Conference Proceedings

Directed greybox fuzzing

M Böhme, VT Pham, MD Nguyen, A Roychoudhury

Proceedings of the ACM Conference on Computer and Communications Security | ASSOC COMPUTING MACHINERY | Published : 2017

Abstract

Existing Greybox Fuzzers (GF) cannot be effectively directed, for instance, towards problematic changes or patches, towards critical system calls or dangerous locations, or towards functions in the stacktrace of a reported vulnerability that we wish to reproduce. In this paper, we introduce Directed Greybox Fuzzing (DGF) which generates inputs with the objective of reaching a given set of target program locations efficiently. We develop and evaluate a simulated annealing-based power schedule that gradually assigns more energy to seeds that are closer to the target locations while reducing energy for seeds that are further away. Experiments with our implementation AFLGo demonstrate that DGF o..

View full abstract

University of Melbourne Researchers

Grants

Awarded by National Research Foundation


Funding Acknowledgements

This research was partially supported by a grant from the National Research Foundation, Prime Minister's Office, Singapore under its National Cybersecurity R&D Program (TSUNAMi project, No. NRF2014NCR-NCR001-21) and administered by the National Cybersecurity R&D Directorate.