng, Jie Liang, Zhiyong Wu, Jingzhou Fu et al.ICSE 2025 · 1 citation
- Fuzzing Enterprise-Grade Blockchain Systems: Industrial Practice and SolutionsFuchen Ma, Yuanliang Chen, Zhen Yan, Yuanhang Zhou et al.EuroSys 2026
Builds on10
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 836 citations
- Hawkeye: Towards a Desired Directed Grey-box FuzzerHongxu Chen, Yinxing Xue, Yuekang Li, Bihuan Chen et al.CCS 2018 · 335 citations
- Testing Database Engines via Pivoted Query SynthesisManuel Rigger, Zhendong SuOSDI 2020 · 150 citations
- Finding bugs in database systems via query partitioningManuel Rigger, Zhendong SuOOPSLA 2020 · 116 citations
- Detecting optimization bugs in database engines via non-optimizing reference engine constructionManuel Rigger, Zhendong SuFSE 2020 · 104 citations
Related papers
- DynSQL: Stateful Fuzzing for Database Management Systems with Complex and Valid SQL Query GenerationZu-Ming Jiang, Jia-Ju Bai, Zhendong SuUSENIX Security 2023
- Mozi: Discovering DBMS Bugs via Configuration-Based Equivalent TransformationJie Liang, Zhiyong Wu, Jingzhou Fu, Mingzhe Wang et al.ICSE 2024 · 18 citations
- Systematically Cover SQL Syntactic Structures via 𝑘-SequenceHongtao Zhou, Yingying Zheng, Yu Gao, Jiansen Song et al.ISSTA 2026 · 1 citation
- Sedar: Obtaining High-Quality Seeds for DBMS Fuzzing via Cross-DBMS SQL TransferJingzhou Fu, Jie Liang, Zhiyong Wu, Yu JiangICSE 2024 · 10 citations
- Towards Generic Database Management System FuzzingYupeng Yang, Yongheng Chen, Rui Zhong, Jizhou Chen et al.USENIX Security 2024 · 8 citations
