RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    Advancing System and Software Reliability Through Differential Fuzzing and Machine Learning = 차등 퍼징과 머신러닝 기반 시스템 및 소프트웨어 신뢰성 향상 기법

    한글로보기

    https://www.riss.kr/link?id=T17314394

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    Software systems increasingly serve as the foundation of modern infrastructure, from web browsers to critical back-end services. Ensuring their reliability requires identifying and eliminating a wide range of bugs, which broadly fall into two categories: memory safety bugs and semantic (logic) bugs. While memory bugs—such as buffer overflows and use-after-free errors—have long been the focus of fuzzing research due to their security implications, semantic bugs are often more subtle and equally damaging, especially in user-facing applications where incorrect behavior may silently propagate.

    This dissertation presents a unified framework for detecting both memory and semantic bugs using differential and coverage-guided fuzzing. First, we introduce CrFuzz, a fuzzing framework that augments input validation awareness to trigger deep memory corruption bugs in multi-purpose programs. Then, we shift focus to rendering correctness in web browsers with R2Z2, a system that applies differential testing to detect rendering regressions by comparing visual outputs across browser versions. Finally, we present Metamong, an automated framework that detects render-update bugs without false positives by exploiting the HTML yielding rule to establish a correctness oracle.

    By combining techniques for detecting low-level memory corruption and high-level behavioral inconsistencies, this dissertation argues that a complete view of software quality must treat both categories of bugs as first-class concerns. Our tools have uncovered dozens of previously unknown vulnerabilities across widely deployed systems, demonstrating that bridging memory safety and semantic correctness leads to more reliable software.
    번역하기

    Software systems increasingly serve as the foundation of modern infrastructure, from web browsers to critical back-end services. Ensuring their reliability requires identifying and eliminating a wide range of bugs, which broadly fall into two categori...

    Software systems increasingly serve as the foundation of modern infrastructure, from web browsers to critical back-end services. Ensuring their reliability requires identifying and eliminating a wide range of bugs, which broadly fall into two categories: memory safety bugs and semantic (logic) bugs. While memory bugs—such as buffer overflows and use-after-free errors—have long been the focus of fuzzing research due to their security implications, semantic bugs are often more subtle and equally damaging, especially in user-facing applications where incorrect behavior may silently propagate.

    This dissertation presents a unified framework for detecting both memory and semantic bugs using differential and coverage-guided fuzzing. First, we introduce CrFuzz, a fuzzing framework that augments input validation awareness to trigger deep memory corruption bugs in multi-purpose programs. Then, we shift focus to rendering correctness in web browsers with R2Z2, a system that applies differential testing to detect rendering regressions by comparing visual outputs across browser versions. Finally, we present Metamong, an automated framework that detects render-update bugs without false positives by exploiting the HTML yielding rule to establish a correctness oracle.

    By combining techniques for detecting low-level memory corruption and high-level behavioral inconsistencies, this dissertation argues that a complete view of software quality must treat both categories of bugs as first-class concerns. Our tools have uncovered dozens of previously unknown vulnerabilities across widely deployed systems, demonstrating that bridging memory safety and semantic correctness leads to more reliable software.

    더보기

    국문 초록 (Abstract) kakao i 다국어 번역

    현대 소프트웨어 시스템은 웹 브라우저, 운영체제, 클라우드 인프라 등 다양한 형태로 우리의 일상과 산업 전반에 깊이 관여하고 있으며, 이들 시스템의 신뢰성과 안정성은 사회적 기반 시설의 핵심 요소로 간주되고 있다. 이러한 시스템의 품질을 보장하기 위해서는 다양한 종류의 버그를 체계적으로 탐지하고 제거하는 과정이 필수적이며, 특히 버그는 크게 메모리 안전성 버그와 의미적(논리적) 버그라는 두 가지 주요 범주로 나뉜다. 메모리 버그는 버퍼 오버플로우, use-after-free와 같이 명확한 보안 취약점을 유발할 수 있기 때문에 오랜 기간 퍼징(fuzzing) 연구의 중심 대상이 되어 왔다. 반면, 의미적 버그는 명시적인 충돌(crash)을 유발하지 않음에도 불구하고, 프로그램의 동작 오류를 야기하며 사용자 경험을 훼손하거나 보이지 않는 방식으로 잘못된 결과를 유도하는 등 실질적인 피해를 초래할 수 있다.

    본 논문은 메모리 버그와 의미적 버그를 통합적으로 탐지하기 위한 새로운 퍼징 기반 프레임워크를 제안하며, differential fuzzing과 coverage-guided fuzzing 기법을 활용하여 이 두 범주에 대한 체계적인 접근을 시도한다. 먼저, CrFuzz는 입력 검증 로직에 주목하여 기존 퍼징 기법들이 접근하기 어려운 깊은 코드 경로에서 메모리 손상 버그를 유발하도록 설계된 퍼징 프레임워크이다. 이를 통해 다양한 목적의 복합 프로그램에서 실질적인 취약점을 효율적으로 탐지할 수 있음을 보인다.

    다음으로, R2Z2는 웹 브라우저의 시각적 정확성에 중점을 두며, 동일한 입력에 대해 브라우저의 버전 간 렌더링 결과를 비교함으로써 시각적 회귀(regression) 버그를 효과적으로 탐지하는 differential testing 시스템이다. 이는 사용자가 직접 관찰할 수 있는 버그를 자동으로 검출할 수 있다는 점에서 의미 있는 진보를 이룬다.

    마지막으로, Metamong은 기존의 자동화된 방법론들이 갖는 거짓 양성(false positive) 문제를 해소하고자, HTML 표준에 정의된 yielding 규칙을 이용하여 정확성 오라클을 구성하는 방식으로 렌더-업데이트(render-update) 버그를 탐지한다. Metamong은 동적으로 변경된 웹 페이지의 렌더링 상태를 기반으로 두 HTML 문서 간의 차이를 비교함으로써, 의도하지 않은 시각적 변경을 정밀하게 탐지할 수 있도록 설계되었다.

    본 연구는 메모리 안전성과 의미적 정확성을 모두 포괄하는 소프트웨어 품질 보증 프레임워크를 제시하며, 이 두 가지 버그 유형을 동등하게 다루는 것이 실질적인 소프트웨어 신뢰성을 확보하는 데 있어 필수적임을 실증적으로 제시한다. 제안된 시스템들은 실제 널리 사용되는 소프트웨어에서 수십 개의 신규 취약점을 발견하였으며, 다수는 개발사로부터 인정 및 수정 조치를 받음으로써 본 연구의 실용성과 확장 가능성을 입증하였다.
    번역하기

    현대 소프트웨어 시스템은 웹 브라우저, 운영체제, 클라우드 인프라 등 다양한 형태로 우리의 일상과 산업 전반에 깊이 관여하고 있으며, 이들 시스템의 신뢰성과 안정성은 사회적 기반 시...

    현대 소프트웨어 시스템은 웹 브라우저, 운영체제, 클라우드 인프라 등 다양한 형태로 우리의 일상과 산업 전반에 깊이 관여하고 있으며, 이들 시스템의 신뢰성과 안정성은 사회적 기반 시설의 핵심 요소로 간주되고 있다. 이러한 시스템의 품질을 보장하기 위해서는 다양한 종류의 버그를 체계적으로 탐지하고 제거하는 과정이 필수적이며, 특히 버그는 크게 메모리 안전성 버그와 의미적(논리적) 버그라는 두 가지 주요 범주로 나뉜다. 메모리 버그는 버퍼 오버플로우, use-after-free와 같이 명확한 보안 취약점을 유발할 수 있기 때문에 오랜 기간 퍼징(fuzzing) 연구의 중심 대상이 되어 왔다. 반면, 의미적 버그는 명시적인 충돌(crash)을 유발하지 않음에도 불구하고, 프로그램의 동작 오류를 야기하며 사용자 경험을 훼손하거나 보이지 않는 방식으로 잘못된 결과를 유도하는 등 실질적인 피해를 초래할 수 있다.

    본 논문은 메모리 버그와 의미적 버그를 통합적으로 탐지하기 위한 새로운 퍼징 기반 프레임워크를 제안하며, differential fuzzing과 coverage-guided fuzzing 기법을 활용하여 이 두 범주에 대한 체계적인 접근을 시도한다. 먼저, CrFuzz는 입력 검증 로직에 주목하여 기존 퍼징 기법들이 접근하기 어려운 깊은 코드 경로에서 메모리 손상 버그를 유발하도록 설계된 퍼징 프레임워크이다. 이를 통해 다양한 목적의 복합 프로그램에서 실질적인 취약점을 효율적으로 탐지할 수 있음을 보인다.

    다음으로, R2Z2는 웹 브라우저의 시각적 정확성에 중점을 두며, 동일한 입력에 대해 브라우저의 버전 간 렌더링 결과를 비교함으로써 시각적 회귀(regression) 버그를 효과적으로 탐지하는 differential testing 시스템이다. 이는 사용자가 직접 관찰할 수 있는 버그를 자동으로 검출할 수 있다는 점에서 의미 있는 진보를 이룬다.

    마지막으로, Metamong은 기존의 자동화된 방법론들이 갖는 거짓 양성(false positive) 문제를 해소하고자, HTML 표준에 정의된 yielding 규칙을 이용하여 정확성 오라클을 구성하는 방식으로 렌더-업데이트(render-update) 버그를 탐지한다. Metamong은 동적으로 변경된 웹 페이지의 렌더링 상태를 기반으로 두 HTML 문서 간의 차이를 비교함으로써, 의도하지 않은 시각적 변경을 정밀하게 탐지할 수 있도록 설계되었다.

    본 연구는 메모리 안전성과 의미적 정확성을 모두 포괄하는 소프트웨어 품질 보증 프레임워크를 제시하며, 이 두 가지 버그 유형을 동등하게 다루는 것이 실질적인 소프트웨어 신뢰성을 확보하는 데 있어 필수적임을 실증적으로 제시한다. 제안된 시스템들은 실제 널리 사용되는 소프트웨어에서 수십 개의 신규 취약점을 발견하였으며, 다수는 개발사로부터 인정 및 수정 조치를 받음으로써 본 연구의 실용성과 확장 가능성을 입증하였다.

    더보기

    목차 (Table of Contents)

    • Abstract i
    • Table of Contents iii
    • Introduction vii
    • List of Figures xii
    • List of Tables i
    • Abstract i
    • Table of Contents iii
    • Introduction vii
    • List of Figures xii
    • List of Tables i
    • 1. CrFuzz: Fuzzing Multi-purpose Programs through Input Validation 1
    • 1.1. Introduction 1
    • 1.2. Background and Motivation 3
    • 1.2.1. Background 4
    • 1.2.2. Motivation 7
    • 1.3. Design of CrFuzz 9
    • 1.3.1. Learning and Testing Validity 11
    • 1.3.1.1. Validity Feature Selection. 12
    • 1.3.1.2. Learning Validity Cluster. 14
    • 1.3.1.3. Testing Validity. 17
    • 1.3.2. Multi-purpose Program Fuzzing 17
    • 1.4. Implementation 19
    • 1.5. Evaluation 20
    • 1.5.1. Accuracy of Validity Checker 21
    • 1.5.2. Fuzzing Efficiency of CrFuzz 24
    • 1.5.3. New Vulnerabilities Found by CrFuzz 27
    • 1.6. Related Work 29
    • 1.7. Conclusion 31
    • 2. R2Z2: Detecting Rendering Regressions in Web Browsers through Differential Fuzz Testing 32
    • 2.1. Introduction 32
    • 2.2. Background 34
    • 2.2.1. Fuzz Testing and Differential Testing 34
    • 2.2.2. The Rendering Pipeline of a Web Browser 36
    • 2.2.3. Rendering Bugs 38
    • 2.3. Challenges and Our Approach 40
    • 2.3.1. Challenges of Rendering Bugs 40
    • 2.3.2. Our Approach 43
    • 2.4. Design of R2Z2 45
    • 2.4.1. Change Detector 46
    • 2.4.2. Bisect Analysis 48
    • 2.4.3. Regression Oracle 49
    • 2.4.3.1. Interoperability Oracle. 50
    • 2.4.3.2. Non-feature-update Oracle. 52
    • 2.4.4. Rendering Pipeline Analysis 54
    • 2.5. Implementation 56
    • 2.6. Evaluation 58
    • 2.6.1. Effectiveness of Change Detection 60
    • 2.6.2. Effectiveness of Bisect Analysis 60
    • 2.6.3. Effectiveness of Regression Oracle 62
    • 2.6.4. Correctness of Rendering Pipeline Analysis 64
    • 2.7. Discussion 65
    • 2.8. Related Work 66
    • 2.9. Conclusion 68
    • 3. Metamong: Detecting Render-Update Bugs in Web Browsers through Fuzzing 70
    • 3.1. Introduction 70
    • 3.2. Background 73
    • 3.2.1. Fuzz Testing and Differential Testing 73
    • 3.2.2. The Rendering of a Web Browser 74
    • 3.2.3. Render-Update Bug 77
    • 3.3. Challenge and Approach 79
    • 3.3.1. Challenge 79
    • 3.3.2. Our Approach 82
    • 3.4. Design of Metamong 84
    • 3.4.1. Overview 85
    • 3.4.2. Page Mutator 87
    • 3.4.3. Render-Update Oracle 89
    • 3.5. Implementation 92
    • 3.6. Evaluation 93
    • 3.6.1. Effectiveness of Render-Update Oracle 93
    • 3.6.1.1. Recall of Render-Update Oracle. 93
    • 3.6.1.2. Accuracy of Render-Update Oracle. 96
    • 3.6.2. Effectiveness of Page Mutator. 98
    • 3.6.3. New Render-Update Bugs Discovered by Metamong. 99
    • 3.7. Related Work 102
    • 3.8. Discussion 104
    • 3.9. Conclusion 105
    • Conclusion 107
    • Bibliography 108
    • Abstract 109
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼