Don't Panic! Finding Bugs Hidden Behind Rust Runtime Safety Checks
Zeyang Zhuang, Zilun Wang, Wei Meng, Michael R. Lyu
摘要
Rust has been extensively used in software and system development due to its guarantees for memory and concurrency safety. Fuzzing is a popular bug detection technique for examining the correctness and robustness of programs. However, we identify that current state-of-the-art Rust fuzzers are significantly impeded by the ubiquitous presence of Rust runtime safety checks, resulting in poor effectiveness and efficiency. These checks, which are inserted either implicitly by the compiler or explicitly by the compiler or developers, could cause a high number of panic crashes and early program termination in fuzzing. Consequently, current fuzzers are unable to effectively explore deep code behind the runtime safety checks, leaving potential vulnerabilities undetected. To address these limitations, we propose PanicKiller, a new Rust fuzzing technique to detect bugs hidden in deep and unsafe code. It performs a cross-IR analysis to precisely identify runtime safety checks and unsafe code in Rust programs, and employs a novel dynamic taint analysis to track the critical input bytes associated with the conditions enforced by these checks. PanicKiller further performs novel input prioritization and mutation strategies to achieve effective and efficient fuzzing. Our evaluation shows that PanicKiller significantly outperformed current state-of-the-art Rust fuzzers by achieving average improvements of 22.0× in bug exposure speed, 1.68× in code coverage, and 18.2× in false-positive crash reduction, and up to 129.0×, 2.10×, and 64.8× improvements, respectively. PanicKiller further helped detect 14 and 53 previously unknown vulnerabilities in the benchmark dataset and in the real world, with 11 RustSec IDs assigned. CCS Concepts • Security and privacy → Software security engineering.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper15
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei 等CCS 2018 · 被引用 753 次
- VUzzer: Application-aware Evolutionary FuzzingSanjay Rawat, Vivek Jain, Ashish Kumar, Lucian Cojocar 等NDSS 2017 · 被引用 700 次
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 被引用 616 次
- CollAFL: Path Sensitive FuzzingShuitao Gan, Chao Zhang, Xiaojun Qin, Xuwen Tu 等S&P 2018 · 被引用 426 次
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik 等NDSS 2019 · 被引用 413 次
相关 Paper
- deepSURF: Detecting Memory Safety Vulnerabilities in Rust Through Fuzzing LLM-Augmented HarnessesGeorgios C. Androutsopoulos, Antonio BianchiS&P 2026 · 被引用 5 次
- RustSan: Retrofitting AddressSanitizer for Efficient Sanitization of RustKyuwon Cho, Jongyoon Kim, Kha Dinh Duy, Hajeong Lim 等USENIX Security 2024 · 被引用 7 次
- FRIES: Fuzzing Rust Library Interactions via Efficient Ecosystem-Guided Target GenerationXizhe Yin, Yang Feng, Qingkai Shi, Zixi Liu 等ISSTA 2024 · 被引用 6 次
- RPG: Rust Library Fuzzing with Pool-based Fuzz Target Generation and Generic SupportZhiwu Xu, Bohao Wu, Cheng Wen, Bin Zhang 等ICSE 2024 · 被引用 9 次
- RULF: Rust Library Fuzzing via API Dependency Graph TraversalJianfeng Jiang, Hui Xu, Yangfan ZhouASE 2021 · 被引用 44 次
