ODDFUZZ: Discovering Java Deserialization Vulnerabilities via Structure-Aware Directed Greybox Fuzzing

被引:0
|
作者
Cao, Sicong [1 ]
He, Biao [2 ]
Sun, Xiaobing [1 ]
Ouyang, Yu [2 ]
Zhang, Chao [3 ]
Wu, Xiaoxue [1 ]
Su, Ting [4 ]
Bo, Lili [1 ]
Li, Bin [1 ]
Ma, Chuanlei [2 ]
Li, Jiajia [2 ]
Wei, Tao [2 ]
机构
[1] Yangzhou University, China
[2] Ant Group, China
[3] Tsinghua University, China
[4] East China Normal University, China
来源
arXiv | 2023年
关键词
Engineering Village;
D O I
暂无
中图分类号
学科分类号
摘要
Analysis solution - Effectiveness and efficiencies - False negatives - False positive - Grey-box - Hybrid solution - Proof of concept - Seeds generation - Structure-aware - Test case
引用
收藏
相关论文
共 46 条
  • [1] ODDFUZZ: Discovering Java']Java Deserialization Vulnerabilities via Structure-Aware Directed Greybox Fuzzing
    Cao, Sicong
    He, Biao
    Sun, Xiaobing
    Ouyang, Yu
    Zhang, Chao
    Wu, Xiaoxue
    Su, Ting
    Bo, Lili
    Li, Bin
    Ma, Chuanlei
    Li, Jiajia
    Wei, Tao
    2023 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, SP, 2023, : 2726 - 2743
  • [2] ODDFuzz: Discovering Java Deserialization Vulnerabilities via Structure-Aware Directed Greybox Fuzzing
    Yangzhou University, China
    不详
    不详
    不详
    Proc. IEEE Symp. Secur. Privacy, (2726-2743):
  • [3] Predecessor-aware Directed Greybox Fuzzing
    Zhang, Yujian
    Liu, Yaokun
    Xu, Jinyu
    Wang, Yanhao
    45TH IEEE SYMPOSIUM ON SECURITY AND PRIVACY, SP 2024, 2024, : 1884 - 1900
  • [4] WasmCFuzz: Structure-aware Fuzzing for Wasm Compilers
    Zhang, Xiangwei
    Wang, Junjie
    Du, Xiaoning
    Liu, Shuang
    PROCEEDINGS 2024 IEEE/ACM 4TH INTERNATIONAL WORKSHOP ON ENGINEERING AND CYBERSECURITY OF CRITICAL SYSTEMS AND 2024 IEEE/ACM SECOND INTERNATIONAL WORKSHOP ON SOFTWARE VULNERABILITY, ENCYCRIS/SVM 2024, 2024, : 1 - 5
  • [5] SyzLego: Enhancing Kernel Directed Greybox Fuzzing via Dependency Inference and Scheduling
    Liao, Chengxiang
    Wang, Ruipeng
    Li, Yuwei
    Chen, Juxing
    Li, Yang
    Pan, Zulie
    INFORMATION SECURITY, PT I, ISC 2024, 2025, 15257 : 171 - 189
  • [6] Efficient ECU Analysis Technology Through Structure-Aware CAN Fuzzing
    Kim, Hyunghoon
    Jeong, Yeonseon
    Choi, Wonsuk
    Lee, Doon Hoon
    Jo, Hyo Jin
    IEEE ACCESS, 2022, 10 : 23259 - 23271
  • [7] Response Generation via Structure-Aware Constraints
    Guan, Mengyu
    Wang, Zhongqing
    Zhou, Guodong
    ACM TRANSACTIONS ON ASIAN AND LOW-RESOURCE LANGUAGE INFORMATION PROCESSING, 2022, 21 (06)
  • [8] Edge Repartitioning via Structure-Aware Group Migration
    Li, He
    Yuan, Hang
    Huang, Jianbin
    Ma, Xiaoke
    Cui, Jiangtao
    Yoo, Jaesoo
    IEEE TRANSACTIONS ON COMPUTATIONAL SOCIAL SYSTEMS, 2022, 9 (03): : 751 - 760
  • [9] Structure-Aware Surface Reconstruction via Primitive Assembly
    Jiang, Jingen
    Zhao, Mingyang
    Xin, Shiqing
    Yang, Yanchao
    Wang, Hanxiao
    Jia, Xiaohong
    Yan, Dong-Ming
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2023), 2023, : 14125 - 14134
  • [10] Parallel Pencil Drawing Stylization via Structure-Aware Optimization
    Chen, Zhihua
    Jin, Yuxi
    Sheng, Bin
    Li, Ping
    Sun, Hanqiu
    PROCEEDINGS OF THE 31ST INTERNATIONAL CONFERENCE ON COMPUTER ANIMATION AND SOCIAL AGENTS (CASA 2016), 2015, : 32 - 37