Minerva: browser API fuzzing with dynamic mod-ref analysis
Abstract
Browser APIs are essential to the modern web experience. Due to their large number and complexity, they vastly expand the attack surface of browsers. To detect vulnerabilities in these APIs, fuzzers generate test cases with a large amount of random API invocations. However, the massive search space formed by arbitrary API combinations hinders their effectiveness: since randomly-picked API invocations unlikely interfere with each other (i.e., compute on partially shared data), few interesting API interactions are explored. Consequently, reducing the search space by revealing inter-API relations is a major challenge in browser fuzzing.
BibTeX
@inproceedings{Zhou-al:FSE22,
author = {Chijin Zhou and
Quan Zhang and
Mingzhe Wang and
Lihua Guo and
Jie Liang and
Zhe Liu and
Mathias Payer and
Yu Jiang},
title = {Minerva: browser {API} fuzzing with dynamic mod-ref analysis},
booktitle = {{ESEC/SIGSOFT} {FSE}},
pages = {1135--1147},
publisher = {{ACM}},
year = {2022},
}