HotFuzz: Discovering Algorithmic Denial-of-Service Vulnerabilities Through Guided Micro-Fuzzing

HotFuzz: Discovering Algorithmic Denial-of-Service Vulnerabilities Through Guided Micro-Fuzzing
复制标题

DOI:
10.14722/ndss.2020.24415
复制
发表时间:
2020-02
期刊:
ArXiv
影响因子:
--
通讯作者:
William Blair;Andrea Mambretti;Sajjad Arshad;Michael Weissbacher;William K. Robertson;E. Kirda;Manuel Egele
William Blair;Andrea Mambretti;Sajjad Arshad;Michael Weissbacher;William K. Robertson;E. Kirda;Manuel Egele
中科院分区:
其他
文献类型:
--
作者:
William Blair;Andrea Mambretti;Sajjad Arshad;Michael Weissbacher;William K. Robertson;E. Kirda;Manuel Egele

文献摘要

被引文献

相似文献

当代模糊测试技术专注于识别允许对手实现远程代码执行或信息泄露的内存损坏漏洞。与此同时,作为拒绝服务攻击的常见攻击媒介的网络复杂性(AC)漏洞仍然是一个未充分研究的威胁。在本文中,我们提出了HotFuzz,一个自动发现Java库中的AC漏洞的框架。HotFuzz使用微模糊,这是一种遗传算法,可以进化任意Java对象,以触发测试方法的最坏情况性能。我们将小递归实例化(SRI)定义为一种技术,用于将表示为Java对象的种子输入导出到微模糊。在微模糊化之后,HotFuzz将触发AC漏洞的测试用例合成到Java程序中,并监视它们的执行,以便在模糊化框架之外再现漏洞。HotFuzz输出那些表现出高CPU利用率的程序,作为Java库中AC漏洞的见证。我们评估了HotFuzz在Java编译环境(JRE),Maven上100个最流行的Java库,以及DARPA网络安全空间和时间分析(STAC)计划中包含的挑战。我们通过比较微模糊与SRI的性能来评估SRI的有效性,通过检测到的AC漏洞的数量来衡量,简单地使用空值作为种子输入。在这次评估中,我们验证了已知的AC漏洞,发现了以前未知的AC漏洞,我们负责任地向供应商报告了这些漏洞,并得到了IBM和Oracle的确认。我们的研究结果表明,微模糊发现AC漏洞在现实世界的软件,和微模糊与SRI派生的种子输入优于使用空值。
Contemporary fuzz testing techniques focus on identifying memory corruption vulnerabilities that allow adversaries to achieve either remote code execution or information disclosure. Meanwhile, Algorithmic Complexity (AC)vulnerabilities, which are a common attack vector for denial-of-service attacks, remain an understudied threat. In this paper, we present HotFuzz, a framework for automatically discovering AC vulnerabilities in Java libraries. HotFuzz uses micro-fuzzing, a genetic algorithm that evolves arbitrary Java objects in order to trigger the worst-case performance for a method under test. We define Small Recursive Instantiation (SRI) as a technique to derive seed inputs represented as Java objects to micro-fuzzing. After micro-fuzzing, HotFuzz synthesizes test cases that triggered AC vulnerabilities into Java programs and monitors their execution in order to reproduce vulnerabilities outside the fuzzing framework. HotFuzz outputs those programs that exhibit high CPU utilization as witnesses for AC vulnerabilities in a Java library. We evaluate HotFuzz over the Java Runtime Environment (JRE), the 100 most popular Java libraries on Maven, and challenges contained in the DARPA Space and Time Analysis for Cybersecurity (STAC) program. We evaluate SRI's effectiveness by comparing the performance of micro-fuzzing with SRI, measured by the number of AC vulnerabilities detected, to simply using empty values as seed inputs. In this evaluation, we verified known AC vulnerabilities, discovered previously unknown AC vulnerabilities that we responsibly reported to vendors, and received confirmation from both IBM and Oracle. Our results demonstrate that micro-fuzzing finds AC vulnerabilities in real-world software, and that micro-fuzzing with SRI-derived seed inputs outperforms using empty values.