Default: Mutual Information-based Crash Triage for Massive Crashes
Xing Zhang, Jiongyi Chen, Chao Feng, Ruilin Li, Wenrui Diao, Kehuan Zhang, Jing Lei, Chaojing Tang
摘要
With the considerable success achieved by modern fuzzing infrastructures, more crashes are produced than ever before. To dig out the root cause, rapid and faithful crash triage for large numbers of crashes has always been attractive. However, hindered by the practical difficulty of reducing analysis imprecision without compromising efficiency, this goal has not been accomplished. In this paper, we present an end-to-end crash triage solution DeFault, for accurately and quickly pinpointing unique root cause from large numbers of crashes. In particular, we quantify the "crash relevance" of program entities based on mutual information, which serves as the criterion of unique crash bucketing and allows us to bucket massive crashes without pre-analyzing their root cause. The quantification of "crash relevance" is also used in the shortening of long crashing traces. On this basis, we use the interpretability of neural networks to precisely pinpoint the root cause in the shortened traces by evaluating each basic block's impact on the crash label. Evaluated with 20 programs with 22216 crashes in total, DeFault demonstrates remarkable accuracy and performance, which is way beyond what the state-of-the-art techniques can achieve: crash de-duplication was achieved at a super-fast processing speed -0.017 seconds per crashing trace, without missing any unique bugs. After that, it identifies the root cause of 43 unique crashes with no false negatives and an average false positive rate of 9.2%. CCS CONCEPTS • Security and privacy → Software security engineering.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Racing on the Negative Force: Efficient Vulnerability Root-Cause Analysis through Reinforcement Learning on CounterexamplesDandan Xu, Di Tang, Yi Chen, XiaoFeng Wang 等USENIX Security 2024 · 被引用 16 次
- Firmrca: Towards Post-Fuzzing Analysis on ARM Embedded Firmware with Efficient Event-Based Fault LocalizationBoyu Chang, Binbin Zhao, Qiao Zhang, Peiyu Liu 等S&P 2025
- No Linux, No Problem: Fast and Correct Windows Binary Fuzzing via Target-embedded SnapshottingLeo Stone, Rishi Ranjan, Stefan Nagy, Matthew HicksUSENIX Security 2023
- GPTrace: Effective Crash Deduplication Using LLM EmbeddingsPatrick Herter, Vincent Ahlrichs, Ridvan Açilan, Julian HorschICSE 2026
- KernelRCA: Facilitating Root Cause Analysis of Memory Corruptions in Linux Kernel with Contextual Causality ChainKangzheng Gu, Yifan Zhang, Yuan Zhang, Min YangUSENIX Security 2026
它引用的顶会 Paper2
相关 Paper
- Reducing Test Cases with Attention Mechanism of Neural NetworksXing Zhang, Jiongyi Chen, Chao Feng, Ruilin Li 等USENIX Security 2021 · 被引用 2 次
- Igor: Crash Deduplication Through Root-Cause ClusteringZhiyuan Jiang, Xiyue Jiang, Ahmad Hazimeh, Chaojing Tang 等CCS 2021 · 被引用 20 次
- FuzzerAid: Grouping Fuzzed Crashes Based On Fault SignaturesAshwin Kallingal Joshy, Wei LeASE 2022 · 被引用 6 次
- NEUZZ: Efficient Fuzzing with Neural Program SmoothingDongdong She, Kexin Pei, Dave Epstein, Junfeng Yang 等S&P 2019 · 被引用 220 次
- DeepAnalyze: Learning to Localize Crashes at ScaleManish Shetty, Chetan Bansal, Suman Nath, Sean Bowles 等ICSE 2022 · 被引用 2 次
