AI 中文总结
针对现有Web应用程序模糊测试器的局限,提出ZIMPAF和RedPhuzz。ZIMPAF通过多粒度运行时解释器检测提供多种功能,RedPhuzz利用这些信息及新变异策略进行针对性模糊测试,在检测漏洞和效率上优于前身Phuzz,ZIMPAF吞吐量也更高。
AI 中文摘要
我们提出了ZIMPAF(运行时解释器检测)和RedPhuzz(一个模糊测试器),以解决现有最先进模糊测试器的关键限制:检测效率低下、缺乏执行环境知识以及Web领域知识有限。ZIMPAF实现了一种新颖的多粒度运行时解释器检测,提供分支覆盖、强大的错误和异常日志记录、函数和语言结构监控,以及识别分支指令中使用的用户提供的输入。该检测能够识别参数被污染的潜在易受攻击函数,将其标记为高价值模糊测试目标,而无需执行污染分析。它还采用了一种新颖的反向常量探测来推断参数源自常量的潜在易受攻击函数,表明其无漏洞并允许跳过它们。RedPhuzz利用这些信息进行高度针对性的函数和输入级模糊测试,超越简单的基于错误的模糊测试,还通过多阶段漏洞检测检测沉默漏洞。我们还引入了三种新颖的变异策略来实现高度针对性和有效的模糊测试:清理感知、分支内输入感知和数据类型感知变异。我们使用RedPhuzz的前身(Phuzz)在六个基准Web应用程序上的86个测试用例评估了RedPhuzz的性能。RedPhuzz检测到了所有漏洞,而Phuzz未能检测到16个。尽管执行了更多任务,但RedPhuzz比Phuzz快73%。ZIMPAF比Phuzz的检测(PCOV和UOPZ)更快,同时写入的数据要多得多。在五个采样基准中,ZIMPAF的吞吐量比PCOV和UOPZ高2.1至41.22倍,在一个基准中高0.87倍。
英文摘要
We present ZIMPAF, runtime interpreter instrumentation, and RedPhuzz, a fuzzer, to address key limitations of state-of-the-art fuzzers: inefficient instrumentation, the lack of knowledge of the execution environment, and limited web domain knowledge. ZIMPAF implements a novel multi-granular runtime interpreter instrumentation that provides branch coverage, robust error and exception logging, function and language construct monitoring, and identification of user-supplied inputs used in branch instructions. The instrumentation is capable of identifying potentially vulnerable functions whose parameters are tainted, marking them as high-valued fuzzing targets, without performing taint analysis. It also employs a novel backward constant probe to infer potentially vulnerable functions whose parameters originate from constants, indicating their invulnerability and allowing them to be skipped. This information is utilized by RedPhuzz to perform highly-targeted function-and input-level fuzzing that goes beyond simple error-based fuzzing, but also detects silent vulnerabilities via multi-stage vulnerability detection. We also introduce three novel mutation strategies to achieve highly targeted and effective fuzzing: sanitization-aware, input-in-branch-aware, and data type-aware mutation. We evaluate RedPhuzz's performance with its predecessor (Phuzz) with 86 test cases across six benchmark web applications. RedPhuzz detects all vulnerabilities, while Phuzz fails to detect 16. RedPhuzz is 73% faster than Phuzz despite performing more tasks. ZIMPAF is faster than Phuzz's instrumentation (PCOV and UOPZ), while writing significantly more data. ZIMPAF achieves 2.1 to 41.22 times higher throughput than PCOV and UOPZ across five sampled benchmarks, and 0.87 times for one.