Fuzzing is a technique for detecting vulnerabilities in target programs by generating a large number of test cases randomly. In this approach, code coverage serves as feedback to guide the evolution of seed queues. However, such evolutionary strategies often utilize context-insensitive branch metrics, which fail to differentiate the execution of the same branch in different contexts, potentially overlooking new internal program states. To address the aforementioned issues, this paper proposes context-sensitive branch coverage-guided fuzzing and implements a prototype tool called CSBFUZZ (Context-sensitive Branch Coverage Feedback Fuzzing). Specifically, CSBFUZZ utilizes context-sensitive branch coverage as feedback information by: (1) CSBFUZZ automatically identifying variables crucial for representing the sequence of branch executions, referred to as critical variables in this paper; (2) CSBFUZZ identifying the current branch execution sequence based on recorded critical variables' order; (3) incorporating test cases that trigger new branch execution sequences into the seed queue to guide subsequent fuzzing. The experimental results demonstrate that, compared to fuzzing tools guided by context-insensitive branch coverage, this paper can uncover more crashes and vulnerabilities, and explore more code in context-sensitive real-world programs.
No takes yet. Share an insight, caveat, or question.
XinYi Liu (2024) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: