ETD PDF

Efficient Seed Generation for Expert-based Directed Fuzzing

Citation

Koffi, Koffi Anderson. (2023-05). Efficient Seed Generation for Expert-based Directed Fuzzing. Theses and Dissertations Collection, University of Idaho Library Digital Collections. https://www.lib.uidaho.edu/digital/etd/items/koffi_idaho_0089n_12617.html

Title:
Efficient Seed Generation for Expert-based Directed Fuzzing
Author:
Koffi, Koffi Anderson
Date:
2023-05
Keywords:
binary analysis fuzzing symbolic execution
Program:
Computer Science
Subject Category:
Computer science
Abstract:

The exploration of the input space of programs can often be prohibitively expensive duringfuzzing. To improve this exploration, modern fuzzing relies on human expertise to provide plausible initial test cases. However, the process of handcrafting test cases for fuzzing is often strenuous for humans and requires a deeper understanding of the Program-Under-Test (PUT). Also, the use of known inputs to programs often cannot trigger vulnerable program behaviors or reach potentially vulnerable code locations in a fuzzing session. To address those issues, we propose a seed generation framework for human-in-the-loop directed fuzzing. Our proposed framework uses symbolic execution to generate seeds that exercise paths to target program locations and uses fuzzing to trigger vulnerable program behaviors. Finally, our framework enables the visualization of the explored execution paths in binaries for generated or user-provided test inputs. The experimental results of our approach show its effectiveness in improving AFL’s performance in discovering software bugs.

Description:
masters, M.S., Computer Science -- University of Idaho - College of Graduate Studies, 2023-05
Major Professor:
Konstantinos, Kolias
Committee:
Vakanski, Alex; Xian, Min; Soule, Terence
Defense Date:
2023-05
Identifier:
Koffi_idaho_0089N_12617
Type:
Text
Format Original:
PDF
Format:
application/pdf

Contact us about this record

Rights
Rights:
In Copyright - Educational Use Permitted. For more information, please contact University of Idaho Library Special Collections and Archives Department at libspec@uidaho.edu.
Standardized Rights:
http://rightsstatements.org/vocab/InC-EDU/1.0/