Meerkat: Pushing the Practical Limits of Dynamic Bisection with PoC Mutation
Joseph Bursey, Christoph Sendner, Ardalan Amiri Sani, Zhiyun Qian
摘要
Once a Linux kernel bug is identified, the developers perform the difficult task of patching it. Triage tools such as Syz-bisect provide a form of root cause analysis called bisection, which systematically checks historical kernel commits for the presence of the bug until it determines the Bug-Introducing Commit (BiC). Unfortunately, Syz-bisect correctly identifies the BiC for only 35% of bugs. In order to improve Syz-bisect while remaining within its time and resource constraints, we identify three areas where Syz-bisect could be improved: bug deduplication, the use of all available PoCs, and PoC mutation. Our solution Meerkat is the first dynamic bisection tool to apply scalable PoC mutation, improving over Syz-bisect by 64%. Through an in-depth manual analysis of Meerkat's bisection results, we find that dynamic bisection is critically limited by bug detectors changing with kernel versions, changes near the buggy code, and unrelated bugs that block dynamic analysis. Based on the nature of these issues, we argue that Meerkat is approaching the practical limits of what is possible with dynamic bisection in the real world. Furthermore, we correct the ground truth for 13 bugs, thus improving the dataset for future research.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper29
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher 等NDSS 2016 · 被引用 1,021 次
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 被引用 836 次
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 被引用 616 次
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang 等USENIX Security 2018 · 被引用 537 次
- NEUZZ: Efficient Fuzzing with Neural Program SmoothingDongdong She, Kexin Pei, Dave Epstein, Junfeng Yang 等S&P 2019 · 被引用 220 次
相关 Paper
- SyzBridge: Bridging the Gap in Exploitability Assessment of Linux Kernel Bugs in the Linux EcosystemXiaochen Zou, Yu Hao, Zheng Zhang, Juefei Pu 等NDSS 2024
- SymBisect: Accurate Bisection for Fuzzer-Exposed VulnerabilitiesZheng Zhang, Yu Hao, Weiteng Chen, Xiaochen Zou 等USENIX Security 2024 · 被引用 7 次
- SyzDirect: Directed Greybox Fuzzing for Linux KernelXin Tan, Yuan Zhang, Jiadong Lu, Xin Xiong 等CCS 2023 · 被引用 25 次
- UBITect: a precise and scalable method to detect use-before-initialization bugs in Linux kernelYizhuo Zhai, Yu Hao, Hang Zhang, Daimeng Wang 等FSE 2020 · 被引用 34 次
- SemBIC: Semantic-Aware Identification of Bug-Inducing CommitsXiao Chen, Hengcheng Zhu, Jialun Cao, Ming Wen 等FSE 2025 · 被引用 1 次
