跳到主要导航 跳到搜索 跳到主要内容

Dodrio: Parallelizing Taint Analysis Based Fuzzing via Redundancy-Free Scheduling

  • Jie Liang
  • , Mingzhe Wang
  • , Chijin Zhou
  • , Zhiyong Wu
  • , Jianzhong Liu
  • , Yu Jiang*
  • *此作品的通讯作者
  • Tsinghua University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Taint analysis significantly enhances the capacity of fuzzing to navigate intricate constraints and delve into the state spaces of the target program. However, practical scenarios involving taint analysis based fuzzers with the common parallel mode still have limitations in terms of overall throughput. These limitations primarily stem from redundant taint analyses and mutations among different fuzzer instances. In this paper, we propose Dodrio, a framework that parallelizes taint analysis based fuzzing. The main idea is to schedule fuzzing tasks in a balanced way by exploiting real-time global state. It consists of two modules: real-time synchronization and load-balanced task dispatch. Real-time synchronization updates global states among all instances by utilizing dual global coverage bitmaps to reduce data race. Based on the global state, load-balanced task dispatch efficiently allocates different tasks to different instances, thereby minimizing redundant behaviors and maximizing the utilization of computing resources. We evaluated Dodrio on real-world programs both in Google’s fuzzer-test-suite and FuzzBench against AFL’s classical parallel mode, PAFL, and Ye’s PAFL on parallelizing two taint analysis based fuzzer FairFuzz and PATA. The results show that Dodrio achieved an average speedup of 123%–398% in covering basic blocks compared to others. Based on the speedup, Dodrio found 5%–16% more basic blocks. We also assessed the scalability of Dodrio. With the same resources, the coverage improvement increases from 4% to 35% when the number of instances in parallel (i.e., CPU cores) increases from 4 to 64, compared to the classical parallel mode.

源语言英语
主期刊名FSE Companion - Companion Proceedings of the 32nd ACM International Conference on the Foundations of Software Engineering
编辑Marcelo d�Amorim
出版商Association for Computing Machinery, Inc
244-254
页数11
ISBN(电子版)9798400706585
DOI
出版状态已出版 - 10 7月 2024
已对外发布
活动32nd ACM International Conference on the Foundations of Software Engineering, FSE Companion - Porto de Galinhas, 巴西
期限: 15 7月 202419 7月 2024

出版系列

姓名FSE Companion - Companion Proceedings of the 32nd ACM International Conference on the Foundations of Software Engineering

会议

会议32nd ACM International Conference on the Foundations of Software Engineering, FSE Companion
国家/地区巴西
Porto de Galinhas
时期15/07/2419/07/24

学术指纹

探究 'Dodrio: Parallelizing Taint Analysis Based Fuzzing via Redundancy-Free Scheduling' 的科研主题。它们共同构成独一无二的学术指纹。

引用此