arrow
返回

CAMFuzz: Explainable Fuzzing with Local Interpretation

delete2022-09-01
delete2
delete
OA
AI
石
石骥 (Ji Shi)
W
Wei Zou
张
张超 (Chao Zhang) *
L
Lingxiao Tan
Y
Yanyan Zou
Y
Yue Peng
W
Wei Huo
DOI:10.1186/s42400-022-00116-xdelete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Grey-box fuzzing techniques have been widely used in software bug finding. In general, there are many decisions to make in the fuzzing process, including which code block in the target program should be explored first, which bytes of an input seed should be mutated to reach the target code block, and how to mutate the chosen input bytes. However, existing solutions usually rely on random exploration or certain heuristics to choose where and how to fuzz, which limits the efficiency of fuzzing. In this paper, we propose a novel solution CAMFuzz to guide the fuzzing process with explainable decisions in explainable artificial intelligence (XAI). First, we propose a dynamic weight adjustment algorithm, which considers both the difficulty of reaching a block and the number of unvisited blocks nearby, to find code blocks worthy to explore first. Second, we utilize a widely used local interpretation technique, i.e., class activation mapping (CAM), to recognize which part of an input seed should be mutated to reach a given target code block. Therefore, CAMFuzz can distinguish which part of code in the program is more important and which positions in the input file should be mutated first, in order to achieve a better code coverage and bug finding efficiency. Third, to further help the fuzzer increase fuzzing efficiency, we leverage a lightweight static program analysis to help the fuzzer identify magic values. We implement a prototype of CAMFuzz and evaluate it on 13 real-world programs (including 11 open source targets, 2 closed-source commercial products including a Microsoft component and Hancom Office) Results show that CAMFuzz outperforms state-of-the-art fuzzers in both code coverage and bug finding. To detail, CAMFuzz on average achieves 2.07x more bugs and 1.17x coverage improvements. In total, it found 19 previously unknown vulnerabilities, of which 6 have been assigned by CVE so far.
Keyword:
Fuzzing
Explainable artificial intelligence
Grey-box fuzzing

期刊

C
Cybersecurity
IF:
3.7
论文数:
589
被引数:
1.0K

机构

C
chinese academy of sciences
学者数:
56.7W
论文数: 45.0W
被引数: 704
引用论文

引用论文

Porphobilinogen synthesis
err1973-01-01
err0
PREAI
errG. W. Kenner; K. M. Smith; J. F. Unsworth
err分享
err收藏
Kimberlite Terminology and Classification金伯利岩术语和分类
err2013-07-12
err0
PREAI
errB. H. Scott Smith; T. E. Nowicki; J. K. Russell; K. J. Webb; R. H. Mitchell; C. M. Hetman; M. Harder; E. M. W. Skinner; Jv. A. Robey
err分享
err收藏
The Gut as a Source of Inflammation in Chronic Kidney Disease
err2015-05-09
err0
errOAAI
errWei Ling Lau; Kamyar Kalantar-Zadeh; Nosratola D. Vaziri
err分享
err收藏
err分享
err收藏
Extending and improving metagenomic taxonomic profiling with uncharacterized species with MetaPhlAn 4用MetaPhlAn 4扩展和改善未表征物种的宏基因组分类学概况
err
IF0
err2022-08-22
err0
PREAI
errAitor Blanco-Miguez; Francesco Beghini; Fabio Cumbo; Lauren J. McIver; Kelsey N. Thompson; Moreno Zolfo; Paolo Manghi; Leonard Dubois; Kun D. Huang; Andrew Maltez Thomas; Gianmarco Piccinno; Elisa Piperni; Michal Punčochář; Mireia Valles-Colomer; Adrian Tett; Francesca Giordano; Richard Davies; Jonathan Wolf; Sarah E. Berry; Tim D. Spector; Eric A. Franzosa; Edoardo Pasolli; Francesco Asnicar; Curtis Huttenhower; Nicola Segata
err分享
err收藏
学者 查看更多内容