ProFuzzer: On-the-fly Input Type Probing for Better Zero-Day Vulnerability Discovery
Wei You, Xueqiang Wang, Shiqing Ma, Jianjun Huang, Xiangyu Zhang, XiaoFeng Wang, Bin Liang
摘要
Existing mutation based fuzzers tend to randomly mutate the input of a program without understanding its underlying syntax and semantics. In this paper, we propose a novel on-the-fly probing technique (called ProFuzzer) that automatically recovers and understands input fields of critical importance to vulnerability discovery during a fuzzing process and intelligently adapts the mutation strategy to enhance the chance of hitting zero-day targets. Since such probing is transparently piggybacked to the regular fuzzing, no prior knowledge of the input specification is needed. During fuzzing, individual bytes are first mutated and their fuzzing results are automatically analyzed to link those related together and identify the type for the field connecting them; these bytes are further mutated together following type-specific strategies, which substantially prunes the search space. We define the probe types generally across all applications, thereby making our technique application agnostic. Our experiments on standard benchmarks and real-world applications show that ProFuzzer substantially outperforms AFL and its optimized version AFLFast, as well as other state-of-art fuzzers including VUzzer, Driller and QSYM. Within two months, it exposed 42 zero-days in 10 intensively tested programs, generating 30 CVEs.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper54
- SAVIOR: Towards Bug-Driven Hybrid TestingYaohui Chen, Peng Li, Jun Xu, Shengjian Guo 等S&P 2020 · 被引用 186 次
- DifuzzRTL: Differential Fuzz Testing to Find CPU BugsJaewon Hur, Suhwan Song, Dongup Kwon, Eunjin Baek 等S&P 2021 · 被引用 126 次
- MemLock: memory usage guided fuzzingCheng Wen, Haijun Wang, Yuekang Li, Shengchao Qin 等ICSE 2020 · 被引用 116 次
- Understanding memory and thread safety practices and issues in real-world Rust programsBoqin Qin, Yilun Chen, Zeming Yu, Linhai Song 等PLDI 2020 · 被引用 112 次
- Typestate-guided fuzzer for discovering use-after-free vulnerabilitiesHaijun Wang, Xiaofei Xie, Yi Li, Cheng Wen 等ICSE 2020 · 被引用 107 次
它引用的顶会 Paper12
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 被引用 1,026 次
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher 等NDSS 2016 · 被引用 1,021 次
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 被引用 836 次
- VUzzer: Application-aware Evolutionary FuzzingSanjay Rawat, Vivek Jain, Ashish Kumar, Lucian Cojocar 等NDSS 2017 · 被引用 700 次
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 被引用 616 次
相关 Paper
- MOPT: Optimized Mutation Scheduling for FuzzersChenyang Lyu, Shouling Ji, Chao Zhang, Yuwei Li 等USENIX Security 2019 · 被引用 5 次
- ShapFuzz: Efficient Fuzzing via Shapley-Guided Byte SelectionKunpeng Zhang, Xiaogang Zhu, Xi Xiao, Minhui Xue 等NDSS 2024
- IDFuzz: Intelligent Directed Grey-box FuzzingYiyang Chen, Chao Zhang, Long Wang, Wenyu Zhu 等USENIX Security 2025
- Zeror: Speed Up Fuzzing with Coverage-sensitive Tracing and SchedulingChijin Zhou, Mingzhe Wang, Jie Liang, Zhe Liu 等ASE 2020 · 被引用 35 次
- Prospector: Boosting Directed Greybox Fuzzing for Large-Scale Target Sets with Iterative PrioritizationZhijie Zhang, Liwei Chen, Haolai Wei, Gang Shi 等ISSTA 2024 · 被引用 4 次
