EconPapers    
Economics at your fingertips  
 

MemConFuzz: Memory Consumption Guided Fuzzing with Data Flow Analysis

Chunlai Du, Zhijian Cui, Yanhui Guo (), Guizhi Xu and Zhongru Wang
Additional contact information
Chunlai Du: School of Information Science and Technology, North China University of Technology, Beijing 100144, China
Zhijian Cui: School of Information Science and Technology, North China University of Technology, Beijing 100144, China
Yanhui Guo: Department of Computer Science, University of Illinois Springfield, Springfield, IL 62703, USA
Guizhi Xu: School of Information Science and Technology, North China University of Technology, Beijing 100144, China
Zhongru Wang: School of Information Science and Technology, North China University of Technology, Beijing 100144, China

Mathematics, 2023, vol. 11, issue 5, 1-19

Abstract: Uncontrolled heap memory consumption, a kind of critical software vulnerability, is utilized by attackers to consume a large amount of heap memory and consequently trigger crashes. There have been few works on the vulnerability fuzzing of heap consumption. Most of them, such as MemLock and PerfFuzz, have failed to consider the influence of data flow. We proposed a heap memory consumption guided fuzzing model named MemConFuzz. It extracts the locations of heap operations and data-dependent functions through static data flow analysis. Based on the data dependency, we proposed a seed selection algorithm in fuzzing to assign more energy to the samples with higher priority scores. The experiment results showed that the MemConFuzz has advantages over AFL, MemLock, and PerfFuzz with more quantity and less time consumption in exploiting the vulnerability of heap memory consumption.

Keywords: fuzzing; memory consumption; data flow; taint analysis (search for similar items in EconPapers)
JEL-codes: C (search for similar items in EconPapers)
Date: 2023
References: View complete reference list from CitEc
Citations:

Downloads: (external link)
https://www.mdpi.com/2227-7390/11/5/1222/pdf (application/pdf)
https://www.mdpi.com/2227-7390/11/5/1222/ (text/html)

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:gam:jmathe:v:11:y:2023:i:5:p:1222-:d:1085803

Access Statistics for this article

Mathematics is currently edited by Ms. Emma He

More articles in Mathematics from MDPI
Bibliographic data for series maintained by MDPI Indexing Manager ().

 
Page updated 2025-03-19
Handle: RePEc:gam:jmathe:v:11:y:2023:i:5:p:1222-:d:1085803