课题基金 / 基金详情

CAREER: Efficient Fuzzing with Neural Program Smoothing

CAREER: Efficient Fuzzing with Neural Program Smoothing
职业:通过神经程序平滑进行高效模糊测试
批准号:
1845995
负责人:
Suman Jana
金额:
$47.6万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-05-01 至 2024-04-30

项目摘要

项目成果

Suman Jana的其他基金

相似基金

相关文献

中文摘要
翻译
模糊是一种自动化软件测试技术,它涉及将无效、意外或罕见的数据流作为输入输入到计算机程序中,以发现导致崩溃、断言失败或内存损坏的错误。模糊是发现软件漏洞的事实上的标准技术。然而,尽管它们有着巨大的前景,但流行的模糊器,特别是对于大型程序,往往会在尝试多余的测试输入时陷入困境,并且很难找到隐藏在程序逻辑中的安全漏洞。为了找到有趣的测试输入,大多数流行的模糊器使用进化算法,该算法从一组输入开始,对这些输入应用随机突变和交叉以生成新输入,并应用适应度函数(例如,实现的代码覆盖率)为下一组突变选择最有希望的新输入。这项研究的关键见解是,通过更有效地利用底层函数的结构(例如,梯度或更高阶导数),使用连续优化技术的方法可以做得更好。这种方法的主要优点是,连续的梯度引导优化可以有效地生成新的有希望的输入,并基于梯度值和步长的一些目标突变,而不是进化技术中使用的随机无指导突变。已有研究表明,在神经网络训练等流行任务中,梯度引导优化技术的表现明显优于进化技术。更好的模糊器将显著提高全球数十亿用户使用的关键基础设施软件的安全性、可靠性和健壮性。数据和工具将通过开放源码提供。将制定课程和培训以传播结果。该项目将开发一套新颖的技术和工具,使模糊者能够充分利用梯度下降等连续优化技术的力量。将连续优化应用于模糊背后的关键挑战之一是,现实世界的程序行为通常包含许多不连续,因此不直接服从平滑优化。因此,在进行连续优化之前,必须对目标程序进行平滑。该项目将开发一种涉及代理神经网络和灰盒工具的新技术,该技术将自动学习不连续程序行为的平滑近似。该项目将进一步使用分支定界和割平面算法等全局优化方案,以避免由于目标程序的非凸性而陷入局部最优。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Fuzzing is an automated software testing technique that involves feeding a stream of invalid, unexpected, or rare data as inputs to a computer program for discovering bugs leading to crashes, assertion failures, or memory corruption. Fuzzing is the de facto standard technique for finding software vulnerabilities. However, despite their tremendous promise, popular fuzzers, especially for large programs, often tend to get stuck trying redundant test inputs and struggle to find security vulnerabilities hidden deep into the program logic. To find interesting test inputs, most popular fuzzers use evolutionary algorithms, which start from a set of inputs, apply random mutations and crossovers on these inputs to generate new inputs, and apply a fitness function (e.g., achieved code coverage) to select the most promising new inputs for the next set of mutations. The key insight of this research is that an approach using continuous optimization techniques can do better, by more efficiently using the structure of the underlying functions (e.g., gradients or higher-order derivatives). The key benefit of this approach is that continuous gradient-guided optimization can efficiently generate new promising inputs with a few targeted mutations based on the gradient value and the step size rather than random unguided mutations used in evolutionary techniques. Gradient-guided optimizations have already been shown to significantly outperform evolutionary techniques in popular tasks like training of neural networks. Better fuzzers will significantly improve the security, reliability, and robustness of critical infrastructure software used by billions of users across the world. Data and tools will be made available through open source. Curriculum and training will be developed to disseminate the results. This project will develop a set of novel techniques and tools that will enable fuzzers to fully exploit the power of continuous optimization techniques like gradient descent. One of the key challenges behind applying continuous optimization for fuzzing is that real-world program behaviors often contain many discontinuities and thus are not directly amenable to smooth optimization. Therefore, the target programs must be smoothed before performing continuous optimization. This project will develop a new technique involving surrogate neural networks and graybox instrumentation that will automatically learn smooth approximations of discontinuous program behaviors. This project will further use global optimization schemes like branch-and-bound and cutting plane algorithms to avoid getting stuck at local optima due to the non-convexity of the target program.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SaTC: CORE: Small: Machine Learning for Cybersecurity: Robustness Against Concept Drift
  • 批准号:
    2154874
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $30.0万
  • 财政年份:
    2022
  • 负责人:
    Suman Jana
  • 依托单位:
SaTC: CORE: Medium: Collaborative: Towards Trustworthy Deep Neural Network Based AI: A Systems Approach
  • 批准号:
    1801426
  • 项目类别:
    Standard Grant
  • 资助金额:
    $30.0万
  • 财政年份:
    2018
  • 负责人:
    Suman Jana
  • 依托单位:
TWC: Small: Collaborative: Automated Detection and Repair of Error Handling Bugs in SSL/TLS Implementations
  • 批准号:
    1617670
  • 项目类别:
    Standard Grant
  • 资助金额:
    $25.0万
  • 财政年份:
    2016
  • 负责人:
    Suman Jana
  • 依托单位:
海外基金