EMS: History-Driven Mutation for Coverage-based Fuzzing
Chenyang Lyu, Shouling Ji, Xuhong Zhang, Hong Liang, Binbin Zhao, Kangjie Lu, Raheem Beyah
摘要
—Mutation-based fuzzing is one of the most popular approaches to discover vulnerabilities in a program. To alleviate the inefficiency of mutation-based fuzzing incurred by high randomness in the mutation process, multiple solutions are developed in recent years, especially coverage-based fuzzing. They mainly employ adaptive mutation strategies or integrate constraint-solving techniques to make a good exploration of the test cases which trigger unique paths and crashes. However, they lack a fine-grained reusing of fuzzing history to construct these interesting test cases, i.e., they largely fail to properly utilize fuzzing history across different fuzzing trials. In fact, we discover that test cases in fuzzing history contain rich knowledge of the key mutation strategies that lead to the discovery of unique paths and crashes. Specifically, partial path constraint solutions implicitly carried in these mutation strategies can be reused to accelerate the discovery of new paths and crashes that share similar partial path constraints. Therefore, we first propose a lightweight and efficient Proba- bilistic Byte Orientation Model ( PBOM ) that properly captures the byte-level mutation strategies from intra- and inter-trial history and thus can effectively trigger unique paths and crashes. We then present a novel history-driven mutation framework named EMS that employs PBOM as one of the mutation operators to probabilistically provide desired mutation byte values according to the input ones. We evaluate EMS against state-of-the-art fuzzers including AFL, QSYM, MO PT , MO PT -dict, EcoFuzz, and AFL++ on 9 real world programs. The results show that EMS discovers up to 4.91 × more unique vulnerabilities than the baseline, and finds more line coverage than other fuzzers on most programs. We report all of the discovered new vulnerabilities to vendors and will open source the prototype of EMS on GitHub.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper16
- A large-scale empirical analysis of the vulnerabilities introduced by third-party components in IoT firmwareBinbin Zhao, Shouling Ji, Jiacheng Xu, Yuan Tian 等ISSTA 2022 · 被引用 49 次
- SLIME: program-sensitive energy allocation for fuzzingChenyang Lyu, Hong Liang, Shouling Ji, Xuhong Zhang 等ISSTA 2022 · 被引用 27 次
- Critical Code Guided Directed Greybox Fuzzing for CommitsYi Xiang, Xuhong Zhang, Peiyu Liu, Shouling Ji 等USENIX Security 2024 · 被引用 14 次
- HTFuzz: Heap Operation Sequence Sensitive FuzzingYuanping Yu, Xiangkun Jia, Yuwei Liu, Yanhao Wang 等ASE 2022 · 被引用 14 次
- Fuzzle: Making a Puzzle for FuzzersHaeun Lee, Soomin Kim, Sang Kil ChaASE 2022 · 被引用 13 次
它引用的顶会 Paper45
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 被引用 1,026 次
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher 等NDSS 2016 · 被引用 1,021 次
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 被引用 836 次
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei 等CCS 2018 · 被引用 753 次
- VUzzer: Application-aware Evolutionary FuzzingSanjay Rawat, Vivek Jain, Ashish Kumar, Lucian Cojocar 等NDSS 2017 · 被引用 700 次
相关 Paper
- MOPT: Optimized Mutation Scheduling for FuzzersChenyang Lyu, Shouling Ji, Chao Zhang, Yuwei Li 等USENIX Security 2019 · 被引用 5 次
- ShapFuzz: Efficient Fuzzing via Shapley-Guided Byte SelectionKunpeng Zhang, Xiaogang Zhu, Xi Xiao, Minhui Xue 等NDSS 2024
- ProFuzzer: On-the-fly Input Type Probing for Better Zero-Day Vulnerability DiscoveryWei You, Xueqiang Wang, Shiqing Ma, Jianjun Huang 等S&P 2019 · 被引用 130 次
- Path Transitions Tell More: Optimizing Fuzzing Schedules via Runtime Program StatesKunpeng Zhang, Xi Xiao, Xiaogang Zhu, Ruoxi Sun 等ICSE 2022 · 被引用 25 次
- EcoFuzz: Adaptive Energy-Saving Greybox Fuzzing as a Variant of the Adversarial Multi-Armed BanditTai Yue, Pengfei Wang, Yong Tang, Enze Wang 等USENIX Security 2020
