Conference Proceedings

Coverage-based Greybox Fuzzing as Markov chain

M Böhme, VT Pham, A Roychoudhury

Proceedings of the ACM Conference on Computer and Communications Security | Published : 2016

Abstract

Coverage-based Greybox Fuzzing (CGF) is a random testing approach that requires no program analysis. A new test is generated by slightly mutating a seed input. If the test exercises a new and interesting path, it is added to the set of seeds; otherwise, it is discarded. We observe that most tests exercise the same few "high-frequency" paths and develop strategies to explore significantly more paths with the same number of tests by gravitating towards low-frequency paths. We explain the challenges and opportunities of CGF using a Markov chain model which specifies the probability that fuzzing the seed that exercises path i generates an input that exercises path j. Each state (i.e., seed) has ..

View full abstract

University of Melbourne Researchers

Grants

Awarded by National Research Foundation Singapore