• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Improving AFLGo's Directed Fuzzing by Considering Indirect Function Calls
 
  • Details
  • Full
Options
September 2023
Conference Paper
Title

Improving AFLGo's Directed Fuzzing by Considering Indirect Function Calls

Abstract
Directed fuzzing is a sophisticated security testing technique that aims to find vulnerabilities in specific locations of a software system. It is thus used in cases where targeting a pre-defined section of a system under test (SUT) is required. The directed fuzzer AFLGo utilizes abstract representations, such as call graphs and control-flow graphs, of the SUT to accomplish directedness. These representations however do not consider indirect function calls, more specifically function pointers. This might distort AFLGo's process of guiding the testing towards the desired locations. In the worst case, it might even break the dirpctpilnpss altogether, This paper introduces Marauder's Map, an extension for AFLGo that rectifies this problem. Its implementation is discussed and experiments with various SUTs are conducted to investigate how AFLGo's directed fuzzing benefits from the consideration of indirect function calls. It shows that Marauder's Map is able to expose vulnerabilities up to five times faster than the unaltered version of AFLGo.
Author(s)
Jezuita, Fabian
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Mainwork
38th IEEE/ACM International Conference on Automated Software Engineering Workshops, ASEW 2023. Proceedings  
Conference
International Conference on Automated Software Engineering Workshops 2023  
International Workshop on Automating Test Case Design, Selection, and Evaluation 2023  
DOI
10.1109/ASEW60602.2023.00024
Language
English
Fraunhofer-Institut für Offene Kommunikationssysteme FOKUS  
Keyword(s)
  • Fuzzing

  • Software systems

  • Security

  • Testing

  • Software engineering

  • grey-box fuzzing

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024