Approaches of Attack Surface Estimation and Web Browser Fuzzing

Alexander Vasilievich Kozachok, Dmitry Nikolaev, Natalya Erokhina · Voprosy kiberbezopasnosti · 2022

Abstract Purpose of the work is to develop of an approach to determining the attack surface based on the analysis of the difference in code coverage and its application to the analysis of web browsers. Research method is to use an instrumentation compiler to analyze code coverage depending on the input data. The proposed approach makes it possible to evaluate the relationship between the input data processed by the analyzed application and the program code by calculating the coverage difference and excluding from the analysis the modules called regardless of the input data. Results of the research: the existing general approaches to software fuzzing, and the features of approaches to fuzzing web browsers, are considered. In general, software fuzzing is performed using one of three methods: blackbox, gray-box, and white-box. The basic criterion for distinguishing these methods is the completeness of information about the source code of the software under test. Web browser fuzzing can be divided into static and dynamic. Approaches to fuzzing complex software can be divided into two groups: analysis of a monolithic application, fuzzing of individual application modules (library interfaces). The difference between these groups is determined by the completeness of the involvement of the functional components of the software under study in the testing process. Each of the levels has its own advantages and disadvantages. Often these shortcomings can be compensated by a combination of fuzzing different fuzzing targets. To correctly determine fuzzing targets, it is necessary to identify the attack surface of the software under study. The authors proposed an approach to assessing the attack surface by calculating the coverage difference; it allows excluding from the analysis modules that are called regardless of the input data. Scientific and practical significance: the results of the article consist in the development of a new approach to determining the attack surface based on the analysis of the difference in coverage of the code of the analyzed application, depending on the data supplied to the input, and allowing to exclude modules from the analysis that are called regardless of the input data.

Read the paper · More papers on PaperTik