TensileFuzz: facilitating seed input generation in fuzzing via string constraint solving
Xuwei Liu, Wei You, Zhuo Zhang, Xiangyu Zhang
摘要
Seed inputs are critical to the performance of mutation based fuzzers. Existing techniques make use of symbolic execution and gradient descent to generate seed inputs. However, these techniques are not particular suitable for input growth (i.e., making input longer and longer), a key step in seed input generation. Symbolic execution models very low level constraints and prefer fix-sized inputs whereas gradient descent only handles cases where path conditions are arithmetic functions of inputs. We observe that growing an input requires considering a number of relations: length, offset, and count, in which a field is the length of another field, the offset of another field, and the count of some pattern in another field, respective. String solver theory is particularly suitable for addressing these relations. We hence propose a novel technique called TensileFuzz, in which we identify input fields and denote them as string variables such that a seed input is the concatenation of these string variables. Additional padding string variables are inserted in between field variables. The aforementioned relations are reverse-engineered and lead to string constraints, solving which instantiates the padding variables and hence grows the input. Our technique also integrates linear regression and gradient descent to ensure the grown inputs satisfy path constraints that lead to path exploration. Our comparison with AFL, and a number of state-of-the-art fuzzers that have similar target applications, including Qsym, Angora, and SLF, shows that TensileFuzz substantially outperforms the others, by 39% - 98% in terms of path coverage.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Sedar: Obtaining High-Quality Seeds for DBMS Fuzzing via Cross-DBMS SQL TransferJingzhou Fu, Jie Liang, Zhiyong Wu, Yu JiangICSE 2024 · 被引用 10 次
- RFCAudit: AI Agent for Auditing Protocol Implementations Against RFC SpecificationsMingwei Zheng, Chengpeng Wang, Xuwei Liu, Jinyao Guo 等ASE 2025 · 被引用 5 次
- Fuzzing for CPS Mutation TestingJaekwon Lee, Enrico Viganò, Oscar Cornejo, Fabrizio Pastore 等ASE 2023 · 被引用 4 次
- FuzzInMem: Fuzzing Programs via In-memory StructuresXuwei Liu, Wei You, Yapeng Ye, Zhuo Zhang 等ICSE 2024 · 被引用 4 次
- Operand-Variation-Oriented Differential Analysis for Fuzzing Binding Calls in PDF ReadersSuyue Guo, Xinyu Wan, Wei You, Bin Liang 等ICSE 2023 · 被引用 2 次
它引用的顶会 Paper19
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 被引用 1,026 次
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher 等NDSS 2016 · 被引用 1,021 次
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 被引用 836 次
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei 等CCS 2018 · 被引用 753 次
- VUzzer: Application-aware Evolutionary FuzzingSanjay Rawat, Vivek Jain, Ashish Kumar, Lucian Cojocar 等NDSS 2017 · 被引用 700 次
相关 Paper
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 被引用 616 次
- Learning to Explore Paths for Symbolic ExecutionJingxuan He, Gishor Sivanrupan, Petar Tsankov, Martin T. VechevCCS 2021 · 被引用 39 次
- Rare Path Guided FuzzingSeemanta Saha, Laboni Sarker, Md Shafiuzzaman, Chaofan Shou 等ISSTA 2023 · 被引用 12 次
- Generator Solving for Symbolic ExecutionSiwei Wei, Yan CaiICSE 2026
- Path Transitions Tell More: Optimizing Fuzzing Schedules via Runtime Program StatesKunpeng Zhang, Xi Xiao, Xiaogang Zhu, Ruoxi Sun 等ICSE 2022 · 被引用 25 次
