基于LLM引导插桩的JavaScript引擎状态感知模糊测试
State-Aware Fuzzing of JavaScript Engines with LLM-Guided Instrumentation
浏览论文内容
中文总结 AI 辅助
StateLens利用LLM引导的智能插桩选择,突破JavaScript引擎模糊测试的覆盖率平台期,通过双反馈机制探索深层内部状态,显著优于现有工具并发现68个新漏洞。
中文摘要 AI 辅助
现代网络的安全性取决于JavaScript(JS)引擎的正确性,然而这些复杂系统仍然容易受到高影响漏洞的攻击。最先进的模糊测试器的一个关键限制是覆盖率平台期:一旦模糊测试器饱和了控制流图,边缘覆盖率就失去了引导发现的能力。由于复杂的引擎行为(如JIT优化层和隐藏类转换)通常共享相同的边缘覆盖率,标准覆盖率指标无法感知触发深层错误所需的不同内部状态。为了弥合这一差距,我们提出了StateLens,一个利用大型语言模型(LLM)自动发现深层内部状态的框架。由于状态空间庞大且运行时开销高,盲目地在所有状态放置插桩探针是不可行的。StateLens引入了一种新颖的基于代理的推理流程,模拟安全研究人员的直觉。通过迭代遍历代码和开发者注释,我们的代理智能地选择高价值的插桩目标,有效地区分逻辑驱动的状态变量与无关数据。这产生了可综合的、高信号的反馈探针,映射引擎的隐藏配置。该插桩支持双反馈机制,有效地引导模糊测试器探索未触及的引擎语义。我们的评估证实,StateLens显著优于最先进的模糊测试器,并发现了68个新漏洞。
英文摘要
The security of the modern web depends on the correctness of JavaScript (JS) engines, yet these complex systems remain vulnerable to high-impact bugs. A critical limitation of state-of-the-art fuzzers is the coverage plateau: once a fuzzer saturates the control-flow graph, edge coverage loses its ability to guide discovery. Because complex engine behaviors, such as JIT optimization tiers and hidden class transitions, often share identical edge coverage, standard coverage metrics are blind to the distinct internal states required to trigger deep errors. To bridge this gap, we present StateLens, a framework that employs Large Language Models (LLM) to automate the discovery of deep internal states. Blindly placing instrumentation probes at all states is infeasible due to the vast state space and the high runtime overhead. StateLens introduces a novel agent-based reasoning pipeline that emulates the intuition of a security researcher. By iteratively traversing code and developer comments, our agents intelligently select high-value instrumentation targets, effectively separating logic-driving state variables from irrelevant data. This results in synthesizable, high-signal feedback probes that map the engine's hidden configurations. This instrumentation feeds a dual-feedback mechanism, effectively guiding the fuzzer toward unexplored engine semantics. Our evaluation confirms that StateLens significantly outperforms state-of-the-art fuzzers and uncovering 68 new bugs.
发表机构
- Hong Kong University of Science and Technology(香港科技大学)
- VX Research Limited(VX研究有限公司)
- Singapore Management University(新加坡管理大学)
机构由 AI 辅助整理,请以论文原文为准。