Improving fuzzing efficiency based on extracted constant values
Sevak Sargsyan, Jivan Hakobyan, Lyudovikos Nersisyan, Karen Sargsyan, Vahagn Melkonyan · 2022
Fuzzing is one of the most efficient methods for bug detection. Many companies use fuzzing for their products’ quality improvement. One of the downsides of fuzzing is the execution time. To provide good code coverage fuzzing should be performed long enough. It is a critical problem for regular testing of large code bases. This work aims to extract constant values used in branch conditions. Then develop a special mutation for fuzzing tool, which uses this information to perform better mutations with input buffer and cover program paths faster. Experimental evaluation of the developed method on Google’s OSS-Fuzz project proves the efficiency of the developed method.