kirancodes.me
To Proof Maintenance & Beyond!

FUDGE: fuzz driver generation at scale

Domagoj Babic, Stefan Bucur, Yaohui Chen, Franjo Ivancic, Tim King, Markus Kusano, Caroline Lemieux, László Szekeres, Wei Wang

Abstract

At Google we have found tens of thousands of security and robustness bugs by fuzzing C and C++ libraries. To fuzz a library, a fuzzer requires a fuzz driver—which exercises some library code—to which it can pass inputs. Unfortunately, writing fuzz drivers remains a primarily manual exercise, a major hindrance to the widespread adoption of fuzzing. In this paper, we address this major hindrance by introducing the Fudge system for automated fuzz driver generation. Fudge automatically generates fuzz driver candidates for libraries based on existing client code. We have used Fudge to generate thousands of new drivers for a wide variety of libraries. Each generated driver includes a synthesized C/C++ program and a corresponding build script, and is automatically analyzed for quality. Developers have integrated over 200 of these generated drivers into continuous fuzzing services and have committed to address reported security bugs. Further, several of these fuzz drivers have been upstreamed to open source projects and integrated into the OSS-Fuzz fuzzing infrastructure. Running these fuzz drivers has resulted in over 150 bug fixes, including the elimination of numerous exploitable security vulnerabilities.

BibTeX
@inproceedings{Babic-al:FSE19,
  author    = {Domagoj Babic and
               Stefan Bucur and
               Yaohui Chen and
               Franjo Ivancic and
               Tim King and
               Markus Kusano and
               Caroline Lemieux and
               L{\'{a}}szl{\'{o}} Szekeres and
               Wei Wang},
  title     = {{FUDGE:} fuzz driver generation at scale},
  booktitle = {{ESEC/SIGSOFT} {FSE}},
  pages     = {975--985},
  publisher = {{ACM}},
  year      = {2019},
}

Related papers