Taming compiler fuzzers

Taming compiler fuzzers
复制标题

DOI:
10.1145/2491956.2462173
复制
发表时间:
2013-06
期刊:
Proceedings of the 34th ACM SIGPLAN Conference on Programming Language Design and Implementation
影响因子:
--
通讯作者:
Yang Chen;Alex Groce;Chaoqiang Zhang;Weng-Keen Wong;Xiaoli Z. Fern;E. Eide;J. Regehr
Yang Chen;Alex Groce;Chaoqiang Zhang;Weng-Keen Wong;Xiaoli Z. Fern;E. Eide;J. Regehr
中科院分区:
其他
文献类型:
--
作者:
Yang Chen;Alex Groce;Chaoqiang Zhang;Weng-Keen Wong;Xiaoli Z. Fern;E. Eide;J. Regehr

文献摘要

被引文献

相似文献

咄咄逼人的随机测试工具("fuzzers")在查找编译器漏洞方面的效果令人印象深刻。例如,一个测试用例生成器就为一个 JavaScript 引擎报告了 1700 多个漏洞。不过,模糊器的使用也可能令人沮丧:它们会不加区分地反复发现一些可能还不够严重的错误,无法立即修复。目前,用户使用临时方法过滤掉不受欢迎的测试用例,例如在测试中禁止有问题的功能和对测试结果进行抓取。本文提出并解决了模糊器驯服问题:给定大量可能会触发故障的随机测试用例,对它们进行排序,使不同的、有趣的测试用例获得较高的排名。我们的评估结果表明,我们有能力解决模糊器驯服问题,在 C 编译器中解决了 3,799 个触发 46 个错误的测试用例,在 JavaScript 引擎中解决了 2,603 个触发 28 个错误的测试用例。
Aggressive random testing tools ("fuzzers") are impressively effective at finding compiler bugs. For example, a single test-case generator has resulted in more than 1,700 bugs reported for a single JavaScript engine. However, fuzzers can be frustrating to use: they indiscriminately and repeatedly find bugs that may not be severe enough to fix right away. Currently, users filter out undesirable test cases using ad hoc methods such as disallowing problematic features in tests and grepping test results. This paper formulates and addresses the fuzzer taming problem: given a potentially large number of random test cases that trigger failures, order them such that diverse, interesting test cases are highly ranked. Our evaluation shows our ability to solve the fuzzer taming problem for 3,799 test cases triggering 46 bugs in a C compiler and 2,603 test cases triggering 28 bugs in a JavaScript engine.