SoK: Prudent Evaluation Practices for Fuzzing

模糊测试 计算机科学 程序设计语言 软件
作者
Moritz Schloegel,Nils Bars,Nico Schiller,Lukas Bernhard,Tobias Scharnowski,Addison Crump,Arash Ale-Ebrahim,Nicolai Bissantz,Marius Muench,Thorsten Holz
标识
DOI:10.1109/sp54263.2024.00137
摘要

Fuzzing has proven to be a highly effective approach to uncover software bugs over the past decade.After AFL popularized the groundbreaking concept of lightweight coverage feedback, the field of fuzzing has seen a vast amount of scientific work proposing new techniques, improving methodological aspects of existing strategies, or porting existing methods to new domains.All such work must demonstrate its merit by showing its applicability to a problem, measuring its performance, and often showing its superiority over existing works in a thorough, empirical evaluation.Yet, fuzzing is highly sensitive to its target, environment, and circumstances, e. g., randomness in the testing process.After all, relying on randomness is one of the core principles of fuzzing, governing many aspects of a fuzzer's behavior.Combined with the often highly difficult to control environment, the reproducibility of experiments is a crucial concern and requires a prudent evaluation setup.To address these threats to validity, several works, most notably Evaluating Fuzz Testing by Klees et al., have outlined how a carefully designed evaluation setup should be implemented, but it remains unknown to what extent their recommendations have been adopted in practice.In this work, we systematically analyze the evaluation of 150 fuzzing papers published at the top venues between 2018 and 2023.We study how existing guidelines are implemented and observe potential shortcomings and pitfalls.We find a surprising disregard of the existing guidelines regarding statistical tests and systematic errors in fuzzing evaluations.For example, when investigating reported bugs, we find that the search for vulnerabilities in real-world software leads to authors requesting and receiving CVEs of questionable quality.Extending our literature analysis to the practical domain, we attempt to reproduce claims of eight fuzzing papers.These case studies allow us to assess the practical reproducibility of fuzzing research and identify archetypal pitfalls in the evaluation design.Unfortunately, our reproduced results reveal several deficiencies in the studied papers, and we are unable to fully support and reproduce the respective claims.To help the field of fuzzing move toward a scientifically reproducible evaluation strategy, we propose updated guidelines for conducting a fuzzing evaluation that future work should follow.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
贪玩半蕾完成签到,获得积分20
3秒前
4秒前
5秒前
顺利兰完成签到 ,获得积分10
6秒前
chennian应助YQQ采纳,获得10
7秒前
8秒前
JiayiMu完成签到 ,获得积分10
8秒前
11秒前
13秒前
很牛的ID完成签到,获得积分20
14秒前
小吃完成签到,获得积分10
16秒前
SCIfafafafa发布了新的文献求助10
17秒前
不爱科研的科研小菜鸡完成签到,获得积分20
17秒前
张颖完成签到 ,获得积分10
17秒前
aa发布了新的文献求助10
18秒前
pluto应助xxhhh采纳,获得10
18秒前
很牛的ID发布了新的文献求助20
18秒前
tengfei应助真实的静珊采纳,获得10
19秒前
19秒前
22秒前
保安队长发布了新的文献求助10
22秒前
xxx7749发布了新的文献求助10
25秒前
26秒前
超级诗桃发布了新的文献求助10
27秒前
科研小白发布了新的文献求助10
28秒前
wxy发布了新的文献求助10
30秒前
Lucas应助雪山飞龙采纳,获得10
31秒前
SZ完成签到,获得积分20
32秒前
PLN完成签到 ,获得积分20
33秒前
33秒前
34秒前
tjxhtj完成签到,获得积分10
34秒前
35秒前
luckytuantuan发布了新的文献求助10
36秒前
大模型应助123采纳,获得10
36秒前
qqy发布了新的文献求助10
37秒前
斯文天曼发布了新的文献求助10
38秒前
海心完成签到 ,获得积分10
40秒前
kk关闭了kk文献求助
40秒前
雪山飞龙完成签到,获得积分10
40秒前
高分求助中
【此为提示信息,请勿应助】请按要求发布求助,避免被关 20000
Technologies supporting mass customization of apparel: A pilot project 450
Mixing the elements of mass customisation 360
Периодизация спортивной тренировки. Общая теория и её практическое применение 310
the MD Anderson Surgical Oncology Manual, Seventh Edition 300
Nucleophilic substitution in azasydnone-modified dinitroanisoles 300
Political Ideologies Their Origins and Impact 13th Edition 260
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 物理 生物化学 纳米技术 计算机科学 化学工程 内科学 复合材料 物理化学 电极 遗传学 量子力学 基因 冶金 催化作用
热门帖子
关注 科研通微信公众号,转发送积分 3781475
求助须知:如何正确求助?哪些是违规求助? 3327071
关于积分的说明 10229393
捐赠科研通 3041969
什么是DOI,文献DOI怎么找? 1669742
邀请新用户注册赠送积分活动 799258
科研通“疑难数据库(出版商)”最低求助积分说明 758757