FuzzEval: Assessing Fuzzers on Generating Context-Sensitive Inputs

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Hasan, S Mahmudul, Kozyreva, Polina, Hoque, Endadul
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866929504778190848
author Hasan, S Mahmudul
Kozyreva, Polina
Hoque, Endadul
author_facet Hasan, S Mahmudul
Kozyreva, Polina
Hoque, Endadul
contents Cryptographic protocols form the backbone of modern security systems, yet vulnerabilities persist within their implementations. Traditional testing techniques, including fuzzing, have struggled to effectively identify vulnerabilities in cryptographic libraries due to their reliance on context-sensitive inputs. This paper presents a comprehensive evaluation of eleven state-of-the-art fuzzers' ability to generate context-sensitive inputs for testing a cryptographic standard, PKCS#1-v1.5, across thirteen implementations. Our study reveals nuanced performance differences among the fuzzers in terms of the validity and diversity of the produced inputs. This investigation underscores the limitations of existing fuzzers in handling context-sensitive inputs. These findings are expected to drive further research and development in this area.
format Preprint
id arxiv_https___arxiv_org_abs_2409_12331
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle FuzzEval: Assessing Fuzzers on Generating Context-Sensitive Inputs
Hasan, S Mahmudul
Kozyreva, Polina
Hoque, Endadul
Cryptography and Security
Cryptographic protocols form the backbone of modern security systems, yet vulnerabilities persist within their implementations. Traditional testing techniques, including fuzzing, have struggled to effectively identify vulnerabilities in cryptographic libraries due to their reliance on context-sensitive inputs. This paper presents a comprehensive evaluation of eleven state-of-the-art fuzzers' ability to generate context-sensitive inputs for testing a cryptographic standard, PKCS#1-v1.5, across thirteen implementations. Our study reveals nuanced performance differences among the fuzzers in terms of the validity and diversity of the produced inputs. This investigation underscores the limitations of existing fuzzers in handling context-sensitive inputs. These findings are expected to drive further research and development in this area.
title FuzzEval: Assessing Fuzzers on Generating Context-Sensitive Inputs
topic Cryptography and Security
url https://arxiv.org/abs/2409.12331