跳到主要导航 跳到搜索 跳到主要内容

Typestate-guided fuzzer for discovering use-after-free vulnerabilities

  • Haijun Wang
  • , Xiaofei Xie
  • , Yi Li
  • , Cheng Wen
  • , Yuekang Li
  • , Yang Liu
  • , Shengchao Qin
  • , Hongxu Chen
  • , Yulei Sui
  • Shenzhen University
  • Nanyang Technological University
  • Teesside University
  • University of Technology Sydney

科研成果: 书/报告/会议事项章节会议稿件同行评审

126 引用 (Scopus)

摘要

Existing coverage-based fuzzers usually use the individual control flow graph (CFG) edge coverage to guide the fuzzing process, which has shown great potential in finding vulnerabilities. However, CFG edge coverage is not effective in discovering vulnerabilities such as use-after-free (UaF). This is because, to trigger UaF vulnerabilities, one needs not only to cover individual edges, but also to traverse some (long) sequence of edges in a particular order, which is challenging for existing fuzzers. To this end, we propose to model UaF vulnerabilities as typestate properties, and develop a typestateguided fuzzer, named UAFL, for discovering vulnerabilities violating typestate properties. Given a typestate property, we first perform a static typestate analysis to find operation sequences potentially violating the property. Our fuzzing process is then guided by the operation sequences in order to progressively generate test cases triggering property violations. In addition, we also employ an information flow analysis to improve the efficiency of the fuzzing process. We have performed a thorough evaluation of UAFL on 14 widely-used real-world programs. The experiment results show that UAFL substantially outperforms the state-of-the-art fuzzers, including AFL, AFLFast, FairFuzz, MOpt, Angora and QSYM, in terms of the time taken to discover vulnerabilities. We have discovered 10 previously unknown vulnerabilities, and received 5 new CVEs.

源语言英语
主期刊名Proceedings - 2020 ACM/IEEE 42nd International Conference on Software Engineering, ICSE 2020
出版商IEEE Computer Society
999-1010
页数12
ISBN(电子版)9781450371216
DOI
出版状态已出版 - 27 6月 2020
已对外发布
活动42nd ACM/IEEE International Conference on Software Engineering, ICSE 2020 - Virtual, Online, 韩国
期限: 27 6月 202019 7月 2020

出版系列

姓名Proceedings - International Conference on Software Engineering
ISSN(印刷版)0270-5257

会议

会议42nd ACM/IEEE International Conference on Software Engineering, ICSE 2020
国家/地区韩国
Virtual, Online
时期27/06/2019/07/20

学术指纹

探究 'Typestate-guided fuzzer for discovering use-after-free vulnerabilities' 的科研主题。它们共同构成独一无二的指纹。

引用此