Reachable Coverage: Estimating Saturation in Fuzzing
Danushka Liyanage, Marcel Böhme, Chakkrit Tantithamthavorn, Stephan Lipp
摘要
Reachable coverage is the number of code elements in the search space of a fuzzer (i.e., an automatic software testing tool). A fuzzer cannot find bugs in code that is unreachable. Hence, reachable coverage quantifies fuzzer effectiveness. Using static program analysis, we can compute an upper bound on the number of reachable coverage elements, e.g., by extracting the call graph. However, we cannot decide whether a coverage element is reachable in general. If we could precisely determine reachable coverage efficiently, we would have solved the software verification problem. Unfortunately, we cannot approach a given degree of accuracy for the static approximation, either. In this paper, we advocate a statistical perspective on the approximation of the number of elements in the fuzzer's search space, where accuracy does improve as a function of the analysis runtime. In applied statistics, corresponding estimators have been developed and well established for more than a quarter century. These estimators hold an exciting promise to finally tackle the long-standing challenge of counting reachability. In this paper, we explore the utility of these estimators in the context of fuzzing. Estimates of reachable coverage can be used to measure (a) the amount of untested code, (b) the effectiveness of the testing technique, and (c) the completeness of the ongoing fuzzing campaign (w.r.t. the asymptotic max. achievable coverage). We make all data and our analysis publicly available.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- SoK: Prudent Evaluation Practices for FuzzingMoritz Schloegel, Nils Bars, Nico Schiller, Lukas Bernhard 等S&P 2024 · 被引用 69 次
- Statistical Reachability AnalysisSeongmin Lee, Marcel BöhmeFSE 2023 · 被引用 12 次
- Constant Optimization Driven Database System TestingChi Zhang, Manuel RiggerSIGMOD 2025 · 被引用 8 次
- Extrapolating Coverage Rate in Greybox FuzzingDanushka Liyanage, Seongmin Lee, Chakkrit Tantithamthavorn, Marcel BöhmeICSE 2024 · 被引用 6 次
- Engineering a Formally Verified Automated Bug FinderArthur Correnson, Dominic SteinhöfelFSE 2023 · 被引用 6 次
它引用的顶会 Paper7
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei 等CCS 2018 · 被引用 753 次
- Boosting fuzzer efficiency: an information theoretic perspectiveMarcel Böhme, Valentin J. M. Manès, Sang Kil ChaFSE 2020 · 被引用 115 次
- On the Reliability of Coverage-Based Fuzzer BenchmarkingMarcel Böhme, László Szekeres, Jonathan MetzmanICSE 2022 · 被引用 91 次
- Fuzzing: on the exponential cost of vulnerability discoveryMarcel Böhme, Brandon FalkFSE 2020 · 被引用 66 次
- Revisiting the Relationship Between Fault Detection, Test Adequacy Criteria, and Test Set SizeYiqun T. Chen, Rahul Gopinath, Anita Tadakamalla, Michael D. Ernst 等ASE 2020 · 被引用 48 次
相关 Paper
- Green Fuzzing: A Saturation-Based Stopping Criterion using Vulnerability PredictionStephan Lipp, Daniel Elsner, Severin Kacianka, Alexander Pretschner 等ISSTA 2023 · 被引用 6 次
- Demystifying the Dependency Challenge in Kernel FuzzingYu Hao, Hang Zhang, Guoren Li, Xingyun Du 等ICSE 2022 · 被引用 15 次
- StorFuzz: Using Data Diversity to Overcome Fuzzing PlateausLeon Weiß, Tobias Holl, Kevin BorgolteICSE 2026 · 被引用 1 次
- Data Coverage for Guided FuzzingMingzhe Wang, Jie Liang, Chijin Zhou, Zhiyong Wu 等USENIX Security 2024 · 被引用 6 次
- SDFuzz: Target States Driven Directed FuzzingPenghui Li, Wei Meng, Chao ZhangUSENIX Security 2024 · 被引用 16 次
