返回
Fuzzing Configurations of Program Options
DOI:10.1145/3580597.png)
摘要
En 中文
While many real-world programs are shipped with configurations to enable/disable functionalities, fuzzers have mostly been applied to test single configurations of these programs. In this work, we first conduct an empirical study to understand how program configurations affect fuzzing performance. We find that limiting a campaign to a single configuration can result in failing to cover a significant amount of code. We also observe that different program configurations contribute differing amounts of code coverage, challenging the idea that each one can be efficiently fuzzed individually. Motivated by these two observations, we propose ConfigFuzz, which can fuzz configurations along with normal inputs. ConfigFuzz transforms the target program to encode its program options within part of the fuzzable input, so existing fuzzers' mutation operators can be reused to fuzz program configurations. We instantiate ConfigFuzz on six configurable, common fuzzing targets, and integrate their executions in FuzzBench. In our evaluation, ConfigFuzz outperforms two baseline fuzzers in four targets, while the results are mixed in the other targets due to program size and configuration space. We also analyze the options fuzzed by ConfigFuzz and how they affect the performance.
Keyword:
Fuzzing
command-line option configurations
期刊
A
IF:
6.2
论文数:
1.2K
被引数:
3.4K
机构
引用论文
Microscale forced combustion: Pyrolysis-combustion flow calorimetry (PCFC)微尺度强制燃烧: 热解-燃烧流量量热法 (PCFC)
Urachal inflammatory myofibroblastic tumor with ALK gene rearrangement: a study of urachal remnants
Urology
IF0
α-Taxilin Interacts with Sorting Nexin 4 and Participates in the Recycling Pathway of Transferrin ReceptorΑ-紫杉素与分选Nexin 4相互作用并参与转铁蛋白受体的循环途径
PLoS ONE
IF0

