Fuzz drivers are essential components in fuzzing, acting as the interface between the fuzzer and the target library. Recent advancements have led to a variety of methods aimed at automating and optimizing fuzz driver generation. However, the performance and applicability of these techniques are influenced by factors such as the complexity of the target library. This paper offers a systematic review of recent progress in fuzz driver generation techniques, providing a comprehensive categorization and analysis of key approaches in the field. We propose a robust set of evaluation criteria that address critical challenges, including statistical evaluation, resource management, and API coverage, establishing a more standardized framework for future assessments. Furthermore, we introduce a set of Best Practices for evaluating fuzz driver generation techniques, which provides practical guidelines to improve transparency, consistency, and reproducibility in research. Finally, we identify promising research directions to address current limitations, with a particular focus on leveraging emerging technologies such as large language models (LLMs) and expanding fuzz driver support to new programming languages and platforms.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

SoK: From Systematization to Best Practices in Fuzz Driver Generation

  • Qian Yan,
  • Minhuan Huang,
  • Huayang Cao,
  • Shuaibing Lu

摘要

Fuzz drivers are essential components in fuzzing, acting as the interface between the fuzzer and the target library. Recent advancements have led to a variety of methods aimed at automating and optimizing fuzz driver generation. However, the performance and applicability of these techniques are influenced by factors such as the complexity of the target library. This paper offers a systematic review of recent progress in fuzz driver generation techniques, providing a comprehensive categorization and analysis of key approaches in the field. We propose a robust set of evaluation criteria that address critical challenges, including statistical evaluation, resource management, and API coverage, establishing a more standardized framework for future assessments. Furthermore, we introduce a set of Best Practices for evaluating fuzz driver generation techniques, which provides practical guidelines to improve transparency, consistency, and reproducibility in research. Finally, we identify promising research directions to address current limitations, with a particular focus on leveraging emerging technologies such as large language models (LLMs) and expanding fuzz driver support to new programming languages and platforms.