BertRLFuzzer: A BERT and Reinforcement Learning Based Fuzzer

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Jha, Piyush, Scott, Joseph, Ganeshna, Jaya Sriram, Singh, Mudit, Ganesh, Vijay
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914961559650304
author Jha, Piyush
Scott, Joseph
Ganeshna, Jaya Sriram
Singh, Mudit
Ganesh, Vijay
author_facet Jha, Piyush
Scott, Joseph
Ganeshna, Jaya Sriram
Singh, Mudit
Ganesh, Vijay
contents We present a novel tool BertRLFuzzer, a BERT and Reinforcement Learning (RL) based fuzzer aimed at finding security vulnerabilities for Web applications. BertRLFuzzer works as follows: given a set of seed inputs, the fuzzer performs grammar-adhering and attack-provoking mutation operations on them to generate candidate attack vectors. The key insight of BertRLFuzzer is the use of RL with a BERT model as an agent to guide the fuzzer to efficiently learn grammar-adhering and attack-provoking mutation operators. In order to establish the efficacy of BertRLFuzzer we compare it against a total of 13 black box and white box fuzzers over a benchmark of 9 victim websites with over 16K LOC. We observed a significant improvement relative to the nearest competing tool in terms of time to first attack (54% less), new vulnerabilities found (17 new vulnerabilities), and attack rate (4.4% more attack vectors generated).
format Preprint
id arxiv_https___arxiv_org_abs_2305_12534
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle BertRLFuzzer: A BERT and Reinforcement Learning Based Fuzzer
Jha, Piyush
Scott, Joseph
Ganeshna, Jaya Sriram
Singh, Mudit
Ganesh, Vijay
Software Engineering
Cryptography and Security
Machine Learning
We present a novel tool BertRLFuzzer, a BERT and Reinforcement Learning (RL) based fuzzer aimed at finding security vulnerabilities for Web applications. BertRLFuzzer works as follows: given a set of seed inputs, the fuzzer performs grammar-adhering and attack-provoking mutation operations on them to generate candidate attack vectors. The key insight of BertRLFuzzer is the use of RL with a BERT model as an agent to guide the fuzzer to efficiently learn grammar-adhering and attack-provoking mutation operators. In order to establish the efficacy of BertRLFuzzer we compare it against a total of 13 black box and white box fuzzers over a benchmark of 9 victim websites with over 16K LOC. We observed a significant improvement relative to the nearest competing tool in terms of time to first attack (54% less), new vulnerabilities found (17 new vulnerabilities), and attack rate (4.4% more attack vectors generated).
title BertRLFuzzer: A BERT and Reinforcement Learning Based Fuzzer
topic Software Engineering
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2305.12534