16 papers · ranked by Valyu relevance
Lu Yu, Yuliang Lu, Yi Shen, Yuwei Li + 1 more
Directed greybox fuzzing (DGF) is an effective method to detect vulnerabilities of the specified target code. Nevertheless, there are three main issues in the existing DGFs. First, the target vulnerable code of the DGFs needs to be manually selected, which is tedious. Second, DGFs mainly leverage distance information…
Chaitra Niddodi, Stefan Nagy, Darko Marinov, Sibin Mohan
—Directed fuzzing is a dynamic testing technique that focuses exploration on specific, pre-targeted program locations. Like other types of fuzzers, directed fuzzers are most effective when maximizing testing speed and precision. To this end, recent directed fuzzers have begun leveraging path pruning: preventing the…
Wang Bin, Ao Yang, Kedan Li, Liu Aofan + 4 more
Wang Bin 1 , Ao Yang 1 , Kedan Li 2 , Aofan Liu 1 , Hui Li1, ∗ , Guibo Luo1, ∗ , Weixiang Huang 3 , Yan Zhuang 3 1 Guangdong Provincial Key Laboratory of Ultra High Definition Immersive Media Technology, Shenzhen Graduate School, Peking University 2 University of Illinois at Urbana-Champaign 3 China Mobile Internet CO…
Darya Parygina, Timofey Mezhuev, Daniil Kuts
In this paper, we enhance directed fuzzing with context weights for graph nodes and resolve indirect edges during call graph construction. We construct flexible tool for directed fuzzing with components able to be easily combined with other techniques. We implement proposed method in three separate modules: DiFuzzLLVM…
Huanyao Rong, Wei You, Xiaofeng Wang, Tianhao Mao
Directed fuzzing is an advanced software testing approach that systematically guides the fuzzing campaign toward userdefined target sites, enabling efficient discovery of vulnerabilities related to these sites. However, we have observed that some complex vulnerabilities remain undetected by directed fuzzers even when…
Xiaofan Li, Xuan Li, Guangfa Lv, Yongzheng Zhang + 1 more
In this paper, we propose a directed greybox fuzzer based on dynamic constraint filtering and focusing (CONFF). First, all path constraints are tracked, and those with high priority are filtered as the next solution targets. Next, focusing on a single path constraint to be satisfied, we obtain its data condition and…
Pengfei Wang, Xu Zhou, Tai Yue, Peihong Lin + 2 more
—Greybox fuzzing has been the most scalable and practical approach to software testing. Most greybox fuzzing tools are coverage-guided as code coverage is strongly correlated with bug coverage. However, since most covered codes may not contain bugs, blindly extending code coverage is less efficient, especially for…
Yubo He, Yuefei Zhu, Ali Safaa Sadiq
Directed greybox fuzzing guides fuzzers to explore specific objective code areas and has achieved good performance in some scenarios such as patch testing. However, if there are multiple objective code to explore, existing directed greybox fuzzers, such as AFLGo and Hawkeye, often neglect some targets because they use…
Yingpei Zeng, Fengming Zhu, Siyi Zhang, Yu Yang + 5 more
'Yufan Pan' 'Guojie Xie' 'Ting Wu' 'Muhammad Aleem'] Fuzzing has become an important method for finding vulnerabilities in software. For fuzzing programs expecting structural inputs, syntactic- and semantic-aware fuzzing approaches have been particularly proposed. However, they still cannot fuzz in-memory data stores…
Mingrui Ma, Lansheng Han, Yekui Qian, Athanasios V. Vasilakos + 1 more
'Vassilis S. Kodogiannis'] As one of the most effective methods of vulnerability mining, fuzzy testing has scalability and complex path detection ability. Fuzzy testing sample generation is the key step of fuzzy testing, and the quality of sample directly determines the vulnerability mining ability of fuzzy tester. At…
Yuying Liu, Pin Yang, Peng Jia, Ziheng He + 2 more
'Zahid Mehmood'] With the continuous development of deep learning, more and more domains use deep learning technique to solve key problems. The security issues of deep learning models have also received more and more attention. Nowadays, malware has become a huge security threat in cyberspace. Traditional…
Yi Nian Niu, Eric G. Roberts, Danielle Denisko, Michael M. Hoffman
Bioinformatics software tools operate largely through the use of specialized genomics file formats. Often these formats lack formal specification, and only rarely do the creators of these tools robustly test them for correct handling of input and output. This causes problems in interoperability between different tools…
Victor H. R. Nogueira, Rishabh Sharma, Rafael V. C. Guido, Michael J. Keiser
As efforts to improve the robustness of molecular representations advance, so does the need for methods to test and validate them. We use a Variational Auto-Encoder (VAE), an unsupervised deep learning model, to generate anomalous samples of a well-known molecular string format called SELF-referencIng Embedded Strings…
Authors not listed
A directed graph (or digraph) consists of a finite vertex set 𝑉 and a set of ordered edges 𝐸 ⊆ 𝑉 × 𝑉, each edge (𝑢, 𝑣) indicating a one-way connection from 𝑢 (source) to 𝑣 (target). A bidirected graph is a generalization of an undirected graph where each edge is assigned a direction at each of its endpoints…
Sebastian Towers, Jessica James, Harrison Steel, Idris Kempf
Directed evolution is a method for engineering biological systems or components, such as proteins, wherein desired traits are optimised through iterative rounds of mutagenesis and selection of fit variants. The process of protein directed evolution can be envisaged as navigation over high-dimensional landscapes with…
Jess James, Sebastian Towers, Jakob Foerster, Harrison Steel
Directed evolution can enable engineering of biological systems with minimal knowledge of their underlying sequence-to-function relationships. A typical directed evolution process consists of iterative rounds of mutagenesis and selection that are designed to steer changes in a biological system (e.g. a protein) towards…