DeepFuzz: Automatic Generation of Syntax Valid C Programs for Fuzz Testing

DeepFuzz: Automatic Generation of Syntax Valid C Programs for Fuzz Testing
复制标题

DOI:
10.1609/aaai.v33i01.33011044
复制
发表时间:
2019-07
期刊:
--
影响因子:
--
通讯作者:
Xiao Liu;Xiaoting Li;Rupesh Prajapati;Dinghao Wu
Xiao Liu;Xiaoting Li;Rupesh Prajapati;Dinghao Wu
中科院分区:
其他
文献类型:
--
作者:
Xiao Liu;Xiaoting Li;Rupesh Prajapati;Dinghao Wu

文献摘要

相似文献

编译器是构建软件的最基本的编程工具之一。然而,生产编译器仍然存在缺陷。模糊测试通常利用新生成的或突变的输入来发现新的错误或安全漏洞。在本文中,我们提出了一个基于语法的模糊工具DEEPFUZZ。基于生成式Sequence-to-Sequence模型,DEEPFUZZ自动连续地生成格式良好的C程序。我们使用这组新的C程序来模糊现成的C编译器,例如,GCC和Clang/LLVM。我们提出了一个详细的案例研究,分析的成功率和覆盖率的提高所产生的C程序的模糊测试。我们分析了DEEPFUZZ的性能与三种类型的采样方法以及三种类型的生成策略。因此,DEEPFUZZ在线路、功能和分支覆盖率方面提高了测试效率。在我们的初步研究中,我们发现并报告了GCC的8个bug,所有这些bug都正在被开发人员积极解决。
Compilers are among the most fundamental programming tools for building software. However, production compilers remain buggy. Fuzz testing is often leveraged with newlygenerated, or mutated inputs in order to find new bugs or security vulnerabilities. In this paper, we propose a grammarbased fuzzing tool called DEEPFUZZ. Based on a generative Sequence-to-Sequence model, DEEPFUZZ automatically and continuously generates well-formed C programs. We use this set of new C programs to fuzz off-the-shelf C compilers, e.g., GCC and Clang/LLVM. We present a detailed case study to analyze the success rate and coverage improvement of the generated C programs for fuzz testing. We analyze the performance of DEEPFUZZ with three types of sampling methods as well as three types of generation strategies. Consequently, DEEPFUZZ improved the testing efficacy in regards to the line, function, and branch coverage. In our preliminary study, we found and reported 8 bugs of GCC, all of which are actively being addressed by developers.