CSEFuzz: Fuzz Testing Based on Symbolic Execution
Autor: | Xie Zhangwei, Jiaming Zhang, Xiulei Liu, Zhanqi Cui, Liwei Zheng |
---|---|
Jazyk: | angličtina |
Rok vydání: | 2020 |
Předmět: |
Parsing
General Computer Science business.industry Computer science General Engineering 020207 software engineering 02 engineering and technology Fuzz testing computer.software_genre Symbolic execution Set (abstract data type) Test case Software initial seeds 020204 information systems 0202 electrical engineering electronic engineering information engineering General Materials Science Data mining lcsh:Electrical engineering. Electronics. Nuclear engineering business computer lcsh:TK1-9971 symbolic execution test coverage criteria |
Zdroj: | IEEE Access, Vol 8, Pp 187564-187574 (2020) |
ISSN: | 2169-3536 |
Popis: | Fuzz testing has been successful in finding defects of various software packages. These defects include file parsing, image processing, Internet browsers, and network protocols. However, the quality of the initial seed test cases greatly influences the coverage and defect detection capability of fuzz testing. To address this issue, we propose CSEFuzz, a fuzz testing approach based on symbolic execution for defect detection. First, CSEFuzz generates candidate test cases by symbolic execution and collects coverage information of the test cases. Then, CSEFuzz extracts the test-case templates of the test cases and selects a set of test-case templates according to specific coverage criteria. Finally, CSEFuzz selects test cases according to the selected test-case templates, and the selected test cases are used as initial seed test cases for fuzz testing. Experiments are conducted on 11 open-source programs. The results show that in comparison with afl-cmin, which is the test-case selection command of Kelinci, CSEFuzz with a path coverage criterion reduces the time costs of the initial seed test selection and verification by 94.26%. In addition, compared with afl-cmin, 32 more paths are covered and 16 more defects are detected by CSEFuzz. |
Databáze: | OpenAIRE |
Externí odkaz: |