Reducing Coverage-Equivalent Inputs in Grammar-based Fuzzing by Avoiding Recurrent Rule Sequences
We present RSFuzz, a new technique to enhance grammar-based fuzzing by reducing the generation of coverage-equivalent inputs during testing. Grammar-based fuzzers apply production rules from a given grammar to generate well-structured inputs for the target program. However, a key limitation is that many existing fuzzers still produce a large number of “coverage-equivalent” inputs—those that revisit already explored program paths—thereby restricting their ability to uncover new bugs and improve coverage. To address this issue, RSFuzz automatically identifies recurrent sequences of production rules that cause coverage-equivalent inputs and prevents their reuse during fuzzing. A key challenge in practice lies in the large number of coverage-equivalent input groups, each with many inputs, making it difficult to identify the underlying recurrent sequences. RSFuzz tackles this challenge with a customized algorithm that iteratively groups coverage-equivalent inputs, selects promising groups, and extracts recurrent sequences for each group based on accumulated data while running any grammar-based fuzzer. We integrated RSFuzz with existing random and probabilistic fuzzers and evaluated it on eight real-world programs using JavaScript and JSON input formats. Experimental results show that incorporating RSFuzz with both fuzzers exclusively detects 108 and 31 crashes with distinct stack traces, increases line coverage by 6.5% and 5.1%, and reduces duplicate-coverage input generation by 29.7% and 37.7%, respectively, compared to their performance without RSFuzz.
Thu 9 JulDisplayed time zone: Eastern Time (US & Canada) change
10:30 - 12:30 | |||
10:30 20mTalk | CuFuzz: An API-Knowledge-Graph Coverage-Driven Fuzzing Framework for CUDA Libraries Research Papers Ximing Fan School of cyber science and engineering, Sichuan University, China, Yong Fang Sichuan University, Peng Jia Sichuan University, Yang Liu Nanyang Technological University, Yijia Xu Sichuan University, Xi Peng Huawei Theory Lab, Yuhao Zhou Fudan University | ||
10:50 20mTalk | SQLiFuzz: Uncovering SQL Injection in Any Web Applications Research Papers I Putu Arya Dharmaadi University of Groningen, Thuan Pham University of Melbourne, Fadi Mohsen University of Groningen, Fatih Turkmen University of Groningen Link to publication | ||
11:10 20mTalk | Reducing Coverage-Equivalent Inputs in Grammar-based Fuzzing by Avoiding Recurrent Rule Sequences Research Papers Jaehan Yoon Sungkyunkwan University, Yunji Seo Korea University, Hakjoo Oh Korea University, Sooyoung Cha Sungkyunkwan University Pre-print | ||
11:30 10mTalk | CapCo: Automating Carla-Apollo Co-Simulation and Scenario Fuzzing Tool Demonstrations Xiaodong Zhang University of Chinese Academy of Science, Songyang Yan Xi'an Jiaotong University, Ming Fan Xi'an Jiaotong University, Zijiang Yang University of Science and Technology of China and Synkrotron, Inc. | ||
11:40 10mTalk | SQLynx: Towards Generic Mutation-Based Fuzzing for DBMSs Across Diverse Dialects Tool Demonstrations Runpei Miao SKLCCSE Lab, Beihang University, Jie Liang Beihang University, Zhiyong Wu Tsinghua University, China, Jingzhou Fu School of Software, Tsinghua University, Yu Jiang Tsinghua University, Shuai Ma SKLCCSE Lab, Beihang University | ||
11:50 10mTalk | A Practical Fuzzer for the Python Runtime System Tool Demonstrations Link to publication Pre-print | ||
12:00 10mTalk | Shark2Pit: Automated Test Template Generation for Protocol Fuzzing Based on Packet Parser Tool Demonstrations Yulai Fu , Yuanliang Chen Tsinghua University, Fuchen Ma Tsinghua University, Changjian Liu Central South University, Wanli Chen Central South University, Dalong Shi AVIC International Digital Network Technology Co., Ltd., Qiang Fu Central South University, Heyuan Shi Central South University | ||