Graphuzz: Data-driven Seed Scheduling for Coverage-guided Greybox Fuzzing

被引:0
|
作者
Xu, Hang [1 ]
Chen, Liheng [2 ]
Gan, Shuitao [3 ]
Zhang, Chao [3 ]
Li, Zheming [3 ]
Ji, Jiangan [4 ]
Chen, Baojian [2 ]
Hu, Fan [1 ]
机构
[1] Minist Educ, Key Lab Cyberspace Secur, Zhengzhou, Henan, Peoples R China
[2] Univ Chinese Acad Sci, Beijing, Peoples R China
[3] Tsinghua Univ, Beijing, Peoples R China
[4] Informat Engn Univ, Zhengzhou, Peoples R China
关键词
Fuzzing; seed scheduling; graph neural network;
D O I
10.1145/3664603
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Seed scheduling is a critical step of greybox fuzzing, which assigns different weights to seed test cases during seed selection, and significantly impacts the efficiency of fuzzing. Existing seed scheduling strategies rely on manually designed models to estimate the potentials of seeds and determine their weights, which fails to capture the rich information of a seed and its execution and thus the estimation of seeds' potentials is not optimal. In this article, we introduce a new seed scheduling solution, Graphuzz, for coverage-guided greybox fuzzing, which utilizes deep learning models to estimate the potentials of seeds and works in a data-driven way. Specifically, we propose an extended control flow graph called e-CFG to represent the control-flow and data-flow features of a seed's execution, which is suitable for graph neural networks (GNN) to process and estimate seeds' potential. We evaluate each seed's code coverage increment and use it as the label to train the GNN model. Further, we propose a self-attention mechanism to enhance the GNN model so that it can capture overlooked features. We have implemented a prototype of Graphuzz based on the baseline fuzzer AFLplusplus. The evaluation results show that our model can estimate the potential of seeds and has the robust capability to generalize to different targets. Furthermore, the evaluation using 12 benchmarks from FuzzBench shows that Graphuzz outperforms AFLplusplus and the state-of-the-art seed scheduling solution K-Scheduler and other coverage-guided fuzzers in terms of code coverage, and the evaluation using 8 benchmarks from Magma shows that Graphuzz outperforms the baseline fuzzer AFLplusplus and SOTA solutions in terms of bug detection.
引用
收藏
页数:36
相关论文
共 50 条
  • [1] RumFuzz: Coverage-guided Greybox Fuzzing with Reasonable Use of Memory
    Xu, Jiangyun
    Wang, Jinbo
    Ma, Yunyun
    Li, Lu
    Jia, Chang
    2024 IEEE 24TH INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY, QRS, 2024, : 526 - 535
  • [2] A Novel Coverage-guided Greybox Fuzzing based on Power Schedule Optimization with Time Complexity
    Chen, Jinfu
    Wang, Shengran
    Cai, Saihua
    Zhang, Chi
    Chen, Haibo
    Chen, Jingyi
    Zhang, Jianming
    PROCEEDINGS OF THE 37TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING, ASE 2022, 2022,
  • [3] A Novel Coverage-Guided Greybox Fuzzing Method based on Grammar-Aware with Particle Swarm Optimization
    Wang, Shengran
    Chen, Jinfu
    Cai, Saihua
    Zhang, Chi
    Chen, Haibo
    2022 IEEE 22ND INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY, AND SECURITY COMPANION, QRS-C, 2022, : 780 - 781
  • [4] SPINALFUZZ: Coverage-Guided Fuzzing for SpinalHDL Designs
    Ruep, Katharina
    Grosse, Daniel
    2022 IEEE EUROPEAN TEST SYMPOSIUM (ETS 2022), 2022,
  • [5] REFuzz: A Remedy for Saturation in Coverage-Guided Fuzzing
    Lyu, Qian
    Zhang, Dalin
    Da, Rihan
    Zhang, Hailong
    ELECTRONICS, 2021, 10 (16)
  • [6] Coverage-guided Fuzzing for Feedforward Neural Networks
    Xie, Xiaofei
    Chen, Hongxu
    Li, Yi
    Ma, Lei
    Liu, Yang
    Zhao, Jianjun
    34TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING (ASE 2019), 2019, : 1162 - 1165
  • [7] Alphuzz: Monte Carlo Search on Seed-Mutation Tree for Coverage-Guided Fuzzing
    Zhao, Yiru
    Wang, Xiaoke
    Zhao, Lei
    Cheng, Yueqiang
    Yin, Heng
    PROCEEDINGS OF THE 38TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2022, 2022, : 534 - 547
  • [8] A Seed Scheduling Method With a Reinforcement Learning for a Coverage Guided Fuzzing
    Choi, Gyeongtaek
    Jeon, Seungho
    Cho, Jaeik
    Moon, Jongsub
    IEEE ACCESS, 2023, 11 : 2048 - 2057
  • [9] RIFF: Reduced Instruction Footprint for Coverage-Guided Fuzzing
    Wang, Mingzhe
    Liang, Jie
    Zhou, Chijin
    Jiang, Yu
    Wang, Rui
    Sun, Chengnian
    Sun, Jiaguang
    PROCEEDINGS OF THE 2021 USENIX ANNUAL TECHNICAL CONFERENCE, 2021, : 147 - 159
  • [10] FOX: Coverage-guided Fuzzing as Online Stochastic Control
    She, Dongdong
    Storek, Adam
    Xie, Yuchong
    Kweon, Seoyoung
    Srivastava, Prashast
    Jana, Suman
    2024 IEEE/ACM INTERNATIONAL WORKSHOP ON SEARCH-BASED AND FUZZ TESTING, SBFT 2024, 2024, : 57 - 58