Semantic Crash Bucketing

Semantic Crash Bucketing
复制标题

DOI:
10.1145/3238147.3238200
复制
发表时间:
2018-09
期刊:
2018 33rd IEEE/ACM International Conference on Automated Software Engineering (ASE)
影响因子:
--
通讯作者:
Rijnard van Tonder;John Kotheimer;Claire Le Goues
Rijnard van Tonder;John Kotheimer;Claire Le Goues
中科院分区:
其他
文献类型:
--
作者:
Rijnard van Tonder;John Kotheimer;Claire Le Goues

文献摘要

相似文献

精确的碰撞分类对于自动化动态测试工具(例如模糊器)很重要。在大规模上,模糊产生了数百万个崩溃的输入。模糊器使用启发式方法,例如堆栈哈希(Hashes),以减少重复的错误报告。这些启发式方法很快,但通常不精确:即使重复数据删除,数百个唯一报告的崩溃仍然可以与同一错误相对应。必须手动检查剩余的撞车事故,并付出巨大的努力。在本文中,我们提出语义崩溃桶,这是一种通用方法,用于使用程序转换进行精确的崩溃存储桶。语义崩溃的贴图映射将输入撞到唯一错误,这是更改程序的函数(即语义三角洲)。我们观察到,真正的错误修复精确地标识了属于同一错误的崩溃。我们的见解是通过轻巧程序转换近似实际错误修复,以获得相同的精度。我们的方法使用(a)补丁模板和(b)程序中的语义反馈自动生成并为一般错误类应用近似修复程序。我们的评估表明,近似修复程序具有使用真实修复程序进行碰撞桶的竞争力,并且对于三种最先进的绒毛状态,大大优于内置的重复数据删除技术。
Precise crash triage is important for automated dynamic testing tools, like fuzzers. At scale, fuzzers produce millions of crashing inputs. Fuzzers use heuristics, like stack hashes, to cut down on duplicate bug reports. These heuristics are fast, but often imprecise: even after deduplication, hundreds of uniquely reported crashes can still correspond to the same bug. Remaining crashes must be inspected manually, incurring considerable effort. In this paper we present Semantic Crash Bucketing, a generic method for precise crash bucketing using program transformation. Semantic Crash Bucketing maps crashing inputs to unique bugs as a function of changing a program (i.e., a semantic delta). We observe that a real bug fix precisely identifies crashes belonging to the same bug. Our insight is to approximate real bug fixes with lightweight program transformation to obtain the same level of precision. Our approach uses (a) patch templates and (b) semantic feedback from the program to automatically generate and apply approximate fixes for general bug classes. Our evaluation shows that approximate fixes are competitive with using true fixes for crash bucketing, and significantly outperforms built-in deduplication techniques for three state of the art fuzzers.