跳到主要导航 跳到搜索 跳到主要内容

SHFuzz: A hybrid fuzzing method assisted by static analysis for binary programs

  • Wenjie Wang
  • , Donghai Tian*
  • , Rui Ma
  • , Hang Wei
  • , Qianjin Ying
  • , Xiaoqi Jia
  • , Lei Zuo
  • *此作品的通讯作者
  • Beijing Institute of Technology
  • CAS - Institute of Information Engineering
  • University of Chinese Academy of Sciences
  • NSFOCUS Inc.

科研成果: 期刊稿件文章同行评审

摘要

Fuzzing is an effective technique to find security bugs in programs by quickly exploring the input space of programs. To further discover vulnerabilities hidden in deep execution paths, the hybrid fuzzing combines fuzzing and concolic execution for going through complex branch conditions. In general, we observe that the execution path which comes across more and complex basic blocks may have a higher chance of containing a security bug. Based on this observation, we propose a hybrid fuzzing method assisted by static analysis for binary programs. The basic idea of our method is to prioritize seed inputs according to the complexity of their associated execution paths. For this purpose, we utilize static analysis to evaluate the complexity of each basic block and employ the hardware trace mechanism to dynamically extract the execution path for calculating the seed inputs' weights. The key advantage of our method is that our system can test binary programs efficiently by using the hardware trace and hybrid fuzzing. To evaluate the effectiveness of our method, we design and implement a prototype system, namely SHFuzz. The evaluation results show SHFuzz discovers more unique crashes on several real-world applications and the LAVA-M dataset when compared to the previous solutions.

源语言英语
期刊论文编号9521142
页(从-至)1-16
页数16
期刊China Communications
18
8
DOI
出版状态已出版 - 8月 2021

学术指纹

探究 'SHFuzz: A hybrid fuzzing method assisted by static analysis for binary programs' 的科研主题。它们共同构成独一无二的学术指纹。

引用此