SnapFuzz: High-throughput fuzzing of network applications
File(s)snapfuzz-issta22.pdf (626.18 KB)
Accepted version
Author(s)
Andronidis, Anastasios
Cadar, Cristian
Type
Conference Paper
Abstract
In recent years, fuzz testing has benefited from increased com-
putational power and important algorithmic advances, leading to
systems that have discovered many critical bugs and vulnerabilities
in production software. Despite these successes, not all applications
can be fuzzed efficiently. In particular, stateful applications such as
network protocol implementations are constrained by a low fuzzing
throughput and the need to develop complex fuzzing harnesses
that involve custom time delays and clean-up scripts.
In this paper, we present SnapFuzz, a novel fuzzing framework
for network applications. SnapFuzz offers a robust architecture
that transforms slow asynchronous network communication into
fast synchronous communication, snapshots the target at the latest
point at which it is safe to do so, speeds up file operations by
redirecting them to a custom in-memory filesystem, and removes
the need for many fragile modifications, such as configuring time
delays or writing clean-up scripts.
Using SnapFuzz, we fuzzed five popular networking applications:
LightFTP, TinyDTLS, Dnsmasq, LIVE555 and Dcmqrscp. We report
impressive performance speedups of 62.8 x, 41.2 x, 30.6 x, 24.6 x, and
8.4 x, respectively, with significantly simpler fuzzing harnesses in
all cases. Due to its advantages, SnapFuzz has also found 12 extra
crashes compared to AFLNet in these applications.
putational power and important algorithmic advances, leading to
systems that have discovered many critical bugs and vulnerabilities
in production software. Despite these successes, not all applications
can be fuzzed efficiently. In particular, stateful applications such as
network protocol implementations are constrained by a low fuzzing
throughput and the need to develop complex fuzzing harnesses
that involve custom time delays and clean-up scripts.
In this paper, we present SnapFuzz, a novel fuzzing framework
for network applications. SnapFuzz offers a robust architecture
that transforms slow asynchronous network communication into
fast synchronous communication, snapshots the target at the latest
point at which it is safe to do so, speeds up file operations by
redirecting them to a custom in-memory filesystem, and removes
the need for many fragile modifications, such as configuring time
delays or writing clean-up scripts.
Using SnapFuzz, we fuzzed five popular networking applications:
LightFTP, TinyDTLS, Dnsmasq, LIVE555 and Dcmqrscp. We report
impressive performance speedups of 62.8 x, 41.2 x, 30.6 x, 24.6 x, and
8.4 x, respectively, with significantly simpler fuzzing harnesses in
all cases. Due to its advantages, SnapFuzz has also found 12 extra
crashes compared to AFLNet in these applications.
Date Issued
2022-07-18
Date Acceptance
2022-04-08
Citation
ISSTA 2022: Proceedings of the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis, 2022, pp.340-351
ISBN
9781450393799
Publisher
ACM
Start Page
340
End Page
351
Journal / Book Title
ISSTA 2022: Proceedings of the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis
Copyright Statement
© 2022 ACM. This is the author's version of the work. It is posted here by permission of ACM for your personal use. Not for redistribution. The definitive version was published in ISSTA 2022: Proceedings of the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis (18 Jul 2022) https://dl.acm.org/doi/10.1145/3533767.3534376
Sponsor
European Research Council (ERC)
Grant Number
819141
Source
International Symposium on Software Testing and Analysis (ISSTA 2022)
Publication Status
Published
Start Date
2202-07-18
Finish Date
2022-07-22
Coverage Spatial
Virtual, South Korea
Date Publish Online
2022-07-18