An Empirical Study of OSS-Fuzz Bugs

An Empirical Study of OSS-Fuzz Bugs
复制标题

DOI:
10.1109/msr52588.2021.00026
复制
发表时间:
2021-03
期刊:
2021 IEEE/ACM 18th International Conference on Mining Software Repositories (MSR)
影响因子:
--
通讯作者:
Zhen Yu Ding;Claire Le Goues
Zhen Yu Ding;Claire Le Goues
中科院分区:
其他
文献类型:
--
作者:
Zhen Yu Ding;Claire Le Goues

文献摘要

相似文献

连续模糊测试是一种日益流行的自动化质量和安全保证技术。谷歌维护OSS-Fuzz:开源软件的连续模糊测试服务。我们对OSS-Fuzz进行了首次实证研究,分析了316个项目中发现的23907个bug。我们研究了模糊检测发现的故障的特征,这些故障的生命周期,以及随着时间的推移模糊检测活动的演变。我们发现OSS-Fuzz在快速发现错误方面通常是有效的,开发人员通常会快速修补它们。然而,零散的bug、超时和内存不足错误是有问题的,人们很少为安全漏洞提交cve,模糊测试活动经常表现出间断的平衡,开发人员可能会对发现的大量bug感到惊讶。我们的发现对未来的模糊化研究和实践具有启示意义。
Continuous fuzzing is an increasingly popular technique for automated quality and security assurance. Google maintains OSS-Fuzz: a continuous fuzzing service for open source software. We conduct the first empirical study of OSS-Fuzz, analyzing 23,907 bugs found in 316 projects. We examine the characteristics of fuzzer-found faults, the lifecycles of such faults, and the evolution of fuzzing campaigns over time. We find that OSS-Fuzz is often effective at quickly finding bugs, and developers are often quick to patch them. However, flaky bugs, timeouts, and out of memory errors are problematic, people rarely file CVEs for security vulnerabilities, and fuzzing campaigns often exhibit punctuated equilibria, where developers might be surprised by large spikes in bugs found. Our findings have implications on future fuzzing research and practice.