Steelix: program-state based binary fuzzing

Author:

Li Yuekang1,Chen Bihuan2,Chandramohan Mahinthan1,Lin Shang-Wei1,Liu Yang1,Tiu Alwen1

Affiliation:

1. Nanyang Technological University, Singapore

2. Fudan University, China / Nanyang Technological University, Singapore

Funder

National Research Foundation Singapore

National Natural Science Foundation of China

Publisher

ACM

Reference31 articles.

1. 1999. Tcpdump & Libpcap. (1999). http://www.tcpdump.org. 2001. Libtiff. (2001). http://www.libtiff.org. 2002. Libpng. (2002). http://www.libpng.org. 2003. Gzip. (2003). http://www.gzip.org. 2005. Defense Advanced Research Projects Agency. (2005). http://www.darpa. mil/. 2005. Dyninst API. (2005). http://www.dyninst.org/dyninst. 2006. The Patroit Missile Failure. (2006). https://www.ima.umn.edu/~arnold/ disasters/patriot.html. 2014. American fuzzy lop. (2014). http://lcamtuf.coredump.cx/afl/. 2014. Cyber Grand Challenge. (2014). http://archive.darpa.mil/ cybergrandchallenge/about.html. 2014. Spike fuzzer platform. (2014). http://www.immunitysec.com/. 2015. AFL-dyninst. (2015). https://github.com/vrtadmin/moflow/tree/master/ afl-dyninst. 2015. AFL-QEMU. (2015). http://lcamtuf.coredump.cx/afl/technical_details.txt. 2015. AFLPIN. (2015). https://github.com/mothran/aflpin. 2015. Peach fuzzer platform. (2015). http://www.peachfuzzer.com/products/ peach-platform/. 2015. Sdl Process: Verification. (2015). https://www.microsoft.com/en-us/sdl/ process/verification.aspx. 2016. The bug-o-rama trophy case of AFL. (2016). http://lcamtuf.coredump.cx/ afl/#bugs. 2016. Circumventing fuzzing roadblocks with compiler transformations. (2016). 1999. Tcpdump & Libpcap. (1999). http://www.tcpdump.org. 2001. Libtiff. (2001). http://www.libtiff.org. 2002. Libpng. (2002). http://www.libpng.org. 2003. Gzip. (2003). http://www.gzip.org. 2005. Defense Advanced Research Projects Agency. (2005). http://www.darpa. mil/. 2005. Dyninst API. (2005). http://www.dyninst.org/dyninst. 2006. The Patroit Missile Failure. (2006). https://www.ima.umn.edu/~arnold/ disasters/patriot.html. 2014. American fuzzy lop. (2014). http://lcamtuf.coredump.cx/afl/. 2014. Cyber Grand Challenge. (2014). http://archive.darpa.mil/ cybergrandchallenge/about.html. 2014. Spike fuzzer platform. (2014). http://www.immunitysec.com/. 2015. AFL-dyninst. (2015). https://github.com/vrtadmin/moflow/tree/master/ afl-dyninst. 2015. AFL-QEMU. (2015). http://lcamtuf.coredump.cx/afl/technical_details.txt. 2015. AFLPIN. (2015). https://github.com/mothran/aflpin. 2015. Peach fuzzer platform. (2015). http://www.peachfuzzer.com/products/ peach-platform/. 2015. Sdl Process: Verification. (2015). https://www.microsoft.com/en-us/sdl/ process/verification.aspx. 2016. The bug-o-rama trophy case of AFL. (2016). http://lcamtuf.coredump.cx/ afl/#bugs. 2016. Circumventing fuzzing roadblocks with compiler transformations. (2016).

2. https://lafintel.wordpress.com/2016/08/15/ circumventing-fuzzing-roadblocks-with-compiler-transformations/. 2016. DARPA Challenge Binaries on Linux and OS X. (2016). https://github. com/trailofbits/cb-multios/. 2016. Driller Source Code. (2016). https://github.com/shellphish/driller. 2016. IDAPython. (2016). https://www.hex-rays.com/products/ida/support/ idapython_docs/. 2017. Steelix. (2017). https://sites.google.com/site/steelix2017/. https://lafintel.wordpress.com/2016/08/15/ circumventing-fuzzing-roadblocks-with-compiler-transformations/. 2016. DARPA Challenge Binaries on Linux and OS X. (2016). https://github. com/trailofbits/cb-multios/. 2016. Driller Source Code. (2016). https://github.com/shellphish/driller. 2016. IDAPython. (2016). https://www.hex-rays.com/products/ida/support/ idapython_docs/. 2017. Steelix. (2017). https://sites.google.com/site/steelix2017/.

3. Brad Arkin. 2009. Adobe Reader and Acrobat Security Initiative. (2009). http: //blogs.adobe.com/security/2009/05/adobe_reader_and_acrobat_secur.html. Brad Arkin. 2009. Adobe Reader and Acrobat Security Initiative. (2009). http: //blogs.adobe.com/security/2009/05/adobe_reader_and_acrobat_secur.html.

4. Domagoj Babić Lorenzo Martignoni Stephen McCamant and Dawn Song. 2011. Statically-directed Dynamic Automated Test Generation. In ISSTA. 12–22. 10.1145/2001420.2001423 Domagoj Babić Lorenzo Martignoni Stephen McCamant and Dawn Song. 2011. Statically-directed Dynamic Automated Test Generation. In ISSTA. 12–22. 10.1145/2001420.2001423

5. Marcel Böhme Van-Thuan Pham and Abhik Roychoudhury. 2016. Coveragebased Greybox Fuzzing as Markov Chain. In CCS. 1032–1043. 10.1145/2976749.2978428 Marcel Böhme Van-Thuan Pham and Abhik Roychoudhury. 2016. Coveragebased Greybox Fuzzing as Markov Chain. In CCS. 1032–1043. 10.1145/2976749.2978428

Cited by 192 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. CatchFuzz: Reliable active anti-fuzzing techniques against coverage-guided fuzzer;Computers & Security;2024-08

2. sqlFuzz: Directed Fuzzing for SQL Injection Vulnerability;Electronics;2024-07-26

3. SLIMECRAFT: State Learning for Client-Server Regression Analysis and Fault Testing;2024 IEEE 48th Annual Computers, Software, and Applications Conference (COMPSAC);2024-07-02

4. Graph Confident Learning for Software Vulnerability Detection;Engineering Applications of Artificial Intelligence;2024-07

5. MicroFuzz: An Efficient Fuzzing Framework for Microservices;Proceedings of the 46th International Conference on Software Engineering: Software Engineering in Practice;2024-04-14

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3