Regression Greybox Fuzzing

模糊测试 计算机科学 计算机安全
作者
Xiaogang Zhu,Marcel Böhme
出处
期刊:Computer and Communications Security
标识
DOI:10.1145/3460120.3484596
摘要

What you change is what you fuzz! In an empirical study of all fuzzer-generated bug reports in OSSFuzz, we found that four in every five bugs have been introduced by recent code changes. That is, 77% of 23k bugs are regressions. For a newly added project, there is usually an initial burst of new reports at 2-3 bugs per day. However, after that initial burst, and after weeding out most of the existing bugs, we still get a constant rate of 3-4 bug reports per week. The constant rate can only be explained by an increasing regression rate. Indeed, the probability that a reported bug is a regression (i.e., we could identify the bug-introducing commit) increases from 20% for the first bug to 92% after a few hundred bug reports. In this paper, we introduce regression greybox fuzzing (RGF) a fuzzing approach that focuses on code that has changed more recently or more often. However, for any active software project, it is impractical to fuzz sufficiently each code commit individually. Instead, we propose to fuzz all commits simultaneously, but code present in more (recent) commits with higher priority. We observe that most code is never changed and relatively old. So, we identify means to strengthen the signal from executed code-of-interest. We also extend the concept of power schedules to the bytes of a seed and introduce Ant Colony Optimization to assign more energy to those bytes which promise to generate more interesting inputs. Our large-scale fuzzing experiment demonstrates the validity of our main hypothesis and the efficiency of regression greybox fuzzing. We conducted our experiments in a reproducible manner within Fuzzbench, an extensible fuzzer evaluation platform. Our experiments involved 3+ CPU-years worth of fuzzing campaigns and 20 bugs in 15 open-source C programs available on OSSFuzz.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
0001发布了新的文献求助10
1秒前
jlw完成签到,获得积分10
1秒前
李健的小迷弟应助小番茄采纳,获得10
2秒前
3秒前
3秒前
5秒前
memory应助0001采纳,获得10
5秒前
淡淡从蕾发布了新的文献求助10
6秒前
狂野的河马完成签到,获得积分0
7秒前
7秒前
lumion11发布了新的文献求助10
7秒前
张明发布了新的文献求助10
7秒前
勤奋的松鼠完成签到,获得积分0
8秒前
背后的鹭洋完成签到,获得积分0
9秒前
淡淡的发卡完成签到,获得积分0
10秒前
暗黑同学完成签到,获得积分0
11秒前
负责戎发布了新的文献求助10
11秒前
mm完成签到 ,获得积分10
11秒前
顺顺当当完成签到 ,获得积分10
14秒前
JamesPei应助xiaoyu采纳,获得10
16秒前
落后的亦巧关注了科研通微信公众号
18秒前
19秒前
19秒前
流砂完成签到,获得积分10
20秒前
科研通AI2S应助书羽采纳,获得10
21秒前
张明完成签到,获得积分20
21秒前
清爽文博完成签到,获得积分10
22秒前
22秒前
24秒前
24秒前
27秒前
27秒前
坚定的芸发布了新的文献求助10
29秒前
六子完成签到,获得积分10
29秒前
SRsora完成签到,获得积分10
29秒前
30秒前
没烦恼完成签到,获得积分10
30秒前
FashionBoy应助八戒的梦想采纳,获得10
30秒前
韩恩轩完成签到,获得积分10
32秒前
xin_qin_Wei发布了新的文献求助10
33秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Development Across Adulthood 800
Chemistry and Physics of Carbon Volume 18 800
The Organometallic Chemistry of the Transition Metals 800
The formation of Australian attitudes towards China, 1918-1941 640
Signals, Systems, and Signal Processing 610
天津市智库成果选编 600
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6446005
求助须知:如何正确求助?哪些是违规求助? 8259491
关于积分的说明 17595287
捐赠科研通 5506679
什么是DOI,文献DOI怎么找? 2901860
邀请新用户注册赠送积分活动 1878867
关于科研通互助平台的介绍 1718946