AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
Article Link
Collect
Submit Manuscript
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Regular Paper

ovAFLow: Detecting Memory Corruption Bugs with Fuzzing-Based Taint Inference

College of Computer Science and Technology, National University of Defense Technology, Changsha 410073, China
Show Author Information

Abstract

Grey-box fuzzing is an effective technology to detect software vulnerabilities, such as memory corruption. Previous fuzzers in detecting memory corruption bugs either use heavy-weight analysis, or use techniques which are not customized for memory corruption detection. In this paper, we propose a novel memory bug guided fuzzer, ovAFLow. To begin with, we broaden the memory corruption targets where we frequently identify bugs. Next, ovAFLow utilizes light-weight and effective methods to build connections between the fuzzing inputs and these corruption targets. Based on the connection results, ovAFLow uses customized techniques to direct the fuzzing process closer to memory corruption. We evaluate ovAFLow against state-of-the-art fuzzers, including AFL (american fuzzy lop), AFLFast, FairFuzz, QSYM, Angora, TIFF, and TortoiseFuzz. The evaluation results show better vulnerability detection ability of ovAFLow, and the performance overhead is acceptable. Moreover, we identify 12 new memory corruption bugs and two CVEs (common vulnerability exposures) with the help of ovAFLow.

Electronic Supplementary Material

Download File(s)
jcst-37-2-405-Highlights.pdf (151.3 KB)

References

【1】
【1】
 
 
Journal of Computer Science and Technology
Pages 405-422

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Zhang G, Wang P-F, Yue T, et al. ovAFLow: Detecting Memory Corruption Bugs with Fuzzing-Based Taint Inference. Journal of Computer Science and Technology, 2022, 37(2): 405-422. https://doi.org/10.1007/s11390-021-1600-9

1265

Views

10

Crossref

9

Web of Science

11

Scopus

1

CSCD

Received: 21 May 2021
Accepted: 15 November 2021
Published: 31 March 2022
©Institute of Computing Technology, Chinese Academy of Sciences 2022