RustGo: Fairly Directed Greybox Fuzzing for Enforcing Rust Memory Safety
Dongyeon Yu, Jiun Min, Yewan Na, Mijung Kim, Taegyu Kim, Yuseok Jeon
摘要
RustGo Artifacts This Zenodo record contains the artifacts for RustGo: Fairly Directed Greybox Fuzzing for Enforcing Rust Memory Safety, evaluated as part of the ACM CCS 2026 Artifact Evaluation. Abstract Rust is a popular systems programming language that provides strong memory safety with low performance overhead. While Rust enforces memory safety through strict policies such as ownership, memory bugs can still occur in unsafe-related Rust code, where these policies are not fully enforced. Although unsafe Rust code accounts for only a small portion of an entire program (e.g., 10%), existing approaches fuzz the entire program—including safe Rust code whose memory safety is already enforced by the Rust compiler—resulting in inefficient use of fuzzing resources. In this paper, we propose RustGo, the first Rust-directed greybox fuzzer that effectively and fairly focuses on code regions that may contain memory bugs. RustGo automatically identifies potential memory-bug targets and accurately prunes paths irrelevant to each target using Rust-specific static analysis. For each identified target, RustGo maintains an independent fuzzing state and applies dynamic pruning to achieve balanced and focused fuzzing. We evaluate RustGo on various real-world Rust applications. On average, RustGo prunes 78.49% of irrelevant paths, reaches targets ×2.09 to ×5.08 faster than existing fuzzers, and identifies 13 previously unknown bugs, including six assigned RUSTSEC IDs and one assigned CVE ID.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper30
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 被引用 836 次
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei 等CCS 2018 · 被引用 753 次
- Hawkeye: Towards a Desired Directed Grey-box FuzzerHongxu Chen, Yinxing Xue, Yuekang Li, Bihuan Chen 等CCS 2018 · 被引用 335 次
- BEACON: Directed Grey-Box Fuzzing with Provable Path PruningHeqing Huang, Yiyuan Guo, Qingkai Shi, Peisen Yao 等S&P 2022 · 被引用 139 次
- Constraint-guided Directed Greybox FuzzingGwangmu Lee, Woochul Shim, Byoungyoung LeeUSENIX Security 2021 · 被引用 99 次
相关 Paper
- deepSURF: Detecting Memory Safety Vulnerabilities in Rust Through Fuzzing LLM-Augmented HarnessesGeorgios C. Androutsopoulos, Antonio BianchiS&P 2026 · 被引用 5 次
- RustSan: Retrofitting AddressSanitizer for Efficient Sanitization of RustKyuwon Cho, Jongyoon Kim, Kha Dinh Duy, Hajeong Lim 等USENIX Security 2024 · 被引用 7 次
- Rudra: Finding Memory Safety Bugs in Rust at the Ecosystem ScaleYechan Bae, Youngsuk Kim, Ammar Askar, Jungwon Lim 等SOSP 2021 · 被引用 61 次
- RULF: Rust Library Fuzzing via API Dependency Graph TraversalJianfeng Jiang, Hui Xu, Yangfan ZhouASE 2021 · 被引用 44 次
- CULPA: Universal Detection of Memory-Safety Bugs in Unsafe Rust Through the Lens of Safety RequirementsHung-Mao Chen, Bo Lu, Xu He, Xiaokuan Zhang 等USENIX Security 2026
