活动预告 | CodeWisdom软件智能化开发与运维学术系列报告:第12期(佘东冬,HKUST)
2024-9-19 20:19:38 Author: mp.weixin.qq.com(查看原文) 阅读量:0 收藏

Dongdong She

Assistant professor at the Hong Kong University of Science and Technology, CSE department

Summary

Title

Unlock the Potential of General-purpose Fuzzing: An Optimization Approach

Abstract

Based on the application domains, fuzzing can be categorized into general-purpose fuzzing (i.e., testing all kinds of software) and domain-specific fuzzing (e.g., testing a specific type of software). AFL havoc mode/AFL++ is the most powerful general-purpose fuzzer, and it has been used in the Google OSS-Fuzz project to harvest tons of bugs. Despite the significant advancement of fuzzing research, general-purpose fuzzing still relies on random strategies and human-written heuristics. In this talk, we show that by formulating general-purpose fuzzing as an online stochastic control problem, a combination of lightweight optimization algorithms can significantly boost its performance. We present FOX, a novel general-purpose fuzzer that can beat the strongest mode of AFL++ (with CMPLOG and fuzzing dictionary) up to 26.45% on standalone programs and 6.59% on FuzzBench programs.

Speaker

Dongdong She is an assistant professor at the Hong Kong University of Science and Technology, CSE department. He obtained his PhD from the CS department at Columbia University. Before Columbia, He earned his M.S. from UC Riverside and B.S. from Huazhong University of Science and Technology. He is broadly interested in security and machine learning. He is particularly interested in applying data-driven approaches (e.g., LLM, optimization) to solve traditional security problems (e.g., vulnerability detection, software testing, program analysis). Multiple PhD positions are available, send him an email at [email protected] if you are interested. 

Schedule

时间:

2024年9月27日(周五)10:00-13:00

September 27th, 2024 from 10:00 to 13:00

腾讯会议链接:

https://meeting.tencent.com/dm/qol4qjWmtftd?rs=30

会议号:730 731 021

地点:

复旦大学江湾校区二号交叉学科楼A2003


文章来源: https://mp.weixin.qq.com/s?__biz=MzU4NDU4OTM4OQ==&mid=2247509918&idx=1&sn=7888d5186b8e3bdd04579429e122b85c&chksm=fd956ebccae2e7aab6aacf7dd45454a50003b692f99072b4f669cc5cbcb36067473d85f270d6&scene=58&subscene=0#rd
如有侵权请联系:admin#unsafe.sh