Context-Sensitive and Directional Concurrency Fuzzing for Data-Race Detection

Context-Sensitive and Directional Concurrency Fuzzing for Data-Race Detection
复制标题

DOI:
10.14722/ndss.2022.24296
复制
发表时间:
2022
期刊:
Proceedings 2022 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Zu-Ming Jiang;Jia-Ju Bai;Kangjie Lu;Shih-Min Hu
Zu-Ming Jiang;Jia-Ju Bai;Kangjie Lu;Shih-Min Hu
中科院分区:
其他
文献类型:
--
作者:
Zu-Ming Jiang;Jia-Ju Bai;Kangjie Lu;Shih-Min Hu

文献摘要

被引文献

相似文献

Fuzzing技术是当今流行的漏洞检测和漏洞发现技术。为了解决数据竞争等并发问题,最近的并发模糊方法考虑了程序执行的并发信息,并通过影响运行时的线程调度来探索线程交织。然而,这些方法仍然局限于数据竞争检测。一方面,它们没有考虑线程交织的执行上下文,这可能会错过特定运行时上下文中的真实的数据竞争。另一方面,它们执行随机的线程交织探索,这频繁地重复已经覆盖的线程交织,并且错过许多不频繁的线程交织。在本文中,我们开发了一个新的并发模糊框架命名为C ONZZER,有效地探索线程交织和检测难以发现的数据竞争。C ONZZER的核心是一种用于线程交织探索的上下文敏感和定向并发模糊方法,具有两种新技术。首先,为了保证上下文敏感性,我们提出了一个新的并发覆盖度量,并发调用对,来描述线程与运行时调用上下文的交织。第二,定向探索线程交织,我们提出了一个邻接定向突变生成新的可能的线程交织与已经覆盖的线程交织,然后使用断点控制方法,试图在运行时实际覆盖它们。通过这两种技术,这种并发模糊方法可以有效地覆盖具有具体上下文信息的不频繁线程交织,以帮助发现难以发现的数据竞争。我们在8个用户级应用程序和4个内核级文件系统上对C ONZZER进行了评估,发现了95个真实的数据竞争。我们确定其中75个数据竞赛是有害的,并将其发送给相关开发人员,其中44个已经得到确认。我们还将C ONZZER与现有的模糊工具进行了比较,C ONZZER不断探索更多的线程交织,并发现了许多
—Fuzzing is popular for bug detection and vulner- ability discovery nowadays. To adopt fuzzing for concurrency problems like data races, several recent concurrency fuzzing ap- proaches consider concurrency information of program execution, and explore thread interleavings by affecting thread scheduling at runtime. However, these approaches are still limited in data-race detection. On the one hand, they fail to consider the execution contexts of thread interleavings, which can miss real data races in specific runtime contexts. On the other hand, they perform random thread-interleaving exploration, which frequently repeats already covered thread interleavings and misses many infrequent thread interleavings. In this paper, we develop a novel concurrency fuzzing frame- work named C ONZZER , to effectively explore thread interleavings and detect hard-to-find data races. The core of C ONZZER is a context-sensitive and directional concurrency fuzzing approach for thread-interleaving exploration, with two new techniques. First, to ensure context sensitivity, we propose a new concurrency-coverage metric, concurrent call pair , to describe thread inter- leavings with runtime calling contexts. Second, to directionally explore thread interleavings, we propose an adjacency-directed mutation to generate new possible thread interleavings with already covered thread interleavings and then use a breakpoint- control method to attempt to actually cover them at runtime. With these two techniques, this concurrency fuzzing approach can effectively cover infrequent thread interleavings with concrete context information, to help discover hard-to-find data races. We have evaluated C ONZZER on 8 user-level applications and 4 kernel-level filesystems, and found 95 real data races. We identify 75 of these data races to be harmful and send them to related developers, and 44 have been confirmed. We also compare C ONZZER to existing fuzzing tools, and C ONZZER continuously explores more thread interleavings and finds many