SoK: Prudent Evaluation Practices for Fuzzing

模糊测试 计算机科学 程序设计语言 软件
作者
Moritz Schloegel,Nils Bars,Nico Schiller,Lukas Bernhard,Tobias Scharnowski,Addison Crump,Arash Ale-Ebrahim,Nicolai Bissantz,Marius Muench,Thorsten Holz
标识
DOI:10.1109/sp54263.2024.00137
摘要

Fuzzing has proven to be a highly effective approach to uncover software bugs over the past decade.After AFL popularized the groundbreaking concept of lightweight coverage feedback, the field of fuzzing has seen a vast amount of scientific work proposing new techniques, improving methodological aspects of existing strategies, or porting existing methods to new domains.All such work must demonstrate its merit by showing its applicability to a problem, measuring its performance, and often showing its superiority over existing works in a thorough, empirical evaluation.Yet, fuzzing is highly sensitive to its target, environment, and circumstances, e. g., randomness in the testing process.After all, relying on randomness is one of the core principles of fuzzing, governing many aspects of a fuzzer's behavior.Combined with the often highly difficult to control environment, the reproducibility of experiments is a crucial concern and requires a prudent evaluation setup.To address these threats to validity, several works, most notably Evaluating Fuzz Testing by Klees et al., have outlined how a carefully designed evaluation setup should be implemented, but it remains unknown to what extent their recommendations have been adopted in practice.In this work, we systematically analyze the evaluation of 150 fuzzing papers published at the top venues between 2018 and 2023.We study how existing guidelines are implemented and observe potential shortcomings and pitfalls.We find a surprising disregard of the existing guidelines regarding statistical tests and systematic errors in fuzzing evaluations.For example, when investigating reported bugs, we find that the search for vulnerabilities in real-world software leads to authors requesting and receiving CVEs of questionable quality.Extending our literature analysis to the practical domain, we attempt to reproduce claims of eight fuzzing papers.These case studies allow us to assess the practical reproducibility of fuzzing research and identify archetypal pitfalls in the evaluation design.Unfortunately, our reproduced results reveal several deficiencies in the studied papers, and we are unable to fully support and reproduce the respective claims.To help the field of fuzzing move toward a scientifically reproducible evaluation strategy, we propose updated guidelines for conducting a fuzzing evaluation that future work should follow.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
1秒前
hxpxp完成签到,获得积分10
1秒前
qinandi124完成签到,获得积分10
3秒前
4秒前
YifanWang应助一个小胖子采纳,获得10
5秒前
英吉利25发布了新的文献求助10
8秒前
cccc完成签到,获得积分10
11秒前
她说肚子是吃大的i完成签到,获得积分10
12秒前
刘亮亮完成签到,获得积分10
12秒前
xiaofengyyy完成签到,获得积分10
19秒前
开心完成签到 ,获得积分10
20秒前
ng完成签到 ,获得积分10
21秒前
lalala完成签到,获得积分10
24秒前
香蕉新儿完成签到,获得积分10
25秒前
水煮鱼完成签到,获得积分10
26秒前
YifanWang应助一个小胖子采纳,获得10
27秒前
AmyHu完成签到,获得积分10
42秒前
时代更迭完成签到 ,获得积分10
42秒前
宋艳芳完成签到,获得积分10
43秒前
Cat4pig完成签到 ,获得积分10
44秒前
feiyafei完成签到 ,获得积分10
44秒前
47秒前
48秒前
48秒前
Wendy完成签到,获得积分10
50秒前
MM完成签到 ,获得积分10
50秒前
养花低手完成签到 ,获得积分10
50秒前
51秒前
zzz完成签到 ,获得积分10
51秒前
liuhua发布了新的文献求助10
52秒前
Chenglong发布了新的文献求助10
53秒前
大大彬完成签到 ,获得积分10
53秒前
andre20完成签到 ,获得积分10
59秒前
小鱼崽完成签到 ,获得积分10
1分钟前
烟花应助一个小胖子采纳,获得10
1分钟前
初昀杭完成签到 ,获得积分10
1分钟前
十八完成签到 ,获得积分10
1分钟前
Twonej应助Benhnhk21采纳,获得50
1分钟前
CY完成签到,获得积分10
1分钟前
独特的秋完成签到 ,获得积分10
1分钟前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Handbook of pharmaceutical excipients, Ninth edition 5000
Aerospace Standards Index - 2026 ASIN2026 3000
Polymorphism and polytypism in crystals 1000
Signals, Systems, and Signal Processing 610
Discrete-Time Signals and Systems 610
T/SNFSOC 0002—2025 独居石精矿碱法冶炼工艺技术标准 600
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 纳米技术 有机化学 物理 生物化学 化学工程 计算机科学 复合材料 内科学 催化作用 光电子学 物理化学 电极 冶金 遗传学 细胞生物学
热门帖子
关注 科研通微信公众号,转发送积分 6043005
求助须知:如何正确求助?哪些是违规求助? 7801434
关于积分的说明 16237796
捐赠科研通 5188531
什么是DOI,文献DOI怎么找? 2776596
邀请新用户注册赠送积分活动 1759645
关于科研通互助平台的介绍 1643202