Optimizing seed inputs in fuzzing with machine learning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Cheng, Liang, Zhang, Yang, Zhang, Yi, Wu, Chen, Li, Zhangtan, Fu, Yu, Li, Haisheng
Format: Preprint
Published: 2019
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914033992466432
author Cheng, Liang
Zhang, Yang
Zhang, Yi
Wu, Chen
Li, Zhangtan
Fu, Yu
Li, Haisheng
author_facet Cheng, Liang
Zhang, Yang
Zhang, Yi
Wu, Chen
Li, Zhangtan
Fu, Yu
Li, Haisheng
contents The success of a fuzzing campaign is heavily depending on the quality of seed inputs used for test generation. It is however challenging to compose a corpus of seed inputs that enable high code and behavior coverage of the target program, especially when the target program requires complex input formats such as PDF files. We present a machine learning based framework to improve the quality of seed inputs for fuzzing programs that take PDF files as input. Given an initial set of seed PDF files, our framework utilizes a set of neural networks to 1) discover the correlation between these PDF files and the execution in the target program, and 2) leverage such correlation to generate new seed files that more likely explore new paths in the target program. Our experiments on a set of widely used PDF viewers demonstrate that the improved seed inputs produced by our framework could significantly increase the code coverage of the target program and the likelihood of detecting program crashes.
format Preprint
id arxiv_https___arxiv_org_abs_1902_02538
institution arXiv
publishDate 2019
record_format arxiv
spellingShingle Optimizing seed inputs in fuzzing with machine learning
Cheng, Liang
Zhang, Yang
Zhang, Yi
Wu, Chen
Li, Zhangtan
Fu, Yu
Li, Haisheng
Cryptography and Security
The success of a fuzzing campaign is heavily depending on the quality of seed inputs used for test generation. It is however challenging to compose a corpus of seed inputs that enable high code and behavior coverage of the target program, especially when the target program requires complex input formats such as PDF files. We present a machine learning based framework to improve the quality of seed inputs for fuzzing programs that take PDF files as input. Given an initial set of seed PDF files, our framework utilizes a set of neural networks to 1) discover the correlation between these PDF files and the execution in the target program, and 2) leverage such correlation to generate new seed files that more likely explore new paths in the target program. Our experiments on a set of widely used PDF viewers demonstrate that the improved seed inputs produced by our framework could significantly increase the code coverage of the target program and the likelihood of detecting program crashes.
title Optimizing seed inputs in fuzzing with machine learning
topic Cryptography and Security
url https://arxiv.org/abs/1902.02538