arrow
返回

Fuzzing JavaScript engines with a syntax-aware neural program model

delete2024-09-01
delete1
PRE
AI
H
Haoran Xu
Y
Yongjun Wang *
Z
Zhiyuan Jiang
S
Shuhui Fan
S
Shaojing Fu
P
Peidai Xie
DOI:10.1016/j.cose.2024.103947delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Neural network language modeling has become a remarkable approach in the generation of test cases for fuzzing JavaScript engines. Fuzzers built upon neural language models offer several advantages. They obviate the need for manually developing code generation rules, enable the extraction of patterns from high -quality seed sets, and exhibit commendable portability. Nevertheless, existing works confront challenges in three key aspects: diminished language modeling performance attributable to extensive vocabularies, potential semantic errors within generated test cases, and the limitation of black -box fuzzing, which fails to leverage the internal feedback from the target engine. This paper proposes an innovative neural model -based grey -box fuzzing approach for JavaScript engines. We incorporate the context -free grammar of JavaScript into the neural language model to mitigate the challenges associated with extensive vocabularies, thereby enhancing the model's performance. Furthermore, to enhance the semantic validity of the generated test cases, we introduce semantic constraints into the mutation process. Notably, this work pioneers the integration of grey -box testing into a fuzzer built upon a neural language model, thereby enhancing the exploration of deep paths. Our prototype, PMFuzz, surpasses NNLMbased counterparts in both language modeling performance and test case generation capabilities. PMFuzz demonstrates a high level of competitiveness in exploring the software state space when compared to traditional coverage -guided grey -box fuzzers. In our evaluation, PMFuzz successfully identified 20 new defects within mainstream JS engines. Eight of them have been confirmed and fixed. Moreover, upon applying our method to C compilers, PMFuzz has revealed 11 new defects.
Keyword:
Fuzzing
JavaScript engines
Language model
Neural network
Grammar
Vocabulary

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

N
national university of defense technology - china
学者数:
1.8W
论文数: 1.4W
被引数: 9
引用论文

引用论文

Kimberlite Terminology and Classification金伯利岩术语和分类
err2013-07-12
err0
PREAI
errB. H. Scott Smith; T. E. Nowicki; J. K. Russell; K. J. Webb; R. H. Mitchell; C. M. Hetman; M. Harder; E. M. W. Skinner; Jv. A. Robey
err分享
err收藏
The Art, Science, and Engineering of Fuzzing: A Survey模糊测试的艺术,科学和工程: 一项调查
err2021-11-01
err306
errOAAI
errManes, Valentin J. M.; Han, HyungSeok; Han, Choongwoo; Cha, Sang Kil; Egele, Manuel; Schwartz, Edward J.; Woo, Maverick
err分享
err收藏
err
IF0
err
err0
PREAI
err
err分享
err收藏
Evaluation of Cardioprotective Effect of 3,5,3′-Tri-iodo-L-thyronine in Isoproterenol-Induced Cardiotoxicity
err2011-01-01
err0
errOAAI
errVinay Mishra; Priya Ghumatkar; Maulik V. Patel; Shilpesh Devada; Ramchandra Ranvir; Prabodha Swain; Rajesh Sundar; Rajesh Bahekar; Mukul R. Jain
err分享
err收藏
Refractory sarcoidosis-like systemic granulomatosis responding to ruxolitinib
err2019-11-01
err0
PREAI
errMichael Levraut; Nihal Martis; Philippe Viau; Felipe Suarez; Viviane Queyrel
err分享
err收藏
学者 查看更多内容