Generating syntactically and semantically valid test cases for fuzzing JavaScript engines

Yazhuo Jin · 2024

JavaScript engines serve as the cornerstone of the modern web ecosystem, and fuzzing, as one of the most advanced vulnerability discovery techniques, is often used to detect vulnerabilities in JavaScript engines. Test cases generated by fuzzing JavaScript engines are essentially JavaScript code. However, randomly generated JavaScript code by fuzzing is often invalid and unable to detect vulnerabilities in JavaScript engines. To ensure the syntactic and semantic correctness of test cases generated by fuzzing JavaScript engines, this paper proposes a code block combination strategy based on semantic constraints. Specifically, the paper first decomposes Proof of Concept (POC) into syntactically correct code blocks. Simultaneously, to satisfy semantic constraints and ensure the correctness of test cases, it is necessary to record the preconditions and postconditions of code blocks during the decomposition process. Then, the originally syntactically correct code blocks are combined to form test cases under the premise of satisfying semantic constraints. This approach not only ensures the syntactic correctness of test cases but also ensures their semantic validity. To validate the effectiveness of the proposed method, this paper designs and implements the fuzzing testing system ValidJSFuzz. ValidJSFuzz is experimentally compared with three classic advanced JavaScript engine fuzzing tools, namely jsfunfuzz, CodeAlchemist, and DIE, on four mainstream JavaScript engines: JavaScriptCore, SpiderMonkey, ChakraCore, and V8. The experimental results indicate that the ValidJSFuzz system can improve test case correctness by 25% compared to the best-performing tool, DIE.

Read the paper · More papers on PaperTik