A Directed Fuzzing Based on the Dynamic Symbolic Execution and Extended Program Behavior Model

Zhe Chen, Shize Guo, Damao Fu · 2012

This paper presents a new automated directed fuzzing technique. First, the behavior information is extracted from the original complex Control Flow Graph (CFG) by using the dynamic symbolic execution. Then, the case theory is used to establish the access control model for the access objects. Subsequently, to describe some access properties of the objects while a program is running, we present a control flow based Extended Program Behavior model with Finite-State Machine controlled parameters (EPBFSM) by adding constraints to the control flow model. Finally, the new fuzzed inputs are generated by resolving the constraints resulting from the EPBFSM. By combining the program behavior with the security model, we can find not only the possible path-aware vulnerabilities but also the possible access control objects-aware vulnerabilities.

Read the paper · More papers on PaperTik