FREEDOM: Engineering a State-of-the-Art DOM Fuzzer

FREEDOM: Engineering a State-of-the-Art DOM Fuzzer
复制标题

DOI:
10.1145/3372297.3423340
复制
发表时间:
2020-10
期刊:
Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Wen Xu;Soyeon Park;Taesoo Kim
Wen Xu;Soyeon Park;Taesoo Kim
中科院分区:
其他
文献类型:
--
作者:
Wen Xu;Soyeon Park;Taesoo Kim

文献摘要

相似文献

Web 浏览器的 DOM 引擎是一个流行的攻击面,并且在其开发过程中已被彻底模糊。最新 DOM 模糊器采用的常见方法是基于上下文无关语法生成新输入。然而,这种生成方法无法捕获 DOM 引擎的输入(即 HTML 文档)中的数据依赖性。与此同时,目前还不清楚覆盖引导突变(众所周知,它可以有效地模糊众多软件)是否仍然对 DOM 引擎有效。更糟糕的是,现有的 DOM 模糊器无法采用覆盖引导的方法,因为它们无法完全支持 HTML 突变,并且浏览器吞吐量较低。为了科学地理解这两种方法的有效性和局限性,我们提出了 FreeDom,这是一种成熟的集群友好 DOM 模糊器,可与生成模式和覆盖引导模式一起使用。 FreeDom 依靠上下文感知的中间表示来描述具有适当数据依赖性的 HTML 文档。 FreeDom 还通过浏览器自我终止将吞吐量提高了 3.74 倍。 FreeDom 在 Safari、Firefox 和 Chrome 等商用浏览器中发现了 24 个以前未知的错误,迄今为止已分配了 10 个 CVE。通过上下文感知生成,FreeDom 在 WebKit 中发现的独特崩溃比最先进的 DOM 模糊器 Domato 多出 3 倍。以覆盖率为指导的 FreeDom 在揭示新代码​​块方面更有效 (2.62%),并发现了其生成方法无法发现的三个复杂错误。然而,使用空语料库引导的覆盖引导突变所引发的独特崩溃比生成方法少 3.8 倍。新披露的覆盖范围通常会对 DOM 模糊器在错误查找方面的有效性产生负面影响。因此,我们认为上下文感知生成是发现更多 DOM 引擎错误的最佳实践,并期望 FreeDom 促进的覆盖引导 DOM 模糊测试得到进一步改进。
The DOM engine of a web browser is a popular attack surface and has been thoroughly fuzzed during its development. A common approach adopted by the latest DOM fuzzers is to generate new inputs based on context-free grammars. However, such a generative approach fails to capture the data dependencies in the inputs of a DOM engine, namely, HTML documents. Meanwhile, it is unclear whether or not coverage-guided mutation, which is well-known to be effective in fuzzing numerous software, still remains to be effective against DOM engines. Worse yet, existing DOM fuzzers cannot adopt a coverage-guided approach because they are unable to fully support HTML mutation and suffer from low browser throughput. To scientifically understand the effectiveness and limitations of the two approaches, we propose FreeDom, a full-fledged cluster-friendly DOM fuzzer that works with both generative and coverage-guided modes. FreeDom relies on a context-aware intermediate representation to describe HTML documents with proper data dependencies. FreeDom also exhibits up to 3.74x higher throughput through browser self-termination. FreeDom has found 24 previously unknown bugs in commodity browsers including Safari, Firefox, and Chrome, and 10 CVEs has been assigned so far. With the context-aware generation, FreeDom finds 3x more unique crashes in WebKit than the state-of-the-art DOM fuzzer, Domato. FreeDom guided by coverage is more effective in revealing new code blocks (2.62%) and finds three complex bugs that its generative approach fails to find. However, coverage-guided mutation that bootstraps with an empty corpus triggers 3.8x fewer unique crashes than the generative approach. The newly revealed coverage, more often than not, negatively affects the effectiveness of DOM fuzzers in bug finding. Therefore, we consider context-aware generation the best practice to find more DOM engine bugs and expect further improvement on coverage-guided DOM fuzzing facilitated by FreeDom.