发表机构
Bernoulli Institute, University of Groningen; Faculty of Engineering, Udayana University; Department of Computer Science, University of Cyprus(格罗宁根大学伯努利学院; 乌达亚纳大学工程学院; 塞浦路斯大学计算机科学系)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
TraceLib通过系统调用转换位图实现语言无关的Web模糊测试覆盖率反馈,在16个应用中验证,优于黑盒并在多个PHP应用上超过原生反馈,开销约1毫秒/请求。
AI 中文摘要
覆盖率反馈是模糊测试的重要指导来源。然而,获取此类反馈通常需要应用程序级插桩,而这种插桩是针对应用程序的语言和运行时定制的。鉴于现代Web应用程序跨越多种语言和运行时,这种应用程序级插桩的实现和维护成本高昂。因此,我们提出了TraceLib,一种系统调用反馈机制,用于实现语言无关的Web模糊测试。我们提出的方法观察系统调用的转换,用有界参数哈希丰富选定的转换,并将其转换为一个65,536位置的类似AFL的位图。通过使用生成的位图,任何Web模糊测试器都可以决定是否保留添加了先前未见位图位置的请求,而无需参考应用程序代码覆盖率。我们将TraceLib集成到WebFuzz中,并在五种WebFuzz反馈模式下对其进行评估:两种提出的TraceLib变体(一种覆盖每个被跟踪的系统调用,另一种投影到受监控的文件路径和识别的SQL缓冲区上)、改编自Xiao等人的N-gram比较器(代表我们所知的最新工作)、WebFuzz的原生灰盒反馈,以及无反馈的黑盒模糊测试。我们在十六个被测Web应用程序(WUTs)上评估TraceLib:八个PHP应用程序和另外八个涵盖HTTP URL、Ruby、Java、Go和Python的应用程序,以展示平台可移植性。结果表明,我们提出的TraceLib投影在所有八个PHP WUTs上超过了黑盒,同时在四个上超过了原生:Joomla、Drupal、PrestaShop和Bagisto。此外,在相同的重放请求工作负载上测量,跟踪器每个请求大约花费一毫秒的服务器端延迟。这些结果表明,紧凑的系统调用反馈是覆盖率指导的有用的运行时无关代理。
英文摘要
Coverage feedback is an important source of guidance for fuzzing. However, obtaining such feedback normally requires application-level instrumentation that is specific to the language and runtime of the application. Given that modern web applications span multiple languages and runtimes, this application-level instrumentation is costly to implement and maintain. Therefore, we present TraceLib, a system-call feedback mechanism for enabling language-agnostic web fuzzing. Our proposed approach observes the transitions of system calls, enriches selected transitions with bounded argument hashes, and converts them into a 65,536-position AFL-like bitmap. By using the generated bitmap, any web fuzzer can decide whether to retain requests that add previously unseen bitmap positions without consulting application code coverage. We integrate TraceLib into WebFuzz and evaluate it under five WebFuzz feedback modes: the two proposed TraceLib variants (one over every traced system call and one projected onto monitored file paths and recognized SQL buffers), the N-gram comparator adapted from Xiao et al. representing the most recent work to our knowledge, WebFuzz's Native grey-box feedback, and black-box fuzzing without feedback. We evaluate TraceLib on sixteen web applications under test (WUTs): eight PHP applications and eight further applications spanning Node.js, Ruby, Java, Go, and Python to demonstrate platform portability. The results show that our proposed TraceLib projected exceeds black-box on all eight PHP WUTs while exceeding Native on four: Joomla, Drupal, PrestaShop, and Bagisto. In addition, measured on an identical replayed request workload, the tracer costs approximately one millisecond of server-side latency per request. These results indicate that compact system-call feedback is a useful runtime-independent proxy for coverage guidance.