跳到主要导航 跳到搜索 跳到主要内容

Sound Predictive Fuzzing for Multi-threaded Programs

  • Yuqi Guo
  • , Zheheng Liang
  • , Shihao Zhu
  • , Jinqiu Wang
  • , Zijiang Yang
  • , Wuqiang Shen
  • , Jinbo Zhang
  • , Yan Cai
  • University of Chinese Academy of Sciences
  • China Southern Power Grid

科研成果: 书/报告/会议事项章节会议稿件同行评审

2 引用 (Scopus)

摘要

Developing correct multi-threaded programs is challenging and concurrency bugs can be easily introduced. Many of them, known as concurrency vulnerabilities, can be exploited to launch attacks. Fuzzing is shown to be a practical and effective technique to expose vulnerabilities. However, existing works on fuzzing concurrency vulnerabilities almost all follow the framework (like AFL++) designed for fuzzing sequential vulnerabilities. Unlike sequential vulnerabilities, concurrency ones cannot be easily triggered. Concurrency vulnerabilities rely on both inputs and thread interleaving to be exposed while existing fuzzing techniques mainly focus on how to generate effective inputs. We present a new framework based on an existing fuzzing technique, AFL++, to integrate the predictive techniques for effective concurrency vulnerability detection. For every input (the original and the mutated ones), we call a predictive tool such that, even if a concurrency vulnerability is not really triggered, it can be predicted. To overcome heavy efficiency challenges existing in predictive tools, we propose to selectively call a predictive tool based on concurrency coverage criteria. We have selected a sound predictive tool SeqCheck and adapted it to propose our fuzzing framework PredFuzz. We compared our tool with two tools, AFL++ integrated with Google ThreadSanitizer and AFL++ directly integrated with SeqCheck, on six previously studied multi-threaded programs. The experimental results showed that PredFuzz detected significantly more vulnerabilities than AFL++ integrated with ThreadSanitizer and about 70% vulnerabilities detected by AFL++ directly integrated with SeqCheck. Besides, it is extremely efficient without compromising the fuzzing speed of AFL++: it added a smaller slowdown to AFL++ than ThreadSanitizer did and achieved a speedup of more than 1,000x when compared to AFL++ directly integrated with SeqCheck.

源语言英语
主期刊名Proceedings - 2023 IEEE 47th Annual Computers, Software, and Applications Conference, COMPSAC 2023
编辑Hossain Shahriar, Yuuichi Teranishi, Alfredo Cuzzocrea, Moushumi Sharmin, Dave Towey, AKM Jahangir Alam Majumder, Hiroki Kashiwazaki, Ji-Jiang Yang, Michiharu Takemoto, Nazmus Sakib, Ryohei Banno, Sheikh Iqbal Ahamed
出版商IEEE Computer Society
810-819
页数10
ISBN(电子版)9798350326970
DOI
出版状态已出版 - 2023
活动47th IEEE Annual Computers, Software, and Applications Conference, COMPSAC 2023 - Hybrid, Torino, 意大利
期限: 26 6月 202330 6月 2023

出版系列

姓名Proceedings - International Computer Software and Applications Conference
2023-June
ISSN(印刷版)0730-3157

会议

会议47th IEEE Annual Computers, Software, and Applications Conference, COMPSAC 2023
国家/地区意大利
Hybrid, Torino
时期26/06/2330/06/23

学术指纹

探究 'Sound Predictive Fuzzing for Multi-threaded Programs' 的科研主题。它们共同构成独一无二的指纹。

引用此