Hopper: Interpretative Fuzzing for Libraries

Hopper: Interpretative Fuzzing for Libraries
复制标题

DOI:
10.1145/3576915.3616610
复制
发表时间:
2023-09
期刊:
Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Peng Chen;Yuxuan Xie;Yunlong Lyu;Yuxiao Wang;Hao Chen
Peng Chen;Yuxuan Xie;Yunlong Lyu;Yuxiao Wang;Hao Chen
中科院分区:
其他
文献类型:
--
作者:
Peng Chen;Yuxuan Xie;Yunlong Lyu;Yuxiao Wang;Hao Chen

文献摘要

相似文献

尽管最先进的模糊器可以有效地生成输入,但现有的模糊驱动程序仍无法充分覆盖库中的条目。这些模糊驱动程序中的大多数都是由开发人员手动制作的,它们的质量取决于开发人员对代码的理解。现有的作品试图通过从代码和执行跟踪中学习API使用来自动化模糊驱动程序的生成。但是,生成的绒毛驱动程序仅限于所学的代码,仅限于一些特定的调用序列。为了应对这些挑战,我们提出了霍珀,它可以无需任何领域知识来制作模糊驱动程序。它将图书馆模糊的问题转化为解释器模糊的问题。与正在测试的库相关的解释者可以解释描述任意API使用的输入。为了为解释器生成语义上正确的输入,Hopper了解了库中的内部和API限制,并以语法意识来突变程序。我们实施了料斗,并评估了其对11个现实世界图书馆的有效性,以针对手动制作的模糊和其他自动解决方案。我们的结果表明,霍珀(Hopper)在代码覆盖范围和错误查找中大大胜过其他模糊器,发现了其他模糊不清的25个未知的错误。此外,我们已经证明,所提出的内部和API间约束学习方法可以正确地学习图书馆所隐含的约束,因此可以显着提高模糊效率。实验结果表明,Hopper能够探索广泛的API用法,以使图书馆开箱即用。
Despite the fact that the state-of-the-art fuzzers can generate inputs efficiently, existing fuzz drivers still cannot adequately cover entries in libraries. Most of these fuzz drivers are crafted manually by developers, and their quality depends on the developers' understanding of the code. Existing works have attempted to automate the generation of fuzz drivers by learning API usage from code and execution traces. However, the generated fuzz drivers are limited to a few specific call sequences by the code being learned. To address these challenges, we present HOPPER, which can fuzz libraries without requiring any domain knowledge to craft fuzz drivers. It transforms the problem of library fuzzing into the problem of interpreter fuzzing. The interpreters linked against libraries under test can interpret the inputs that describe arbitrary API usage. To generate semantically correct inputs for the interpreter, HOPPER learns the intra-and inter-API constraints in the libraries and mutates the program with grammar awareness. We implemented HOPPER and evaluated its effectiveness on 11 real-world libraries against manually crafted fuzzers and other automatic solutions. Our results show that HOPPER greatly outperformed the other fuzzers in both code coverage and bug finding, having uncovered 25 previously unknown bugs that other fuzzers couldn't. Moreover, we have demonstrated that the proposed intra- and inter-API constraint learning methods can correctly learn constraints implied by the library and, therefore, significantly improve the fuzzing efficiency. The experiment results indicate that HOPPER is able to explore a vast range of API usages for library fuzzing out of the box.