PBFuzz: Potential-aware Branch-oriented Hybrid Fuzzing
Wenyu Fang, Xia Yang, Wensheng Guo, Haiyong Sun, Qiming Li, Zhongping Lin · 2024
Hybrid fuzzing integrates fuzzing and concolic execution to detect software vulnerabilities. It utilizes the rapid exploration of fuzzing and the constraint-solving capabilities of concolic execution. However, current hybrid fuzzing techniques face challenges in coordinating fuzzing seeds with concolic execution inputs, particularly in identifying promising seeds. These methods frequently struggle to efficiently prioritize seeds from the fuzzing seed queue for reaching critical code areas, leading to concolic execution spending significant resources on inputs with minimal coverage improvements. To address these issues, we introduce a Potential-aware Branch-oriented Hybrid Fuzzing approach (PBHF) to enhance testing efficacy. PBHF synchronizes seeds between hybrid fuzzing and concolic execution using a branch-oriented scheduling strategy. We propose a lightweight branch utility evaluation algorithm to assess seed utility based on branch exploration potential. We developed a prototype of PBHF, named PBFuzz, which integrates AFL and QSYM. Experimental results show that PBFuzz achieves superior branch coverage in vulnerability detection compared to existing methods. These findings validate the efficacy and superiority of our approach.