About | Contact Us | Register | Login
ProceedingsSeriesJournalsSearchEAI
Security and Privacy in Communication Networks. 18th EAI International Conference, SecureComm 2022, Virtual Event, October 2022, Proceedings

Research Article

No-Fuzz: Efficient Anti-fuzzing Techniques

Cite
BibTeX Plain Text
  • @INPROCEEDINGS{10.1007/978-3-031-25538-0_38,
        author={Zhengxiang Zhou and Cong Wang and Qingchuan Zhao},
        title={No-Fuzz: Efficient Anti-fuzzing Techniques},
        proceedings={Security and Privacy in Communication Networks. 18th EAI International Conference, SecureComm 2022, Virtual Event, October 2022, Proceedings},
        proceedings_a={SECURECOMM},
        year={2023},
        month={2},
        keywords={Anti-fuzzing Software testing Fuzzing},
        doi={10.1007/978-3-031-25538-0_38}
    }
    
  • Zhengxiang Zhou
    Cong Wang
    Qingchuan Zhao
    Year: 2023
    No-Fuzz: Efficient Anti-fuzzing Techniques
    SECURECOMM
    Springer
    DOI: 10.1007/978-3-031-25538-0_38
Zhengxiang Zhou,*, Cong Wang, Qingchuan Zhao
    *Contact email: zxzhou4-c@my.cityu.edu.hk

    Abstract

    Fuzzing is an automated software testing technique that has achieved great success in recent years. While this technique allows developers to uncover vulnerabilities avoiding consequent issues (e.g., financial loss), it can also be leveraged by attackers to find zero-day vulnerabilities. To mitigate, anti-fuzzing techniques were proposed to impede the fuzzing process by slowing down its rate, misinforming the feedback, and complicating the data flow. Unfortunately, the state-of-the-art of anti-fuzzing entirely focuses on enhancing its defensive capability but underestimates the nontrivial performance overhead and overlooks the requirement of extra manual efforts. In this paper, to advance the state-of-the-art, we propose an efficient and automatic anti-fuzzing technique and implement a prototype, called No-Fuzz. Comparing to prior works, our evaluations illustrate that No-Fuzz introduces less performance overhead, i.e., less than 15% of the storage cost for one fake block. In addition, in respect of the binary-only fuzzing, No-Fuzz can precisely determine the corresponding running environments and eliminate unnecessary storage overheads with high effectiveness. Specifically, it reduces 95% of the total storage cost compared with the prior works for the same number of branch reductions. Moreover, our study sheds light on approaches to improve the practicality of anti-fuzzing techniques.

    Keywords
    Anti-fuzzing Software testing Fuzzing
    Published
    2023-02-04
    Appears in
    SpringerLink
    http://dx.doi.org/10.1007/978-3-031-25538-0_38
    Copyright © 2022–2025 ICST
    EBSCOProQuestDBLPDOAJPortico
    EAI Logo

    About EAI

    • Who We Are
    • Leadership
    • Research Areas
    • Partners
    • Media Center

    Community

    • Membership
    • Conference
    • Recognition
    • Sponsor Us

    Publish with EAI

    • Publishing
    • Journals
    • Proceedings
    • Books
    • EUDL