Paper Presented at the Outstanding Security Conference USENIX Security Symposium 2023 (Information Security Laboratory)
Files

▲ Professor Choi Jae-seung, Department of Computer Science & Engineering
The paper 'DAFL: Directed Grey-box Fuzzing Guided by Data Dependency', co-authored by Professor Choi Jae-seung of the University's Department of Computer Science & Engineering, will be presented at USENIX Security Symposium 2023. USENIX Security Symposium is one of the four leading conferences in information security (S&P, CCS, USENIX, NDSS); it is listed at the highest grade in the Korean Institute of Information Scientists and Engineers' list of outstanding conferences and at a converted IF of 3 in the BK21 list of outstanding conferences. The research was carried out in collaboration with Kim Tae-eun, Professor Heo Ki-hong and Professor Cha Sang-kil of KAIST. The paper studies ways of improving directed fuzzing. Directed fuzzing is a technique that, given a target point in a program, tests that point intensively to detect vulnerabilities. The key to realizing this technique is accurately judging how close a given test case is to triggering a vulnerability at the target point. Existing directed fuzzing research relies chiefly on the program's control-flow graph to make this judgement, and so sometimes fails to capture the relationship to the bug at the target point properly. This research overcomes that problem by exploiting data dependency analysis, improving the effectiveness of directed fuzzing. USENIX Security Symposium will be held in Anaheim, United States, from 9 to 11 August; programme information is available at https://www.usenix.org/conference/usenixsecurity23/technical-sessions.