POLYFUZZ: Holistic Greybox Fuzzing of Multi-Language Systems

被引:0
作者
Li, Wen [1 ]
Ruan, Jinyang [1 ]
Yi, Guangbei [1 ]
Cheng, Long [2 ]
Luo, Xiapu [3 ]
Cai, Haipeng [1 ]
机构
[1] Washington State Univ, Pullman, WA 99164 USA
[2] Clemson Univ, Clemson, SC 29631 USA
[3] Hong Kong Polytech Univ, Hong Kong, Peoples R China
来源
PROCEEDINGS OF THE 32ND USENIX SECURITY SYMPOSIUM | 2023年
基金
美国国家科学基金会;
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
While offering many advantages during software process, the practice of using multiple programming languages in constructing one software system also introduces additional security vulnerabilities in the resulting code. As this practice becomes increasingly prevalent, securing multi-language systems is of pressing criticality. Fuzzing has been a powerful security testing technique, yet existing fuzzers are commonly limited to single-language software. In this paper, we present POLYFUZZ, a greybox fuzzer that holistically fuzzes a given multi-language system through cross-language coverage feedback and explicit modeling of the semantic relationships between (various segments of) program inputs and branch predicates across languages. POLYFUZZ is extensible for supporting multilingual code written in different language combinations and has been implemented for C, Python, Java, and their combinations. We evaluated POLYFUZZ versus state-of-the-art single-language fuzzers for these languages as baselines against 15 real-world multi-language systems and 15 single-language benchmarks. POLYFUZZ achieved 25.3-52.3% higher code coverage and found 1-10 more bugs than the baselines against the multilingual programs, and even 10-20% higher coverage against the single-language benchmarks. In total, POLYFUZZ has enabled the discovery of 12 previously unknown multilingual vulnerabilities and 2 single-language ones, with 5 CVEs assigned. Our results show great promises of POLYFUZZ for cross-language fuzzing, while justifying the strong need for holistic fuzzing against trivially applying single-language fuzzers to multi-language software.
引用
收藏
页码:1379 / 1396
页数:18
相关论文
共 50 条
[21]   Perspectives to promote modularity, reusability, and consistency in multi-language systems [J].
Hyacinth Ali ;
Gunter Mussbacher ;
Jörg Kienzle .
Innovations in Systems and Software Engineering, 2022, 18 :5-37
[22]   Perspectives to promote modularity, reusability, and consistency in multi-language systems [J].
Ali, Hyacinth ;
Mussbacher, Gunter ;
Kienzle, Jorg .
INNOVATIONS IN SYSTEMS AND SOFTWARE ENGINEERING, 2022, 18 (01) :5-37
[23]   Towards an efficient simulation of multi-language descriptions of heterogeneous systems [J].
Dubois, Mathieu ;
Aboulhamid, El Mostapha ;
Rousseau, Frederic .
2006 IEEE ASIA PACIFIC CONFERENCE ON CIRCUITS AND SYSTEMS, 2006, :538-+
[24]   MULTI-LANGUAGE BLAS - A PROPOSAL [J].
AHARONIAN, G .
SIGPLAN NOTICES, 1985, 20 (11) :11-13
[25]   MULTI-LANGUAGE POETRY IN OSIRIS [J].
MELANCON, R .
LIBERTE, 1984, 26 (03) :167-167
[26]   Multi-Language Probabilistic Programming [J].
Stites, Sam ;
Li, John M. ;
Holtzen, Steven .
PROCEEDINGS OF THE ACM ON PROGRAMMING LANGUAGES-PACMPL, 2025, 9 (OOPSLA1)
[27]   Multi-Language Neural Network Language Models [J].
Ragni, Anton ;
Dakin, Edgar ;
Chen, Xie ;
Gales, Mark J. F. ;
Knill, Kate M. .
17TH ANNUAL CONFERENCE OF THE INTERNATIONAL SPEECH COMMUNICATION ASSOCIATION (INTERSPEECH 2016), VOLS 1-5: UNDERSTANDING SPEECH PROCESSING IN HUMANS AND MACHINES, 2016, :3042-3046
[28]   ANALYSIS OF THE DNN-BASED SRE SYSTEMS IN MULTI-LANGUAGE CONDITIONS [J].
Novotny, Ondrej ;
Matejka, Pavel ;
Glembek, Ondrej ;
Plchot, Oldrich ;
Grezl, Frantisek ;
Burget, Lukas ;
Cernocky, Jan .
2016 IEEE WORKSHOP ON SPOKEN LANGUAGE TECHNOLOGY (SLT 2016), 2016, :199-204
[29]   Multi-Language Online Handwriting Recognition [J].
Keysers, Daniel ;
Deselaers, Thomas ;
Rowley, Henry A. ;
Wang, Li-Lun ;
Carbune, Victor .
IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2017, 39 (06) :1180-1194
[30]   Realization of multi-language operating system [J].
Wang, Z.H. .
2001, Shanghai Computer Society (27)