Regression Greybox Fuzzing

模糊测试 计算机科学 计算机安全
作者
Xiaogang Zhu,Marcel Böhme
出处
期刊:Computer and Communications Security
标识
DOI:10.1145/3460120.3484596
摘要

What you change is what you fuzz! In an empirical study of all fuzzer-generated bug reports in OSSFuzz, we found that four in every five bugs have been introduced by recent code changes. That is, 77% of 23k bugs are regressions. For a newly added project, there is usually an initial burst of new reports at 2-3 bugs per day. However, after that initial burst, and after weeding out most of the existing bugs, we still get a constant rate of 3-4 bug reports per week. The constant rate can only be explained by an increasing regression rate. Indeed, the probability that a reported bug is a regression (i.e., we could identify the bug-introducing commit) increases from 20% for the first bug to 92% after a few hundred bug reports. In this paper, we introduce regression greybox fuzzing (RGF) a fuzzing approach that focuses on code that has changed more recently or more often. However, for any active software project, it is impractical to fuzz sufficiently each code commit individually. Instead, we propose to fuzz all commits simultaneously, but code present in more (recent) commits with higher priority. We observe that most code is never changed and relatively old. So, we identify means to strengthen the signal from executed code-of-interest. We also extend the concept of power schedules to the bytes of a seed and introduce Ant Colony Optimization to assign more energy to those bytes which promise to generate more interesting inputs. Our large-scale fuzzing experiment demonstrates the validity of our main hypothesis and the efficiency of regression greybox fuzzing. We conducted our experiments in a reproducible manner within Fuzzbench, an extensible fuzzer evaluation platform. Our experiments involved 3+ CPU-years worth of fuzzing campaigns and 20 bugs in 15 open-source C programs available on OSSFuzz.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
酷炫的背包完成签到,获得积分10
刚刚
搜集达人应助111采纳,获得10
刚刚
学术发布了新的文献求助10
1秒前
科研通AI5应助逍遥解牛采纳,获得10
2秒前
jochimchan发布了新的文献求助10
3秒前
ze发布了新的文献求助10
3秒前
麻薯完成签到,获得积分10
3秒前
3秒前
姜酱酱酱完成签到,获得积分20
3秒前
冰魂应助wzllyt采纳,获得10
4秒前
阳光男孩发布了新的文献求助10
4秒前
boboking发布了新的文献求助10
4秒前
酷波er应助轻松的雨竹采纳,获得10
5秒前
烟花应助Yang采纳,获得10
5秒前
pluto应助葛力采纳,获得10
6秒前
舒适的晓山完成签到,获得积分10
6秒前
6秒前
7秒前
ruochenzu发布了新的文献求助10
7秒前
MISS完成签到,获得积分20
7秒前
哞哞完成签到,获得积分10
7秒前
7秒前
轻松小张给司徒文青的求助进行了留言
8秒前
wsj完成签到,获得积分20
8秒前
kekeji完成签到 ,获得积分10
8秒前
Ava应助无欲无求傻傻采纳,获得10
9秒前
椰子在长江送礼物应助666采纳,获得10
9秒前
开心的茗茗完成签到 ,获得积分10
9秒前
苹果完成签到,获得积分10
10秒前
你腿毛有点长完成签到,获得积分10
10秒前
科研通AI5应助鲤鱼采纳,获得10
10秒前
天蓬猪悟能完成签到,获得积分10
11秒前
11秒前
星辰大海应助Shinewei采纳,获得10
11秒前
wsj发布了新的文献求助10
12秒前
kylin发布了新的文献求助10
12秒前
12秒前
学术完成签到,获得积分20
12秒前
12秒前
静心404完成签到,获得积分10
14秒前
高分求助中
Les Mantodea de Guyane Insecta, Polyneoptera 2500
Encyclopedia of Geology (2nd Edition) 2000
One Man Talking: Selected Essays of Shao Xunmei, 1929–1939 (PDF!) 1000
Technologies supporting mass customization of apparel: A pilot project 450
Tip60 complex regulates eggshell formation and oviposition in the white-backed planthopper, providing effective targets for pest control 400
A Field Guide to the Amphibians and Reptiles of Madagascar - Frank Glaw and Miguel Vences - 3rd Edition 400
China Gadabouts: New Frontiers of Humanitarian Nursing, 1941–51 400
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 物理 生物化学 纳米技术 计算机科学 化学工程 内科学 复合材料 物理化学 电极 遗传学 量子力学 基因 冶金 催化作用
热门帖子
关注 科研通微信公众号,转发送积分 3786875
求助须知:如何正确求助?哪些是违规求助? 3332553
关于积分的说明 10256102
捐赠科研通 3047830
什么是DOI,文献DOI怎么找? 1672720
邀请新用户注册赠送积分活动 801534
科研通“疑难数据库(出版商)”最低求助积分说明 760271