DSFuzz: Detecting Deep State Bugs with Dependent State Exploration
Yinxi Liu, Wei Meng
摘要
Traditional random mutation-based fuzzers are ineffective at reaching deep program states that require specific input values. Consequently, a large number of deep bugs remain undiscovered. To enhance the effectiveness of input mutation, previous research has utilized taint analysis to identify control-dependent critical bytes and only mutates those bytes. However, existing works do not consider indirect control dependencies, in which the critical bytes for taking one branch can only be set in a basic block that is control dependent on a series of other basic blocks. These critical bytes cannot be identified unless that series of basic blocks are visited in the execution path. Existing approaches would take an unacceptably long time and computation resources to attempt multiple paths before setting these critical bytes. In other words, the search space for identifying the critical bytes cannot be effectively explored by the current mutation strategies. In this paper, we aim to explore a new input generation strategy for satisfying a series of indirect control dependencies that can lead to deep program states. We present DSFuzz, a directed fuzzing scheme that effectively constructs inputs for exploring particular deep states. DSFuzz focuses on the deep targets reachable by only satisfying a set of indirect control dependencies. By analyzing the conditions that a deep state indirectly depends on, it can generate dependent critical bytes for taking the corresponding branches. It also rules out the control flows that are unlikely to lead to the target state. As a result, it only needs to mutate under a limited search space. DSFuzz significantly outperformed state-of-the-art directed greybox fuzzers in detecting bugs in deep program states: it detected eight new bugs that other tools failed to find. CCS CONCEPTS • Security and privacy Software security engineering.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- WhiteFox: White-Box Compiler Fuzzing Empowered by Large Language ModelsChenyuan Yang, Yinlin Deng, Runyu Lu, Jiayi Yao 等OOPSLA 2024 · 被引用 74 次
- From Intention to Practice: Towards Systematic Validation of NIDS Rule EnforcementHuan Liu, Haoyu Chen, Biang Xu, Jingyao Zhou 等NSDI 2026
- ChainFuzz: Exploiting Upstream Vulnerabilities in Open-Source Supply ChainsPeng Deng, Lei Zhang, Yuchuan Meng, Zhemin Yang 等USENIX Security 2025
它引用的顶会 Paper30
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher 等NDSS 2016 · 被引用 1,021 次
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 被引用 836 次
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei 等CCS 2018 · 被引用 753 次
- VUzzer: Application-aware Evolutionary FuzzingSanjay Rawat, Vivek Jain, Ashish Kumar, Lucian Cojocar 等NDSS 2017 · 被引用 700 次
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 被引用 616 次
相关 Paper
- Critical Variable State-Aware Directed Greybox FuzzingXu Chen, Ningning Cui, Zhe Pan, Liwei Chen 等ICSE 2025 · 被引用 3 次
- FuzzGuard: Filtering out Unreachable Inputs in Directed Grey-box Fuzzing through Deep LearningPeiyuan Zong, Tao Lv, Dawei Wang, Zizhuang Deng 等USENIX Security 2020
- Predecessor-aware Directed Greybox FuzzingYujian Zhang, Yaokun Liu, Jinyu Xu, Yanhao WangS&P 2024 · 被引用 8 次
- SelectFuzz: Efficient Directed Fuzzing with Selective Path ExplorationChanghua Luo, Wei Meng, Penghui LiS&P 2023
- IDFuzz: Intelligent Directed Grey-box FuzzingYiyang Chen, Chao Zhang, Long Wang, Wenyu Zhu 等USENIX Security 2025
