GRIMOIRE: Synthesizing Structure while Fuzzing

GRIMOIRE: Synthesizing Structure while Fuzzing
复制标题

DOI:
--
复制
发表时间:
2019
期刊:
--
影响因子:
--
通讯作者:
Tim Blazytko;Cornelius Aschermann;Moritz Schlögel;A. Abbasi;Sergej Schumilo;Simon Wörner;Thorsten Holz
Tim Blazytko;Cornelius Aschermann;Moritz Schlögel;A. Abbasi;Sergej Schumilo;Simon Wörner;Thorsten Holz
中科院分区:
其他
文献类型:
--
作者:
Tim Blazytko;Cornelius Aschermann;Moritz Schlögel;A. Abbasi;Sergej Schumilo;Simon Wörner;Thorsten Holz

文献摘要

被引文献

相似文献

在过去的几年里,模糊化得到了研究界的极大关注。然而,大多数注意力都集中在没有专用解析阶段的程序上。在这种情况下,利用程序的输入结构的模糊器可以实现比传统模糊方法更高的代码覆盖率。这种覆盖率的提高是通过在应用程序的输入空间中应用大规模突变来实现的。然而,这种改进是以需要专家领域知识为代价的,因为这些模糊器依赖于结构输入规范(例如,例如,在一个实施例中,语法)。语法推理是一种可以为给定程序自动生成这种语法的技术,可以用来解决这个缺点。这种技术通常在预处理步骤中推断程序的语法,并且可能错过仅在正常模糊化期间稍后才发现的重要结构。在本文中,我们提出了GRIMOIRE的设计和实现,一个完全自动化的覆盖引导模糊,没有任何形式的人类互动或预配置的工作,但它仍然能够有效地测试程序,期望高度结构化的输入。我们通过在程序输入空间中使用类似语法的组合进行大规模突变来合成新的高度结构化的输入,而无需任何预处理步骤。我们的评估表明,GRIMOIRE优于其他coverageguided模糊模糊程序时,高度结构化的输入。此外,它改进了现有的基于语法的覆盖率指导模糊。使用GRIMOIRE,我们确定了19个不同的内存损坏错误在现实世界中的程序,并获得了11个新的CVE。
In the past few years, fuzzing has received significant attention from the research community. However, most of this attention was directed towards programs without a dedicated parsing stage. In such cases, fuzzers which leverage the input structure of a program can achieve a significantly higher code coverage compared to traditional fuzzing approaches. This advancement in coverage is achieved by applying large-scale mutations in the application’s input space. However, this improvement comes at the cost of requiring expert domain knowledge, as these fuzzers depend on structure input specifications (e. g., grammars). Grammar inference, a technique which can automatically generate such grammars for a given program, can be used to address this shortcoming. Such techniques usually infer a program’s grammar in a pre-processing step and can miss important structures that are uncovered only later during normal fuzzing. In this paper, we present the design and implementation of GRIMOIRE, a fully automated coverage-guided fuzzer which works without any form of human interaction or preconfiguration; yet, it is still able to efficiently test programs that expect highly structured inputs. We achieve this by performing large-scale mutations in the program input space using grammar-like combinations to synthesize new highly structured inputs without any pre-processing step. Our evaluation shows that GRIMOIRE outperforms other coverageguided fuzzers when fuzzing programs with highly structured inputs. Furthermore, it improves upon existing grammarbased coverage-guided fuzzers. Using GRIMOIRE, we identified 19 distinct memory corruption bugs in real-world programs and obtained 11 new CVEs.