Breaking Through Binaries: Compiler-quality Instrumentation for Better Binary-only Fuzzing

Breaking Through Binaries: Compiler-quality Instrumentation for Better Binary-only Fuzzing
复制标题

DOI:
--
复制
发表时间:
2021
影响因子:
2.9
通讯作者:
Stefan Nagy;A. Nguyen-Tuong;Jason Hiser;J. Davidson;Matthew Hicks
Stefan Nagy;A. Nguyen-Tuong;Jason Hiser;J. Davidson;Matthew Hicks
中科院分区:
工程技术3区
文献类型:
--
作者:
Stefan Nagy;A. Nguyen-Tuong;Jason Hiser;J. Davidson;Matthew Hicks

文献摘要

被引文献

相似文献

覆盖率引导模糊测试是最有效的软件安全测试技术之一。Fuzing采用两种形式之一:基于编译器的或仅二进制的,具体取决于源代码的可用性。虽然Fuzing社区通过性能和反馈增强的程序转换改进了基于编译器的Fuzing,但由于在二进制级别检测代码的语义和性能限制,只有二进制Fuzing落后。许多模糊用例都是纯二进制的(即封闭源代码)。因此,在不牺牲性能的情况下,将模糊增强程序转换应用于仅限二进制的模糊仍然是一个紧迫的挑战。本文研究了实现编译器质量的纯二进制模糊插装所需的属性。基于我们的发现,我们设计了Fibre:一个平台,用于将模糊增强程序转换应用于仅限二进制的目标-保持编译器级别的性能。我们在流行的Fuzzer AFL的实现中展示了Fibre的能力,包括五个编译器风格的模糊增强转换,并与领先的仅二进制模糊工具AFL-QEMU和AFL-DYNINST进行了评估。在LAVA-M和真实目标中,Fibre分别将崩溃查找和吞吐量分别提高了26-96%和37-131%;与AFL-Dyinst和AFLQEMU相比,吞吐量分别提高了48-78%和159-203%-同时保持了27%的编译器开销水平。我们还展示了Fibre支持不同大小(10K-100MB)、不同复杂性(100-1M基本块)、不同平台(Linux和Windows)和不同格式(例如,Strired和PIC)的现实世界中的开放和封闭源代码软件。
Coverage-guided fuzzing is one of the most effective software security testing techniques. Fuzzing takes on one of two forms: compiler-based or binary-only, depending on the availability of source code. While the fuzzing community has improved compiler-based fuzzing with performanceand feedback-enhancing program transformations, binaryonly fuzzing lags behind due to the semantic and performance limitations of instrumenting code at the binary level. Many fuzzing use cases are binary-only (i.e., closed source). Thus, applying fuzzing-enhancing program transformations to binary-only fuzzing—without sacrificing performance— remains a compelling challenge. This paper examines the properties required to achieve compiler-quality binary-only fuzzing instrumentation. Based on our findings, we design FIBRE: a platform for applying fuzzing-enhancing program transformation to binary-only targets—maintaining compiler-level performance. We showcase FIBRE’s capabilities in an implementation for the popular fuzzer AFL, including five compiler-style fuzzing-enhancing transformations, and evaluate it against the leading binaryonly fuzzing instrumenters AFL-QEMU and AFL-Dyninst. Across LAVA-M and real-world targets, FIBRE improves crash-finding by 26–96% and 37–131%; and throughput by 48–78% and 159–203% compared to AFL-Dyninst and AFLQEMU, respectively—while maintaining compiler-level of overhead of 27%. We also show that FIBRE supports realworld openand closed-source software of varying size (10K– 100MB), complexity (100–1M basic blocks), platform (Linux and Windows), and format (e.g., stripped and PIC).