Automated Whitebox Fuzz Testing

Automated Whitebox Fuzz Testing
复制标题

DOI:
--
复制
发表时间:
2008
期刊:
--
影响因子:
--
通讯作者:
Patrice Godefroid;Michael Y. Levin;D. Molnar
Patrice Godefroid;Michael Y. Levin;D. Molnar
中科院分区:
其他
文献类型:
--
作者:
Patrice Godefroid;Michael Y. Levin;D. Molnar

文献摘要

被引文献

相似文献

模糊测试是一种发现软件安全漏洞的有效技术。传统上,模糊测试工具将随机突变应用于程序的格式良好的输入,并测试结果值。我们提出了一种替代的白盒模糊测试方法,灵感来自于符号执行和动态测试生成方面的最新进展。我们的方法在格式良好的输入上记录被测试程序的实际运行,以符号方式评估记录的跟踪,并收集对输入的约束,以捕获程序如何使用这些约束。然后,收集的约束被一个接一个地否定,并用约束求解器求解,产生在程序中执行不同控制路径的新输入。这个过程在代码覆盖率最大化的启发式方法的帮助下重复,旨在尽可能快地发现缺陷。我们已经在SAGE(Scalable,Automated,Guidted Execution)中实现了该算法,SAGE是一个使用x86指令级跟踪和仿真的新工具,用于对任意文件读取的Windows应用程序进行白盒模糊处理。我们描述了使动态测试生成扩展到大型输入文件和具有数亿条指令的长执行轨迹所需的关键优化。然后,我们给出了几个Windows应用程序的详细实验。值得注意的是,在没有任何格式特定知识的情况下,Sage检测到MS07-017 ANI漏洞,而大量的Blackbox Fuzing和静态分析工具没有发现该漏洞。此外,虽然Sage还处于开发的早期阶段,但它已经在大型Windows应用程序中发现了30多个新的错误,包括图像处理器、媒体播放器和文件解码器。其中几个错误可能是可利用的内存访问违规。
Fuzz testing is an effective technique for finding security vulnerabilities in software. Traditionally, fuzz testing tools apply random mutations to well-formed inputs of a program and test the resulting values. We present an alternative whitebox fuzz testing approach inspired by recent advances in symbolic execution and dynamic test generation. Our approach records an actual run of the program under test on a well-formed input, symbolically evaluates the recorded trace, and gathers constraints on inputs capturing how the program uses these. The collected constraints are then negated one by one and solved with a constraint solver, producing new inputs that exercise different control paths in the program. This process is repeated with the help of a code-coverage maximizing heuristic designed to find defects as fast as possible. We have implemented this algorithm in SAGE (Scalable, Automated, Guided Execution), a new tool employing x86 instruction-level tracing and emulation for whitebox fuzzing of arbitrary file-reading Windows applications. We describe key optimizations needed to make dynamic test generation scale to large input files and long execution traces with hundreds of millions of instructions. We then present detailed experiments with several Windows applications. Notably, without any format-specific knowledge, SAGE detects the MS07-017 ANI vulnerability, which was missed by extensive blackbox fuzzing and static analysis tools. Furthermore, while still in an early stage of development, SAGE has already discovered 30+ new bugs in large shipped Windows applications including image processors, media players, and file decoders. Several of these bugs are potentially exploitable memory access violations.