arrow
Return

PTfuzz: Guided Fuzzing With Processor Trace Feedback

delete2018-01-01
delete52
delete
OA
AI
G
Gen Zhang
X
Xu Zhou *
Y
Yingqi Luo
X
Xugang Wu
E
Erxue Min
DOI:10.1109/ACCESS.2018.2851237delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Greybox fuzzing, such as american fuzzy lop (AFL), is very efficient in finding software vulnerability, which makes it the state-of-the-art fuzzing technology. Greybox fuzzing leverages the branch information collected during program running as feedback to guide choosing seeds. Current greybox fuzzing generally uses two kinds of methods to collect branch information: compile-time instrumentation (AFL) and emulation [AFL extended with QEMU emulation (QAFL)]. Compile-time instrumentation is efficient, but it does not support binary programs. Meanwhile, emulation supports binary programs, but its efficiency is very low. In this paper, we propose a greybox fuzzing approach named PTfuzz, which leverages hardware mechanism (Intel Processor Trace) to collect branch information. Our approach supports binary programs, just like the emulation method, while it gains a comparable performance with the compile-time instrumentation method. Our experiments show that PTfuzz can fuzz the original binary programs without any modification, and we gain a 3 x performance improvement compared to QAFL.
Keywords:
Feedback
greybox fuzzing
Intel PT
software security
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.8W
Citations:
29.4W

Organization

N
national university of defense technology - china
Scholars:
1.8W
Papers: 1.4W
Citations: 9