FOX: Coverage-guided Fuzzing as Online Stochastic Control
Dongdong She, Adam Štorek, Yuchong Xie, Seoyoung Kweon, Prashast Srivastava, Suman Jana · 2024
Fuzzing is an effective technique for discovering software vulnerabilities by generating random test inputs and executing them against the target program. However, fuzzing large and complex programs remains challenging due to difficulties in uncovering deeply hidden vulnerabilities. This paper addresses the limitations of existing coverage-guided fuzzers, focusing on the scheduler and mutator components. Existing schedulers suffer from information sparsity and the inability to handle fine-grained feedback metrics. The mutators are agnostic of target program branches, leading to wasted computation and slower coverage exploration.