arrow
返回

VPGFuzz: Vulnerable Path-Guided Greybox Fuzzing

delete2025-01-01
delete0
PRE
AI
Z
Zhechao Lin
曹家豪 封面图
曹家豪 (Jiahao Cao)
X
Xinda Wang
R
Renjie Xie
Y
Yuxi Zhu
X
Xiao Li
李
李琦 (Qi Li)
王旸旸 封面图
王旸旸 (Yangyang Wang)
徐
徐明伟 (Mingwei Xu) *
DOI:10.1109/TIFS.2025.3607249delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Fuzzing is a prevalent technology for identifying software vulnerabilities. Existing fuzzing techniques predominantly focus on maximizing code coverage to unearth potential security issues. However, the mere expansion of explored code does not necessarily correlate with an increased discovery of vulnerabilities. Additionally, existing fuzzers often neglect comprehensive execution path information in code exploration. Consequently, potential vulnerabilities may be delayed or overlooked in the fuzzing process. To address this, we propose VPGFuzz, a vulnerable path-guided fuzzer that can not only explore new code but also exploit known vulnerability path knowledge for vulnerability discovery. It employs a vulnerable path recognition model to identify test cases with potentially vulnerable paths. This model is trained with various execution paths derived from real-world vulnerability PoCs (Proof of Concepts). Based on this model, VPGFuzz applies an explore-exploit seed selection strategy to effectively choose test cases for testing. Unlike traditional seed selection methods that maintain a single queue for exploring new code, this strategy includes a separate queue for retaining test cases identified as potentially vulnerable, allowing for more thorough testing. Experimental results demonstrate that VPGFuzz discovers 24 previously unknown vulnerabilities, with 18 receiving vulnerability identifiers from third-party organizations such as CVE. Our evaluation also shows VPGFuzz's superior efficiency by uncovering the first vulnerability approximately 1.2 to 70 times faster than popular fuzzers in most programs.
Keyword:
Greybox fuzzing
vulnerable path
recognition model
explore-exploit seed selection
Greybox fuzzing
vulnerable path
recognition model
explore-exploit seed selection

期刊

IEEE Transactions on Information Forensics and Security 封面图
IEEE Transactions on Information Forensics and Security
IF:
8
论文数:
5.3K
被引数:
2.3W

机构

T
Tsinghua University
学者数:
8.6K
论文数: 4.1K
被引数: 17.7W
U
university of texas system
学者数:
18.5W
论文数: 15.6W
被引数: 210
引用论文

引用论文

DeepHunter: a coverage-guided fuzz testing framework for deep neural networks
err2019-07-10
err0
errOAAI
errXiaofei Xie; Lei Ma; Felix Juefei-Xu; Minhui Xue; Hongxu Chen; Yang Liu; Jianjun Zhao; Bo Li; Jianxiong Yin; Simon See
err分享
err收藏
err分享
err收藏
Snipuzz: Black-box Fuzzing of IoT Firmware via Message Snippet Inference
err2021-11-13
err0
errOAAI
errXiaotao Feng; Ruoxi Sun; Xiaogang Zhu; Minhui Xue; Sheng Wen; Dongxi Liu; Surya Nepal; Yang Xiang
err分享
err收藏
LOKI: State-Aware Fuzzing Framework for the Implementation of Blockchain Consensus Protocols
err2023-01-01
err0
errOAAI
errFuchen Ma; Yuanliang Chen; Meng Ren; Yuanhang Zhou; Yu Jiang; Ting Chen; Huizhong Li; Jiaguang Sun
err分享
err收藏
err分享
err收藏
DeepXplore
err2017-10-14
err0
errOAAI
errKexin Pei; Yinzhi Cao; Junfeng Yang; Suman Jana
err分享
err收藏
What You Corrupt Is Not What You Crash: Challenges in Fuzzing Embedded Devices
err2018-01-01
err0
errOAAI
errMarius Muench; Jan Stijohann; Frank Kargl; Aurelien Francillon; Davide Balzarotti
err分享
err收藏
SAVIOR: Towards Bug-Driven Hybrid Testing救世主: 走向Bug驱动的混合测试
err2020-05-01
err0
errOAAI
errYaohui Chen; Peng Li; Jun Xu; Shengjian Guo; Rundong Zhou; Yulong Zhang; Tao Wei; Long Lu
err分享
err收藏
学者 查看更多内容