Sequence-Oriented DBMS Fuzzing
Jie Liang, Yaoguang Chen, Zhiyong Wu, Jingzhou Fu, Mingzhe Wang, Yu Jiang, Xiangdong Huang, Ting Chen, Jiashui Wang, Jiajia Li
摘要
The SQL specification consists of hundreds of statement types, which leads to difficulties in DBMS fuzzing: stateof-the-art works generally reuse the statements of predefined types; the limited types cannot cover the full input space and test the corresponding logic consequently. In this paper, we propose LEGO, a fuzzer to generate SQL sequences with abundant types to improve DBMS fuzzing coverage. The key idea of sequence generation is type-affinity, which indicates the meaningful occurrence of SQL type pairs (e.g., INSERT and SELECT). During each fuzzing iteration, LEGO first proactively explores SQL statements of different types and analyzes affinities with coverage feedback. Next, when a new affinity is discovered, LEGO synthesizes new SQL sequences containing the types progressively.
We evaluate LEGO on PostgreSQL, MySQL, MariaDB, and Comdb2 against SQLancer, SQLsmith, and SQUIRREL. The sequence-oriented fuzzing helps LEGO outperform other fuzzers on branch coverage by 44%-198%. More importantly, in the continuous fuzzing, LEGO has discovered 102 new vulnerabilities confirmed by the corresponding vendors, including 6 bugs in PostgreSQL, 21 bugs in MySQL, 42 bugs in MariaDB, and 33 bugs in Comdb2. Among them, 22 CVEs have been assigned due to their severe security influences.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper22
- Detecting Logic Bugs in Database Engines via Equivalent Expression TransformationZu-Ming Jiang, Zhendong SuOSDI 2024 · 被引用 22 次
- Detecting Isolation Bugs via Transaction Oracle ConstructionWensheng Dou, Ziyu Cui, Qianwang Dai, Jiansen Song 等ICSE 2023 · 被引用 21 次
- Mozi: Discovering DBMS Bugs via Configuration-Based Equivalent TransformationJie Liang, Zhiyong Wu, Jingzhou Fu, Mingzhe Wang 等ICSE 2024 · 被引用 18 次
- WingFuzz: Implementing Continuous Fuzzing for DBMSsJie Liang, Zhiyong Wu, Jingzhou Fu, Yiyuan Bai 等USENIX ATC 2024 · 被引用 16 次
- Detecting Metadata-Related Logic Bugs in Database Systems via Raw Database ConstructionJiansen Song, Wensheng Dou, Yu Gao, Ziyu Cui 等VLDB 2024 · 被引用 13 次
它引用的顶会 Paper14
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei 等CCS 2018 · 被引用 753 次
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang 等USENIX Security 2018 · 被引用 537 次
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik 等NDSS 2019 · 被引用 413 次
- Testing Database Engines via Pivoted Query SynthesisManuel Rigger, Zhendong SuOSDI 2020 · 被引用 150 次
- EnFuzz: Ensemble Fuzzing with Seed Synchronization among Diverse FuzzersYuanliang Chen, Yu Jiang, Fuchen Ma, Jie Liang 等USENIX Security 2019 · 被引用 139 次
相关 Paper
- Systematically Cover SQL Syntactic Structures via 𝑘-SequenceHongtao Zhou, Yingying Zheng, Yu Gao, Jiansen Song 等ISSTA 2026 · 被引用 1 次
- DynSQL: Stateful Fuzzing for Database Management Systems with Complex and Valid SQL Query GenerationZu-Ming Jiang, Jia-Ju Bai, Zhendong SuUSENIX Security 2023
- SQUIRREL: Testing Database Management Systems with Language Validity and Coverage FeedbackRui Zhong, Yongheng Chen, Hong Hu, Hangfan Zhang 等CCS 2020 · 被引用 5 次
- VIREO: Human-in-the-Loop DBMS Fuzzing with Visualization and LLM SupportJie Liang, Zhiyong Wu, Jingzhou Fu, Chi Zhang 等ICDE 2026
- Efficiently Detecting DBMS Bugs through Bottom-up Syntax-based SQL GenerationYu Liang, Peng LiuNDSS 2026
