Skip to main content

Performant Binary Fuzzing without Source Code using Static Instrumentation

Publication ,  Conference
Pauley, E; Tan, G; Zhang, D; McDaniel, P
Published in: 2022 IEEE Conference on Communications and Network Security, CNS 2022
January 1, 2022

Advancements in fuzz testing have achieved the ability to quickly and comprehensively find security-critical faults in software systems. Yet, some of these techniques rely on access to source code, which is often unavailable in practice. In this paper, we explore techniques to replicate the depth and efficiency of source-code available fuzzers via static binary instrumentation. Developing such instrumentation is difficult because compilation is a lossy process, and much of the source-level semantics leveraged by these techniques are not available in binaries. We recover much of this information via heuristic control flow reconstruction, a shadow stack for function identification, and a novel technique for instrumenting comparison instructions. We evaluate RWFUZZ on the LAVA-M dataset, achieving the same effectiveness as a best-in-class source-available fuzzer with a 3.4 × execution time overhead (lower than existing dynamic fuzzing approaches). In this way, we show that techniques for binary fuzzing may approach the functional ability of source-available fuzzing.

Duke Scholars

Published In

2022 IEEE Conference on Communications and Network Security, CNS 2022

DOI

Publication Date

January 1, 2022

Start / End Page

226 / 235
 

Citation

APA
Chicago
ICMJE
MLA
NLM
Pauley, E., Tan, G., Zhang, D., & McDaniel, P. (2022). Performant Binary Fuzzing without Source Code using Static Instrumentation. In 2022 IEEE Conference on Communications and Network Security, CNS 2022 (pp. 226–235). https://doi.org/10.1109/CNS56114.2022.9947273
Pauley, E., G. Tan, D. Zhang, and P. McDaniel. “Performant Binary Fuzzing without Source Code using Static Instrumentation.” In 2022 IEEE Conference on Communications and Network Security, CNS 2022, 226–35, 2022. https://doi.org/10.1109/CNS56114.2022.9947273.
Pauley E, Tan G, Zhang D, McDaniel P. Performant Binary Fuzzing without Source Code using Static Instrumentation. In: 2022 IEEE Conference on Communications and Network Security, CNS 2022. 2022. p. 226–35.
Pauley, E., et al. “Performant Binary Fuzzing without Source Code using Static Instrumentation.” 2022 IEEE Conference on Communications and Network Security, CNS 2022, 2022, pp. 226–35. Scopus, doi:10.1109/CNS56114.2022.9947273.
Pauley E, Tan G, Zhang D, McDaniel P. Performant Binary Fuzzing without Source Code using Static Instrumentation. 2022 IEEE Conference on Communications and Network Security, CNS 2022. 2022. p. 226–235.

Published In

2022 IEEE Conference on Communications and Network Security, CNS 2022

DOI

Publication Date

January 1, 2022

Start / End Page

226 / 235