The Use of Likely Invariants as Feedback for Fuzzers

The Use of Likely Invariants as Feedback for Fuzzers
复制标题

DOI:
--
复制
发表时间:
2021
期刊:
--
影响因子:
--
通讯作者:
Andrea Fioraldi;Daniele Cono D'Elia;D. Balzarotti
Andrea Fioraldi;Daniele Cono D'Elia;D. Balzarotti
中科院分区:
其他
文献类型:
--
作者:
Andrea Fioraldi;Daniele Cono D'Elia;D. Balzarotti

文献摘要

被引文献

相似文献

虽然模糊测试被证明是一种非常有效的fi和软件错误的技术,但仍然存在开放的挑战。它的主要限制之一是,流行的覆盖制导设计经过优化,可以到达被测程序的不同部分,但当仅有可达性不足以触发漏洞时,它会很难实现。在现实中,许多错误需要特定的fic程序状态,该状态不仅涉及控制flow,而且还涉及一些程序变量的值。不幸的是,过去提出的捕获程序状态的替代探索策略在实践中几乎没有帮助,因为它们会立即导致状态爆炸。在本文中,我们提出了一种新的反馈机制,通过考虑程序变量之间的常见值和关系来扩大代码覆盖率。为此,我们在基本块级学习变量上的可能不变量,并相应地划分程序状态空间。我们的反馈可以区分输入何时违反一个或多个不变量并奖励它,从而恢复代码覆盖率通常提供的程序状态近似值(fi)。我们在一个名为I NVS COV的原型中实现了我们的技术,该原型是在LLVM和AFL++之上开发的。我们的实验表明,对于使用纯代码覆盖反馈的Fuzzer,我们的方法可以发现更多不同的错误(fi)。此外,它们还导致在OSS-Fuzz上每天测试的一个库中发现了两个漏洞,并且在当时的最新版本中仍然存在。
While fuzz testing proved to be a very effective technique to find software bugs, open challenges still exist. One of the its main limitations is the fact that popular coverage-guided designs are optimized to reach different parts of the program under test, but struggle when reachability alone is insufficient to trigger a vulnerability. In reality, many bugs require a specific program state that involve not only the control flow, but also the values of some of the program variables. Unfortunately, alternative exploration strategies that have been proposed in the past to capture the program state are of little help in practice, as they immediately result in a state explosion. In this paper, we propose a new feedback mechanism that augments code coverage by taking into account the usual values and relationships among program variables. For this purpose, we learn likely invariants over variables at the basic-block level, and partition the program state space accordingly. Our feedback can distinguish when an input violates one or more invariants and reward it, thus refining the program state approximation that code coverage normally offers. We implemented our technique in a prototype called I NVS C OV , developed on top of LLVM and AFL ++ . Our experiments show that our approach can find more, and different, bugs with respect to fuzzers that use a pure code-coverage feedback. Furthermore, they led to the discovery of two vulnerabilities in a library tested daily on OSS-Fuzz, and still present at the time in its latest version.