about
Neural Networks for Fuzzing (arxiv.org)
1 point by webstar12 on Jan 26, 2017 | hide | past | pdf | discuss on HN

In plain words: A neural network learns valid file structure from samples, then points the fuzzer at the spots most worth breaking, instead of using a hand-written grammar. Unlike random mutation, it breaks that structure in smart places, reaching unexpected code paths in Edge's PDF parser.

Abstract · Learn&Fuzz: Machine Learning for Input Fuzzing

Fuzzing consists of repeatedly testing an application with modified, or fuzzed, inputs with the goal of finding security vulnerabilities in input-parsing code. In this paper, we show how to automate the generation of an input grammar suitable for input fuzzing using sample inputs and neural-network-based statistical machine-learning techniques. We present a detailed case study with a complex input format, namely PDF, and a large complex security-critical parser for this format, namely, the PDF parser embedded in Microsoft's new Edge browser. We discuss (and measure) the tension between conflicting learning and fuzzing goals: learning wants to capture the structure of well-formed inputs, while fuzzing wants to break that structure in order to cover unexpected code paths and find bugs. We also present a new algorithm for this learn&fuzz challenge which uses a learnt input probability distribution to intelligently guide where to fuzz inputs.

Patrice Godefroid, Hila Peleg, Rishabh Singh
arXiv:1701.07232 · cs.AI, cs.CR, cs.LG, cs.PL, cs.SE · submitted Jan 25, 2017
abstract · pdf · html

add comment on HN
Also discussed: Jun 2017 (1 point, 0 comments)