Gramatron: effective grammar-aware fuzzing
Prashast Srivastava, Mathias Payer
摘要
Fuzzers aware of the input grammar can explore deeper program states using grammar-aware mutations. Existing grammar-aware fuzzers are ineffective at synthesizing complex bug triggers due to: (i) grammars introducing a sampling bias during input generation due to their structure, and (ii) the current mutation operators for parse trees performing localized small-scale changes. Gramatron uses grammar automatons in conjunction with aggressive mutation operators to synthesize complex bug triggers faster. We build grammar automatons to address the sampling bias. It restructures the grammar to allow for unbiased sampling from the input state space. We redesign grammar-aware mutation operators to be more aggressive, i.e., perform large-scale changes. Gramatron can consistently generate complex bug triggers in an efficient manner as compared to using conventional grammars with parse trees. Inputs generated from scratch by Gramatron have higher diversity as they achieve up to 24.2% more coverage relative to existing fuzzers. Gramatron makes input generation 98% faster and the input representations are 24% smaller. Our redesigned mutation operators are 6.4× more aggressive while still being 68% faster at performing these mutations. We evaluate Gramatron across three interpreters with 10 known bugs consisting of three complex bug triggers and seven simple bug triggers against two Nautilus variants. Gramatron finds all the complex bug triggers reliably and faster. For the simple bug triggers, Gramatron outperforms Nautilus four out of seven times. To demonstrate Gramatron's effectiveness in the wild, we deployed Gramatron on three popular interpreters for a 10-day fuzzing campaign where it discovered 10 new vulnerabilities. CCS CONCEPTS • Software and its engineering → Software testing and debugging; • Security and privacy → Software and application security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper41
- LibAFL: A Framework to Build Modular and Reusable FuzzersAndrea Fioraldi, Dominik Christian Maier, Dongjia Zhang, Davide BalzarottiCCS 2022 · 被引用 71 次
- Cascade: CPU Fuzzing via Intricate Program GenerationFlavien Solt, Katharina Ceesay-Seitz, Kaveh RazaviUSENIX Security 2024 · 被引用 46 次
- Hopper: Interpretative Fuzzing for LibrariesPeng Chen, Yuxuan Xie, Yunlong Lyu, Yuxiao Wang 等CCS 2023 · 被引用 23 次
- Minerva: browser API fuzzing with dynamic mod-ref analysisChijin Zhou, Quan Zhang, Mingzhe Wang, Lihua Guo 等FSE 2022 · 被引用 20 次
- Towards Better Semantics Exploration for Browser FuzzingChijin Zhou, Quan Zhang, Lihua Guo, Mingzhe Wang 等OOPSLA 2023 · 被引用 15 次
它引用的顶会 Paper7
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei 等CCS 2018 · 被引用 753 次
- Skyfire: Data-Driven Seed Generation for FuzzingJunjie Wang, Bihuan Chen, Lei Wei, Yang LiuS&P 2017 · 被引用 382 次
- NAUTILUS: Fishing for Deep Bugs with GrammarsCornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig 等NDSS 2019 · 被引用 291 次
- CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript EnginesHyungSeok Han, DongHyeon Oh, Sang Kil ChaNDSS 2019 · 被引用 178 次
- Fuzzing JavaScript Engines with Aspect-preserving MutationSoyeon Park, Wen Xu, Insu Yun, Daehee Jang 等S&P 2020 · 被引用 126 次
相关 Paper
- GRIMOIRE: Synthesizing Structure while FuzzingTim Blazytko, Cornelius Aschermann, Moritz Schlögel, Ali Abbasi 等USENIX Security 2019 · 被引用 123 次
- Token-Level FuzzingChristopher Salls, Chani Jindal, Jake Corina, Christopher Kruegel 等USENIX Security 2021
- Repair-Driven Greybox FuzzingBachir Bendrissou, Alastair F. Donaldson, Cristian CadarISSTA 2026
- An Empirical Examination of Fuzzer Mutator PerformanceJames Kukucka, Luís Pina, Paul Ammann, Jonathan BellISSTA 2024 · 被引用 4 次
- Low-Cost and Comprehensive Non-textual Input Fuzzing with LLM-Synthesized Input GeneratorsKunpeng Zhang, Zongjie Li, Daoyuan Wu, Shuai Wang 等USENIX Security 2025
