SoK: Prudent Evaluation Practices for Fuzzing

模糊测试 计算机科学 程序设计语言 软件
作者
Moritz Schloegel,Nils Bars,Nico Schiller,Lukas Bernhard,Tobias Scharnowski,Addison Crump,Arash Ale-Ebrahim,Nicolai Bissantz,Marius Muench,Thorsten Holz
标识
DOI:10.1109/sp54263.2024.00137
摘要

Fuzzing has proven to be a highly effective approach to uncover software bugs over the past decade.After AFL popularized the groundbreaking concept of lightweight coverage feedback, the field of fuzzing has seen a vast amount of scientific work proposing new techniques, improving methodological aspects of existing strategies, or porting existing methods to new domains.All such work must demonstrate its merit by showing its applicability to a problem, measuring its performance, and often showing its superiority over existing works in a thorough, empirical evaluation.Yet, fuzzing is highly sensitive to its target, environment, and circumstances, e. g., randomness in the testing process.After all, relying on randomness is one of the core principles of fuzzing, governing many aspects of a fuzzer's behavior.Combined with the often highly difficult to control environment, the reproducibility of experiments is a crucial concern and requires a prudent evaluation setup.To address these threats to validity, several works, most notably Evaluating Fuzz Testing by Klees et al., have outlined how a carefully designed evaluation setup should be implemented, but it remains unknown to what extent their recommendations have been adopted in practice.In this work, we systematically analyze the evaluation of 150 fuzzing papers published at the top venues between 2018 and 2023.We study how existing guidelines are implemented and observe potential shortcomings and pitfalls.We find a surprising disregard of the existing guidelines regarding statistical tests and systematic errors in fuzzing evaluations.For example, when investigating reported bugs, we find that the search for vulnerabilities in real-world software leads to authors requesting and receiving CVEs of questionable quality.Extending our literature analysis to the practical domain, we attempt to reproduce claims of eight fuzzing papers.These case studies allow us to assess the practical reproducibility of fuzzing research and identify archetypal pitfalls in the evaluation design.Unfortunately, our reproduced results reveal several deficiencies in the studied papers, and we are unable to fully support and reproduce the respective claims.To help the field of fuzzing move toward a scientifically reproducible evaluation strategy, we propose updated guidelines for conducting a fuzzing evaluation that future work should follow.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
思源应助企鹅不耐热采纳,获得10
刚刚
萱1988完成签到,获得积分10
刚刚
温谷完成签到 ,获得积分10
刚刚
1秒前
万能图书馆应助伟大人物采纳,获得10
2秒前
3秒前
Csy发布了新的文献求助10
5秒前
6秒前
辛勤的莹芝完成签到,获得积分10
8秒前
9秒前
田様应助LMDD采纳,获得10
10秒前
里奥少先生完成签到,获得积分20
11秒前
kinsley完成签到,获得积分10
11秒前
鹿lu完成签到 ,获得积分10
12秒前
14秒前
yummy完成签到,获得积分10
15秒前
xcxcxcily完成签到,获得积分10
15秒前
CipherSage应助zuoyou采纳,获得10
16秒前
17秒前
Leon应助小刘采纳,获得20
17秒前
17秒前
媛宝&硕宝完成签到,获得积分10
18秒前
虚心的夏青完成签到,获得积分10
19秒前
ccc关闭了ccc文献求助
19秒前
Jemmy完成签到,获得积分10
20秒前
20秒前
20秒前
21秒前
天天快乐应助科研通管家采纳,获得10
21秒前
毛豆应助科研通管家采纳,获得20
21秒前
斯文败类应助科研通管家采纳,获得10
21秒前
十一玮应助科研通管家采纳,获得10
22秒前
竹筏过海应助科研通管家采纳,获得30
22秒前
Jasper应助科研通管家采纳,获得10
22秒前
所所应助科研通管家采纳,获得10
22秒前
CNAxiaozhu7应助科研通管家采纳,获得10
22秒前
烟花应助科研通管家采纳,获得10
22秒前
十一玮应助科研通管家采纳,获得10
22秒前
上官若男应助科研通管家采纳,获得10
22秒前
22秒前
高分求助中
Healthcare Finance: Modern Financial Analysis for Accelerating Biomedical Innovation 2000
Agaricales of New Zealand 1: Pluteaceae - Entolomataceae 1040
지식생태학: 생태학, 죽은 지식을 깨우다 600
Crystal structures of UP2, UAs2, UAsS, and UAsSe in the pressure range up to 60 GPa 520
Mantodea of the World: Species Catalog Andrew M 500
海南省蛇咬伤流行病学特征与预后影响因素分析 500
Neuromuscular and Electrodiagnostic Medicine Board Review 500
热门求助领域 (近24小时)
化学 医学 材料科学 生物 工程类 有机化学 生物化学 纳米技术 内科学 物理 化学工程 计算机科学 复合材料 基因 遗传学 物理化学 催化作用 细胞生物学 免疫学 电极
热门帖子
关注 科研通微信公众号,转发送积分 3464525
求助须知:如何正确求助?哪些是违规求助? 3057942
关于积分的说明 9059097
捐赠科研通 2748071
什么是DOI,文献DOI怎么找? 1507718
科研通“疑难数据库(出版商)”最低求助积分说明 696632
邀请新用户注册赠送积分活动 696290