AI 中文总结
该研究针对多驱动程序模糊测试下的软件结构开展实证研究,提出结构抽象方法,经27个OSS-Fuzz项目验证,多驱动程序模糊测试在相同预算下性能优于单驱动程序,可提升覆盖率并发现更多独特漏洞。
AI 中文摘要
许多软件系统通过命令行选项、子命令和配置标志暴露多种执行模式。对于这类程序,模糊测试既依赖变异输入,也依赖调用的模式。然而,现有评估仍聚焦于代码覆盖率和漏洞数量,尚未明确执行模式如何划分、重叠以及遗漏软件结构,以及这些差异如何影响模糊测试的有效性。我们针对多驱动程序模糊测试下的软件结构开展实证研究,提出一种结构抽象方法:以静态调用图作为共享主干,将驱动程序特有的动态覆盖率投影到该图上,从而推导驱动程序诱导的子图。基于此抽象,我们开发了包含四个阶段的方法,分别为主干构建、模糊测试与分析、基于图的分析,以及研究问题驱动的评估。我们将该方法应用于27个来自OSS-Fuzz的C/C++项目,涵盖43个可执行文件和854种驱动程序配置。在相同总预算下,多驱动程序模糊测试优于最佳单驱动程序基线,使覆盖的调用图节点增加27.9%,控制流图(CFG)边覆盖率提高73.5%,并发现11个单驱动程序模糊测试基本遗漏的独特漏洞和异常行为。不过,驱动程序的贡献并不均衡,子图在内聚性、碎片化、模块化、重叠性等方面存在显著差异,且剩余未探索部分遵循重复模式,而非均匀分布的尾部。这些结果表明,多驱动程序模糊测试本质上是一个结构探索问题。
英文摘要
Many software systems expose multiple execution modes through command-line options, subcommands, and configuration flags. For such programs, fuzzing depends on both mutated inputs and the invoked mode. Yet evaluations still focus on coverage and bug counts, leaving unclear how execution modes partition, overlap, and miss software structure, and how these differences affect effectiveness. We present an empirical study of software structure under multi-driver fuzzing. We propose a structural abstraction that uses a static call graph as a shared backbone and projects driver-specific dynamic coverage onto it to derive driver-induced subgraphs. Based on this abstraction, we develop a four-phase methodology for backbone construction, fuzzing and profiling, graph-based analysis, and research-question-driven evaluation. We apply it to 27 OSS-Fuzz-derived C/C++ projects, spanning 43 executables and 854 driver configurations. Under the same total budget, multi-driver fuzzing outperforms the best single-driver baseline, increasing covered call-graph nodes by 27.9% and CFG-edge coverage by 73.5%, and revealing 11 unique bugs and abnormal behaviors largely missed by single-driver fuzzing. However, driver contributions are uneven, subgraphs differ substantially in cohesion, fragmentation, modularity, overlap, and residual under-exploration follows recurring regimes rather than a homogeneous tail. These results show that multi-driver fuzzing is fundamentally a structural exploration problem.