MC2: Rigorous and Efficient Directed Greybox Fuzzing
Abhishek Shah, Dongdong She, Samanway Sadhu, Krish Singal, Peter Coffman, Suman Jana
摘要
Directed greybox fuzzing is a popular technique for targeted software testing that seeks to find inputs that reach a set of target sites in a program. Most existing directed greybox fuzzers do not provide any theoretical analysis of their performance or optimality. In this paper, we introduce a complexity-theoretic framework to pose directed greybox fuzzing as a oracle-guided search problem where some feedback about the input space (e.g., how close an input is to the target sites) is received by querying an oracle. Our framework assumes that each oracle query can return arbitrary content with a large but constant amount of information. Therefore, we use the number of oracle queries required by a fuzzing algorithm to find a target-reaching input as the performance metric. Using our framework, we design a randomized directed greybox fuzzing algorithm that makes a logarithmic (wrt. the number of all possible inputs) number of queries in expectation to find a target-reaching input. We further prove that the number of oracle queries required by our algorithm is optimal, i.e., no fuzzing algorithm can improve (i.e., minimize) the query count by more than a constant factor. We implement our approach in MC 2 and outperform state-of-theart directed greybox fuzzers on challenging benchmarks (Magma and Fuzzer Test Suite) by up to two orders of magnitude (i.e., 134×) on average. MC 2 also found 15 previously undiscovered bugs that other state-of-the-art directed greybox fuzzers failed to find. CCS CONCEPTS • Security and privacy → Software and application security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper17
- SoK: Prudent Evaluation Practices for FuzzingMoritz Schloegel, Nils Bars, Nico Schiller, Lukas Bernhard 等S&P 2024 · 被引用 69 次
- Titan : Efficient Multi-target Directed Greybox FuzzingHeqing Huang, Peisen Yao, Hung-Chun Chiu, Yiyuan Guo 等S&P 2024 · 被引用 28 次
- SDFuzz: Target States Driven Directed FuzzingPenghui Li, Wei Meng, Chao ZhangUSENIX Security 2024 · 被引用 16 次
- Everything is Good for Something: Counterexample-Guided Directed Fuzzing via Likely Invariant InferenceHeqing Huang, Anshunkang Zhou, Mathias Payer, Charles ZhangS&P 2024 · 被引用 15 次
- Critical Code Guided Directed Greybox Fuzzing for CommitsYi Xiang, Xuhong Zhang, Peiyu Liu, Shouling Ji 等USENIX Security 2024 · 被引用 14 次
它引用的顶会 Paper28
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher 等NDSS 2016 · 被引用 1,021 次
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 被引用 616 次
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang 等USENIX Security 2018 · 被引用 537 次
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik 等NDSS 2019 · 被引用 413 次
- Hawkeye: Towards a Desired Directed Grey-box FuzzerHongxu Chen, Yinxing Xue, Yuekang Li, Bihuan Chen 等CCS 2018 · 被引用 335 次
相关 Paper
- Constraint-guided Directed Greybox FuzzingGwangmu Lee, Woochul Shim, Byoungyoung LeeUSENIX Security 2021 · 被引用 99 次
- DirectFuzz: Automated Test Generation for RTL Designs using Directed Graybox FuzzingSadullah Canakci, Leila Delshadtehrani, Furkan Eris, Michael Bedford Taylor 等DAC 2021 · 被引用 53 次
- Predecessor-aware Directed Greybox FuzzingYujian Zhang, Yaokun Liu, Jinyu Xu, Yanhao WangS&P 2024 · 被引用 8 次
- FISHFUZZ: Catch Deeper Bugs by Throwing Larger NetsHan Zheng, Jiayuan Zhang, Yuhang Huang, Zezhong Ren 等USENIX Security 2023
- Critical Variable State-Aware Directed Greybox FuzzingXu Chen, Ningning Cui, Zhe Pan, Liwei Chen 等ICSE 2025 · 被引用 3 次
