Lune

FSE2025顶会

MendelFuzz: The Return of the Deterministic Stage

Han Zheng, Flavio Toffalini, Marcel Böhme, Mathias Payer

2025年份
2被引次数
4顶会引用

摘要

Can a fuzzer cover more code with minimal corruption of the initial seed? Before a seed is fuzzed, the early greybox fuzzers first systematically enumerated slightly corrupted inputs by applying every mutation operator to every part of the seed, once per generated input. The hope of this so-called "deterministic" stage was that simple changes to the seed would be less likely to break the complex file format; the resulting inputs would find bugs in the program logic well beyond the program's parser. However, when experiments showed that disabling the deterministic stage achieves more coverage, i.e., applying multiple mutation operators at the same time to a single input, most fuzzers disabled the deterministic stage by default.

Instead of ignoring the deterministic stage, we analyze its potential and substantially improve deterministic exploration. Our deterministic stage is now the default in AFL++, reverting the earlier decision of dropping deterministic exploration. We start by investigating the overhead and the contribution of the deterministic stage to the discovery of coverage-increasing inputs. While the sheer number of generated inputs explains the overhead, we find that only a few critical seeds (20%), and only a few critical bytes in a seed (0.5%) are responsible for the vast majority of the coverage-increasing inputs (83% and 84%, respectively). Hence, we develop an efficient technique, called MendelFuzz, to identify these critical seeds / bytes so as to prune a large number of unnecessary inputs. MendelFuzz retains the benefits of the classic deterministic stage by only enumerating a tiny part of the total deterministic state space.

We evaluate MendelFuzz implementation on two benchmarking frameworks, FuzzBench and Magma. Our evaluation shows that MendelFuzz outperforms state-of-the-art fuzzers with and without the (old) deterministic stage enabled, both in terms of coverage and bug finding. MendelFuzz also discovered 8 new CVEs on exhaustively fuzzed security-critical applications. Finally, MendelFuzz has been independently evaluated and integrated into AFL++ as default option.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper4

问问它们各自怎么用它

它引用的顶会 Paper22

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖