跳到主要导航 跳到搜索 跳到主要内容

Daisy: Effective Fuzz Driver Synthesis with Object Usage Sequence Analysis

  • Mingrui Zhang
  • , Chijin Zhou
  • , Jianzhong Liu
  • , Mingzhe Wang
  • , Jie Liang
  • , Juan Zhu*
  • , Yu Jiang
  • *此作品的通讯作者
  • Tsinghua University
  • ShuiMuYuLin Co. Ltd
  • Hubei University of Arts and Science

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Fuzzing is increasingly used in industrial settings for vulnerability detection due to its scalability and effectiveness. Libraries require driver programs to feed the fuzzer-generated inputs into library-provided interfaces. Writing such drivers manually is tedious and error-prone, thus greatly hindering the widespread use of fuzzing in practical situations. Previous attempts at automatic driver synthesis perform static analysis on the libraries and their consumers. However, a lack of dynamic object usage information renders them ineffective at generating interface function calls with correct parameters and meaningful sequences. This severely limits fuzzing's bug-finding capabilities and can produce faulty drivers.In this paper, we propose Daisy, a driver synthesis framework, which extracts dynamic object usage sequences of library consumers to synthesize significantly more effective drivers. Daisy uses the following two steps to synthesize a fuzz driver for a library. First, it models each object's behaviors into an object usage sequence during the execution of its consumers. Next, it merges all the extracted sequences and constructs a series of interface calls with valid object usages based on the merged sequence. We implemented Daisy and evaluated its effectiveness on real-world libraries selected from both the Android Open Source Project (AOSP) and Google's FuzzBench. Daisy's synthesized drivers significantly outperform drivers produced by other state-of-the-art fuzz driver synthesizers. In addition, on applying Daisy to the latest versions of those extensively-fuzzed real-world libraries of the benchmark, e.g. libaom and freetype2, we also found 9 previously-unknown bugs with 3 CVEs assigned.

源语言英语
主期刊名Proceedings - 2023 IEEE/ACM 45th International Conference on Software Engineering
主期刊副标题Software Engineering in Practice, ICSE-SEIP 2023
出版商IEEE Computer Society
87-98
页数12
ISBN(电子版)9798350300376
DOI
出版状态已出版 - 20 9月 2023
已对外发布
活动45th IEEE/ACM International Conference on Software Engineering: Software Engineering in Practice, ICSE-SEIP 2023 - Melbourne, 澳大利亚
期限: 17 5月 202319 5月 2023

出版系列

姓名Proceedings - International Conference on Software Engineering
ISSN(印刷版)0270-5257

会议

会议45th IEEE/ACM International Conference on Software Engineering: Software Engineering in Practice, ICSE-SEIP 2023
国家/地区澳大利亚
Melbourne
时期17/05/2319/05/23

指纹

探究 'Daisy: Effective Fuzz Driver Synthesis with Object Usage Sequence Analysis' 的科研主题。它们共同构成独一无二的指纹。

引用此