Efficient Seed Generation for Expert-based Directed Fuzzing
Koffi, Koffi Anderson. (2023-05). Efficient Seed Generation for Expert-based Directed Fuzzing. Theses and Dissertations Collection, University of Idaho Library Digital Collections. https://www.lib.uidaho.edu/digital/etd/items/koffi_idaho_0089n_12617.html
- Title:
- Efficient Seed Generation for Expert-based Directed Fuzzing
- Author:
- Koffi, Koffi Anderson
- Date:
- 2023-05
- Keywords:
- binary analysis fuzzing symbolic execution
- Program:
- Computer Science
- Subject Category:
- Computer science
- Abstract:
-
The exploration of the input space of programs can often be prohibitively expensive duringfuzzing. To improve this exploration, modern fuzzing relies on human expertise to provide plausible initial test cases. However, the process of handcrafting test cases for fuzzing is often strenuous for humans and requires a deeper understanding of the Program-Under-Test (PUT). Also, the use of known inputs to programs often cannot trigger vulnerable program behaviors or reach potentially vulnerable code locations in a fuzzing session. To address those issues, we propose a seed generation framework for human-in-the-loop directed fuzzing. Our proposed framework uses symbolic execution to generate seeds that exercise paths to target program locations and uses fuzzing to trigger vulnerable program behaviors. Finally, our framework enables the visualization of the explored execution paths in binaries for generated or user-provided test inputs. The experimental results of our approach show its effectiveness in improving AFL’s performance in discovering software bugs.
- Description:
- masters, M.S., Computer Science -- University of Idaho - College of Graduate Studies, 2023-05
- Major Professor:
- Konstantinos, Kolias
- Committee:
- Vakanski, Alex; Xian, Min; Soule, Terence
- Defense Date:
- 2023-05
- Identifier:
- Koffi_idaho_0089N_12617
- Type:
- Text
- Format Original:
- Format:
- application/pdf
- Rights:
- In Copyright - Educational Use Permitted. For more information, please contact University of Idaho Library Special Collections and Archives Department at libspec@uidaho.edu.
- Standardized Rights:
- http://rightsstatements.org/vocab/InC-EDU/1.0/