LiveFuzz: Detecting Exploitable Library Vulnerabilities from Client Programs via Directed Greybox Fuzzing
Developers frequently utilize third-party libraries to improve productivity, which also introduces potential security risks. To enhance program security, existing approaches generate tests for public functions to trigger library vulnerabilities from client programs, yet they depend on proof-of-concepts (PoCs), which are often unavailable. In this paper, we propose a new approach, LiveFuzz, based on directed greybox fuzzing (DGF) to trigger library vulnerabilities from client programs without PoCs, thereby detecting their exploitability from the clients. LiveFuzz exploits a target tuple to extend existing DGF techniques to cross-program scenarios. Based on the target tuple, LiveFuzz introduces a novel Abstract Path Mapping mechanism to project execution paths, mitigating the preference for shorter paths. LiveFuzz also proposes a risk-based adaptive mutation to mitigate excessive mutation. To evaluate LiveFuzz, we construct a new dataset including 61 cases of library vulnerabilities exploited from client programs. Results show that LiveFuzz increases the number of target-reachable paths compared with all baselines and improves the average speed of vulnerability exposure. Three vulnerabilities are triggered exclusively by LiveFuzz.
Sat 18 JulDisplayed time zone: Brisbane change
11:40 - 12:40 | Session 1: Software Vulnerabilities and Security IResearch Track at Ballroom Chair(s): Yi Song School of Computer Science, Wuhan University | ||
11:40 15mTalk | LiveFuzz: Detecting Exploitable Library Vulnerabilities from Client Programs via Directed Greybox Fuzzing Research Track Yukai Zhao , Menghan Wu Zhejiang University, Xing Hu Zhejiang University, Shaohua Wang Central University of Finance and Economics, Meng Luo The State Key Laboratory of Blockchain and Data Security, Zhejiang University, Xin Xia Zhejiang University | ||
11:55 15mTalk | ATTAIN: Automated Exploit Failure Analysis through Trace-Driven Diff Analysis Research Track Xinwei Mao Zhejiang University, Zirui Chen Zhejiang University, Xing Hu Zhejiang University, Xin Xia Zhejiang University Pre-print | ||
12:10 15mTalk | VulnForge: Building Enhanced OSS Vulnerability Datasets via Uncertainty-based Patch Analysis Research Track Li Lu Huazhong University of Science and Technology, Xinyu She Huazhong University of Science and Technology, Shengming Zhao Fudan University, Ningke Li National University of Singapore, Yanjie Zhao Huazhong University of Science and Technology, Haoyu Wang Huazhong University of Science and Technology | ||
12:25 15mTalk | RelocSC: Compiler-Driven Generation of Self-Relocating Linux Shellcode Research Track Ruimin Wang Information Engineering University, Jintao Bao Information Engineering University, Jian Lin Information Engineering University, Guoan Liu Information Engineering University, Shuai Ren Information Engineering University | ||