AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
Article Link
Collect
Submit Manuscript
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Regular Paper

Vulnerable Region-Aware Greybox Fuzzing

State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing 210023, China
School of Information Management, Nanjing University, Nanjing 210023, China
Department of Computer Science, University of Georgia, Athens, GA 30602, U.S.A.
College of Information Sciences and Technology, Pennsylvania State University, State College, PA 16802, U.S.A.

Invited from Xia Peisu Forum 2020

Show Author Information

Abstract

Fuzzing is known to be one of the most effective techniques to uncover security vulnerabilities of large-scale software systems. During fuzzing, it is crucial to distribute the fuzzing resource appropriately so as to achieve the best fuzzing performance under a limited budget. Existing distribution strategies of American Fuzzy Lop (AFL) based greybox fuzzing focus on increasing coverage blindly without considering the metrics of code regions, thus lacking the insight regarding which region is more likely to be vulnerable and deserves more fuzzing resources. We tackle the above drawback by proposing a vulnerable region-aware greybox fuzzing approach. Specifically, we distribute more fuzzing resources towards regions that are more likely to be vulnerable based on four kinds of code metrics. We implemented the approach as an extension to AFL named RegionFuzz. Large-scale experimental evaluations validate the effectiveness and efficiency of RegionFuzz-11 new bugs including three new CVEs are successfully uncovered by RegionFuzz.

Electronic Supplementary Material

Download File(s)
jcst-36-5-1212-Highlights.pdf (1.1 MB)

References

【1】
【1】
 
 
Journal of Computer Science and Technology
Pages 1212-1228

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Situ L-Y, Zuo Z-Q, Guan L, et al. Vulnerable Region-Aware Greybox Fuzzing. Journal of Computer Science and Technology, 2021, 36(5): 1212-1228. https://doi.org/10.1007/s11390-021-1196-0

1058

Views

8

Crossref

5

Web of Science

7

Scopus

0

CSCD

Received: 03 December 2020
Accepted: 18 May 2021
Published: 30 September 2021
© Institute of Computing Technology, Chinese Academy of Sciences 2021