Research on Directed Grey-box Fuzzing Technology Based on Target (S)
Liang Sun, Peng Wu, Shaoxian Shu · Proceedings/Proceedings of the ... International Conference on Software Engineering and Knowledge Engineering · 2023
In recent years, grey-box fuzzing has been proven to be the most effective method for discovering vulnerabilities in software.However, the present grey-box fuzzing still has some shortcomings.Most existing grey-box fuzzers are coverage guided and consider the program code equally, and spend a lot of time on improving the code coverage.However, most of the code in the program does not contain bugs and only a small percentage of the code may have bugs.Therefore, blindly improving code coverage can waste limited resources on a large number of bug independent locations and reduce the efficiency of fuzzing.In order to solve the above problems, we propose a targeted mutation strategy for continuous target exploration.By identifying the key bytes in the input seeds, a mutation algorithm for different stages of mutation is proposed to ensure that the subsequent generation of seeds can still hit the target location as much as possible, to realize the continuous exploration of the target location.In addition, based on this mutation strategy, we propose a fuzzing optimization method based on multi-factor seed selection, using LLVM framework to insert the target location information into the test program for preprocessing, and then the multi-factor seed selection strategy is used to select better seeds to explore the target location.