登录 EN

添加临时用户

基于种子评分的高效定向灰盒模糊测试技术研究

Research on High-efficiency Directed Greybox Fuzzing Based on Seed Scoring

作者:刘啸龙
  • 学号
    2022******
  • 学位
    硕士
  • 电子邮箱
    845******com
  • 答辩日期
    2025.05.13
  • 导师
    肖喜
  • 学科名
    计算机技术
  • 页码
    63
  • 保密级别
    公开
  • 培养单位
    599 国际研究生院
  • 中文关键词
    定向模糊测试;崩溃复现;种子评分;种子调度;变异策略
  • 英文关键词
    Directed Fuzzing;Crash Reproduction;Seed Scoring;Seed Scheduling;Mutation Strategy

摘要

灰盒模糊测试是自动化软件测试的先进技术之一。传统的覆盖率引导的灰盒模糊测试致力于最大化被测代码的覆盖率,以期能暴露更多的漏洞;而新兴的定向灰盒模糊测试则侧重于到达并测试被测代码的某一特定位置,以期暴露该位置存在的漏洞。定向灰盒模糊测试因其在崩溃重现、补丁测试等应用场景下的优秀表现,成为了软件安全领域的一大热门。然而,目前的定向灰盒模糊测试器大量使用继承自覆盖率引导的灰盒模糊测试器的方法。这些方法缺乏针对定向性的设计,导致定向灰盒模糊测试整体效率低下。为了克服这一局限,本文提出了一种基于种子评分的高效定向灰盒模糊测试方法,可以显著提升定向灰盒模糊测试器暴露目标漏洞的速度。本文的主要工作如下:(1)针对定向灰盒模糊测试在模糊测试过程中未能及时关注高优先级种子的问题,提出了用于优化调度的种子优先队列和基于评分的深度优先模糊测试过程,提高了模糊测试的效率。定向灰盒模糊测试的技术框架继承自覆盖率引导的灰盒模糊测试。然而,这套技术框架中有两个设计并不利于定向灰盒模糊测试,包括顺序选择种子进行调度以及一轮模糊测试过程中均选择初始种子进行变异,这会导致模糊测试过程效率低下。对此,本文提出了用于优化调度的种子优先队列和基于评分的深度优先模糊测试过程,以改善现有的定向灰盒模糊测试方法。本文实现了一个定向灰盒模糊测试器DFAFL,并在23个真实目标漏洞上与先进的模糊测试器(AFL、AFLGo、WindRanger以及DAFL)进行了对比实验。实验结果表明,DFAFL暴露目标漏洞的速度平均是基线模糊测试器速度的3.24倍。(2)针对定向灰盒模糊测试在变异种子的过程中没有使用历史变异信息的问题,提出了一种基于历史变异信息的奖励变异策略,提高了变异种子的效率。在变异种子的过程中,模糊测试器可以从历史变异信息中学习各个字节与目标位置之间的控制关系。然而,现有的定向灰盒模糊测试器仍然在使用随机选择位置进行变异的策略,这导致种子变异的效率低下。对此,本文提出了一种轻量级的学习历史变异信息的方法,用于指导种子变异,提升变异种子的效率。本文实现了一个定向灰盒模糊测试器DFAFL-RM,并在23个真实目标漏洞上与先进的模糊测试器(AFL、AFLGo、WindRanger以及DAFL)进行了对比实验。实验结果表明,DFAFL-RM暴露目标漏洞的速度平均是基线模糊测试器速度的2.99倍。

Greybox fuzzing stands as one of the advanced techniques in automated software testing. Traditional coverage-guided greybox fuzzing aims to maximize code coverage of the program under test to expose potential vulnerabilities, while emerging directed greybox fuzzing focuses on reaching and testing specific target locations in the code to reveal vulnerabilities at those points. Directed greybox fuzzing has gained significant attention in software security due to its outstanding performance in scenarios such as crash reproduction and patch testing. However, current directed greybox fuzzers heavily rely on methods inherited from coverage-guided greybox fuzzers. These methods lack designs tailored for directionality, resulting in overall inefficiency in directed fuzzing. To address this limitation, this research proposes an high-efficiency directed greybox fuzzing method based on seed scoring, which significantly accelerates the exposure of target vulnerabilities. The main contributions of this research are as follows:(1) To address the issue where directed greybox fuzzing fails to prioritize high-value seeds during testing, we propose a seed priority queue for optimized scheduling and a seed scoring-based depth-first fuzzing process to enhance efficiency. While the technical framework of directed greybox fuzzing inherits from coverage-guided greybox fuzzing, two critical limitations hinder its performance: sequential seed selection for scheduling and the use of initial seeds for mutation during each fuzzing process. This research introduces a prioritized scheduling mechanism and a depth-first fuzzing process guided by seed scores to improve existing directed greybox fuzzing methods. This research implements a directed greybox fuzzer named DFAFL and conducts comparative experiments on 23 real-world target vulnerabilities against state-of-the-art fuzzers (AFL, AFLGo, WindRanger, and DAFL). The experimental results demonstrate that DFAFL exposes target vulnerabilities 3.24$\times$ faster on average compared to baseline fuzzers.(2) To address the issue that directed greybox fuzzing does not utilize historical mutation information during seed mutation, we propose a reward-based mutation strategy using historical mutation information to improve mutation efficiency. During the seed mutation process, fuzzers can learn control relationships between individual bytes and target locations from historical mutation information. However, existing directed greybox fuzzers still employ random position selection strategies for mutation, resulting in low efficiency in seed mutation. To resolve this, this research introduces a lightweight learning method for historical mutation information to guide seed mutation and enhance mutation efficiency. This research implements a directed greybox fuzzer named DFAFL-RM and conducts comparative experiments on 23 real-world target vulnerabilities against state-of-the-art fuzzers (AFL, AFLGo, WindRanger, and DAFL). The experimental results demonstrate that DFAFL-RM exposes target vulnerabilities 2.99$\times$ faster on average compared to baseline fuzzers.