{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,22]],"date-time":"2026-01-22T08:25:11Z","timestamp":1769070311035,"version":"3.49.0"},"reference-count":52,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2024,6,26]],"date-time":"2024-06-26T00:00:00Z","timestamp":1719360000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2024,6,26]],"date-time":"2024-06-26T00:00:00Z","timestamp":1719360000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cloud Comp"],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Coverage-guided fuzzing is one of the most popular approaches to detect bugs in programs. Existing work has shown that coverage metrics are a crucial factor in guiding fuzzing exploration of targets. A fine-grained coverage metric can help fuzzing to detect more bugs and trigger more execution states. Cloud-native applications that written by Golang play an important role in the modern computing paradigm. However, existing fuzzers for Golang still employ coarse-grained block coverage metrics, and there is no fuzzer specifically for cloud-native applications, which hinders the bug detection in cloud-native applications. Using fine-grained coverage metrics introduces more seeds and even leads to seed explosion, especially in large targets such as cloud-native applications.<\/jats:p><jats:p> Therefore, we employ an accurate edge coverage metric in fuzzer for Golang, which achieves finer test granularity and more accurate coverage information than block coverage metrics. To mitigate the seed explosion problem caused by fine-grained coverage metrics and large target sizes, we propose smart seed selection and adaptive task scheduling algorithms based on a variant of the classical adversarial multi-armed bandit (AMAB) algorithm. Extensive evaluation of our prototype on 16 targets in real-world cloud-native infrastructures shows that our approach detects 233% more bugs than go-fuzz, achieving an average coverage improvement of 100.7%. Our approach effectively mitigates seed explosion by reducing the number of seeds generated by 41% and introduces only 14% performance overhead.<\/jats:p>","DOI":"10.1186\/s13677-024-00681-1","type":"journal-article","created":{"date-parts":[[2024,6,26]],"date-time":"2024-06-26T17:03:23Z","timestamp":1719421403000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Adaptive scheduling-based fine-grained greybox fuzzing for cloud-native applications"],"prefix":"10.1186","volume":"13","author":[{"given":"Jiageng","family":"Yang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chuanyi","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Binxing","family":"Fang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,6,26]]},"reference":[{"key":"681_CR1","unstructured":"Zalewski M (2014) American fuzzy lop. https:\/\/lcamtuf.coredump.cx\/afl. Accessed 17 Feb 2024"},{"key":"681_CR2","unstructured":"Vyukov D (2021) go-fuzz: randomized testing for go. https:\/\/github.com\/dvyukov\/go-fuzz. Accessed 17 Feb 2024"},{"key":"681_CR3","unstructured":"Wilk J (2019) Python-afl. https:\/\/jwilk.net\/software\/python-afl. Accessed 17 Feb 2024"},{"key":"681_CR4","doi-asserted-by":"crossref","unstructured":"Jiang J, Xu H, Zhou Y (2021) Rulf: Rust library fuzzing via api dependency graph traversal. In: 2021 36th IEEE\/ACM International Conference on Automated Software Engineering (ASE). IEEE, Melbourne, pp 581\u2013592","DOI":"10.1109\/ASE51524.2021.9678813"},{"key":"681_CR5","unstructured":"Google (2021) Go fuzzing. https:\/\/go.dev\/security\/fuzz. Accessed 17 Feb 2024"},{"key":"681_CR6","doi-asserted-by":"crossref","unstructured":"Aschermann C, Schumilo S, Blazytko T, Gawlik R, Holz T (2019) Redqueen: Fuzzing with input-to-state correspondence. In: Network and Distributed Systems Security (NDSS) Symposium,\u00a0vol 19. The Internet Society, San Diego,\u00a0 pp 1\u201315","DOI":"10.14722\/ndss.2019.23371"},{"key":"681_CR7","unstructured":"Fioraldi A, Maier D, Ei\u00dffeldt H, Heuse M (2020) Afl++ combining incremental steps of fuzzing research. In: Proceedings of the 14th USENIX Conference on Offensive Technologies. {USENIX} Association, pp 10\u201310"},{"issue":"9","key":"681_CR8","first-page":"1980","volume":"47","author":"VT Pham","year":"2019","unstructured":"Pham VT, B\u00f6hme M, Santosa AE, C\u0103ciulescu AR, Roychoudhury A (2019) Smart greybox fuzzing. IEEE Trans Softw Eng 47(9):1980\u20131997","journal-title":"IEEE Trans Softw Eng"},{"key":"681_CR9","unstructured":"Schumilo S, Aschermann C, Gawlik R, Schinzel S, Holz T (2017) kafl: Hardware-assisted feedback fuzzing for os kernels. In: 26th USENIX Security Symposium (USENIX Security 17). USENIX Association, Vancouver, pp 167\u2013182"},{"key":"681_CR10","unstructured":"Wang J, Duan Y, Song W, Yin H, Song C (2019) Be sensitive and collaborative: Analyzing impact of coverage metrics in greybox fuzzing. In: Proceedings of the 22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID\u201919). USENIX Association, Beijing, pp 1\u201315"},{"key":"681_CR11","doi-asserted-by":"crossref","unstructured":"Wang J, Song C, Yin H (2021) Reinforcement learning-based hierarchical seed scheduling for greybox fuzzing. In: Network and Distributed Systems Security (NDSS) Symposium, The Internet Society, virtual, vol 2021","DOI":"10.14722\/ndss.2021.24486"},{"issue":"3","key":"681_CR12","doi-asserted-by":"publisher","first-page":"1544","DOI":"10.1109\/TDSC.2020.3027690","volume":"19","author":"S Gan","year":"2020","unstructured":"Gan S, Zhang C, Qin X, Tu X, Li K, Pei Z, Chen Z (2020) Path sensitive fuzzing for native applications. IEEE Trans Dependable Secure Comput 19(3):1544\u20131561","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"681_CR13","doi-asserted-by":"crossref","unstructured":"Gan S, Zhang C, Qin X, Tu X, Li K, Pei Z, Chen Z (2018) Collafl: Path sensitive fuzzing. In: 2018 IEEE Symposium on Security and Privacy (SP). {IEEE} Computer Society, San Francisco, pp 679\u2013696","DOI":"10.1109\/SP.2018.00040"},{"key":"681_CR14","doi-asserted-by":"crossref","unstructured":"Auer P, Cesa-Bianchi N, Freund Y, Schapire RE (1995) Gambling in a rigged casino: The adversarial multi-armed bandit problem. In: Proceedings of IEEE 36th annual foundations of computer science. {IEEE} Computer Society, Milwaukee, pp 322\u2013331","DOI":"10.1109\/SFCS.1995.492488"},{"key":"681_CR15","doi-asserted-by":"crossref","unstructured":"Wang Y, Jia X, Liu Y, Zeng K, Bao T, Wu D, Su P (2020) Not all coverage measurements are equal: Fuzzing by coverage accounting for input prioritization. In: Network and Distributed Systems Security (NDSS) Symposium. The Internet Society, San Diego","DOI":"10.14722\/ndss.2020.24422"},{"key":"681_CR16","doi-asserted-by":"crossref","unstructured":"Rawat S, Jain V, Kumar A, Cojocar L, Giuffrida C, Bos H (2017) Vuzzer: Application-aware evolutionary fuzzing. In: Network and Distributed Systems Security (NDSS) Symposium. The Internet Society, San Diego, vol 17. pp 1\u201314","DOI":"10.14722\/ndss.2017.23404"},{"key":"681_CR17","doi-asserted-by":"crossref","unstructured":"B\u00f6hme M, Pham VT, Nguyen MD, Roychoudhury A (2017) Directed greybox fuzzing. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. Association for Computing Machinery, New York, pp 2329\u20132344","DOI":"10.1145\/3133956.3134020"},{"key":"681_CR18","doi-asserted-by":"crossref","unstructured":"B\u00f6hme M, Pham VT, Roychoudhury A (2016) Coverage-based greybox fuzzing as markov chain. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. Association for Computing Machinery, New York, pp 1032\u20131043","DOI":"10.1145\/2976749.2978428"},{"key":"681_CR19","doi-asserted-by":"crossref","unstructured":"Coppik N, Schwahn O, Suri N (2019) Memfuzz: Using memory accesses to guide fuzzing. In: 2019 12th IEEE Conference on Software Testing, Validation and Verification (ICST). IEEE, Xi'an, pp 48\u201358","DOI":"10.1109\/ICST.2019.00015"},{"key":"681_CR20","doi-asserted-by":"crossref","unstructured":"Chen P, Chen H (2018) Angora: Efficient fuzzing by principled search. In: 2018 IEEE Symposium on Security and Privacy (SP). {IEEE} Computer Society, San Francisco, pp 711\u2013725","DOI":"10.1109\/SP.2018.00046"},{"key":"681_CR21","doi-asserted-by":"crossref","unstructured":"Jiang ZM, Bai JJ, Lu K, Hu SM (2022) Context-sensitive and directional concurrency fuzzing for data-race detection. In: Proceedings of the 29th Network and Distributed System Security Symposium (NDSS). The Internet Society, San Diego, pp 1\u201318","DOI":"10.14722\/ndss.2022.24296"},{"key":"681_CR22","unstructured":"Yue T, Wang P, Tang Y, Wang E, Yu B, Lu K, Zhou X (2020) Ecofuzz: Adaptive energy-saving greybox fuzzing as a variant of the adversarial multi-armed bandit. In: Proceedings of the 29th USENIX Conference on Security Symposium. USENIX Association, Boston, pp 2307\u20132324"},{"key":"681_CR23","unstructured":"Wang D, Zhang Z, Zhang H, Qian Z, Krishnamurthy SV, Abu-Ghazaleh NB (2021) Syzvegas: Beating kernel fuzzing odds with reinforcement learning. In: 30th USENIX Security Symposium (USENIX Security 21). USENIX Association, Vancouver, pp 2741\u20132758"},{"key":"681_CR24","unstructured":"Jiang, Zu-Ming and Bai, Jia-Ju and Lu, Kangjie and Hu, Shi-Min (2020) Fuzzing error handling code using context-sensitive software fault injection. In: Proceedings of the 29th USENIX Conference on Security Symposium. USENIX Association, Boston, pp 2595\u20132612"},{"key":"681_CR25","unstructured":"Google (2015) Libfuzzer: a library for coverage-guided fuzz testing. https:\/\/llvm.org\/docs\/LibFuzzer.html. Accessed 17 Feb 2024"},{"key":"681_CR26","unstructured":"Swiecki R (2017) Honggfuzz. https:\/\/honggfuzz.dev. Accessed 17 Feb 2024"},{"key":"681_CR27","unstructured":"Google (2016) Oss-fuzz: Continuous fuzzing for open source software. https:\/\/github.com\/google\/oss-fuzz. Accessed 17 Feb 2024"},{"key":"681_CR28","doi-asserted-by":"crossref","unstructured":"Wang T, Wei T, Gu G, Zou W (2010) Taintscope: A checksum-aware directed fuzzing tool for automatic software vulnerability detection. In: 2010 IEEE Symposium on Security and Privacy. {IEEE} Computer Society, Oakland, pp 497\u2013512","DOI":"10.1109\/SP.2010.37"},{"key":"681_CR29","doi-asserted-by":"crossref","unstructured":"Stephens N, Grosen J, Salls C, Dutcher A, Wang R, Corbetta J, Shoshitaishvili Y, Kruegel C, Vigna G (2016) Driller: Augmenting fuzzing through selective symbolic execution. In: Network and Distributed Systems Security (NDSS) Symposium, vol 16. The Internet Society, San Diego, pp 1\u201316","DOI":"10.14722\/ndss.2016.23368"},{"key":"681_CR30","doi-asserted-by":"crossref","unstructured":"Zhao L, Duan Y, Yin H, Xuan J (2019) Send hardest problems my way: Probabilistic path prioritization for hybrid fuzzing. In: Network and Distributed Systems Security (NDSS) Symposium. The Internet Society, San Diego, pp 1\u201318","DOI":"10.14722\/ndss.2019.23504"},{"key":"681_CR31","doi-asserted-by":"crossref","unstructured":"Chen P, Liu J, Chen H (2019) Matryoshka: fuzzing deeply nested branches. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security. Association for Computing Machinery, New York, pp 499\u2013513","DOI":"10.1145\/3319535.3363225"},{"key":"681_CR32","doi-asserted-by":"crossref","unstructured":"Han H, Cha SK (2017) Imf: Inferred model-based fuzzer. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. Association for Computing Machinery, New York, pp 2345\u20132358","DOI":"10.1145\/3133956.3134103"},{"key":"681_CR33","doi-asserted-by":"crossref","unstructured":"Peng H, Shoshitaishvili Y, Payer M (2018) T-fuzz: fuzzing by program transformation. In: 2018 IEEE Symposium on Security and Privacy (SP). {IEEE} Computer Society, San Francisco, pp 697\u2013710","DOI":"10.1109\/SP.2018.00056"},{"key":"681_CR34","doi-asserted-by":"crossref","unstructured":"Godefroid P, Peleg H, Singh R (2017) Learn &fuzz: Machine learning for input fuzzing. In: 2017 32nd IEEE\/ACM International Conference on Automated Software Engineering (ASE). {IEEE} Computer Society, Urbana, pp 50\u201359","DOI":"10.1109\/ASE.2017.8115618"},{"key":"681_CR35","doi-asserted-by":"crossref","unstructured":"She D, Pei K, Epstein D, Yang J, Ray B, Jana S (2019) Neuzz: Efficient fuzzing with neural program smoothing. In: 2019 IEEE Symposium on Security and Privacy (SP). {IEEE} Computer Society, San Francisco, pp 803\u2013817","DOI":"10.1109\/SP.2019.00052"},{"key":"681_CR36","doi-asserted-by":"crossref","unstructured":"Zhang G, Wang P, Yue T, Kong X, Huang S, Zhou X, Lu K (2022) Mobfuzz: Adaptive multi-objective optimization in gray-box fuzzing. In: Network and Distributed Systems Security (NDSS) Symposium, vol 16. The Internet Society, San Diego, pp 1\u201318","DOI":"10.14722\/ndss.2022.24314"},{"key":"681_CR37","doi-asserted-by":"crossref","unstructured":"Bernhard L, Scharnowski T, Schloegel M, Blazytko T, Holz T (2022) Jit-picking: Differential fuzzing of javascript engines. In: Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, CCS \u201922. Association for Computing Machinery, New York, pp 351\u2013364","DOI":"10.1145\/3548606.3560624"},{"key":"681_CR38","doi-asserted-by":"crossref","unstructured":"Gro\u00df S, Koch S, Bernhard L, Holz T, Johns M (2023) Fuzzilli: Fuzzing for javascript jit compiler vulnerabilities. In: Network and Distributed Systems Security (NDSS) Symposium. vol 2023. The Internet Society, San Diego, pp 1\u201318","DOI":"10.14722\/ndss.2023.24290"},{"key":"681_CR39","doi-asserted-by":"crossref","unstructured":"Wang J, Chen B, Wei L, Liu Y (2017) Skyfire: Data-driven seed generation for fuzzing. In: 2017 IEEE Symposium on Security and Privacy (SP). {IEEE} Computer Society, San Jose, pp 579\u2013594","DOI":"10.1109\/SP.2017.23"},{"key":"681_CR40","unstructured":"Wang J, Zhang Z, Liu S, Du X, Chen J (2023) Fuzzjit: Oracle-enhanced fuzzing for javascript engine jit compiler. In: Proceedings of the 32nd USENIX Conference on Security Symposium. USENIX Association, Anaheim, CA, pp 1865\u20131882"},{"key":"681_CR41","doi-asserted-by":"crossref","unstructured":"Corina J, Machiry A, Salls C, Shoshitaishvili Y, Hao S, Kruegel C, Vigna G (2017) Difuze: Interface aware fuzzing for kernel drivers. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. Association for Computing Machinery, New York, pp 2123\u20132138","DOI":"10.1145\/3133956.3134069"},{"key":"681_CR42","unstructured":"Google (2015) syzkaller is an unsupervised coverage-guided kernel fuzzer. https:\/\/github.com\/google\/syzkaller. Accessed 17 Feb 2024"},{"key":"681_CR43","doi-asserted-by":"crossref","unstructured":"Xu W, Moon H, Kashyap S, Tseng PN, Kim T (2019) Fuzzing file systems via two-dimensional input space exploration. In: 2019 IEEE Symposium on Security and Privacy (SP). {IEEE} Computer Society, San Francisco, pp 818\u2013834","DOI":"10.1109\/SP.2019.00035"},{"key":"681_CR44","doi-asserted-by":"crossref","unstructured":"Banks G, Cova M, Felmetsger V, Almeroth K, Kemmerer R, Vigna G (2006) Snooze: toward a stateful network protocol fuzzer. In: Information Security, vol 4176. Springer Berlin Heidelberg, Berlin, pp 343\u2013358","DOI":"10.1007\/11836810_25"},{"key":"681_CR45","doi-asserted-by":"crossref","unstructured":"Maier D, Bittner O, Munier M, Beier J (2022) Fitm: Binary-only coverage-guided fuzzing for stateful network protocols. In: Workshop on Binary Analysis Research (BAR), vol 2022. The Internet Society, San Diego, pp 1\u201311","DOI":"10.14722\/bar.2022.23008"},{"key":"681_CR46","unstructured":"Chen L, Wang Y, Cai Q, Zhan Y, Hu H, Linghu J, Hou Q, Zhang C, Duan H, Xue Z (2021) Sharing more and checking less: Leveraging common input keywords to detect bugs in embedded systems. In: USENIX Security Symposium. {USENIX} Association, pp 303\u2013319"},{"key":"681_CR47","doi-asserted-by":"crossref","unstructured":"Qin C, Peng J, Liu P, Zheng Y, Cheng K, Zhang W, Sun L (2023) Ucrf: Static analyzing firmware to generate under-constrained seed for fuzzing soho router. Computers & Security, vol 128, pp 103\u2013157","DOI":"10.1016\/j.cose.2023.103157"},{"key":"681_CR48","doi-asserted-by":"crossref","unstructured":"Ma F, Chen Y, Ren M, Zhou Y, Jiang Y, Chen T, Li H, Sun J (2023) Loki: State-aware fuzzing framework for the implementation of blockchain consensus protocols. In: Network and Distributed Systems Security (NDSS) Symposium, vol 2023. The Internet Society, San Diego, pp 1\u201318","DOI":"10.14722\/ndss.2023.24078"},{"key":"681_CR49","doi-asserted-by":"crossref","unstructured":"Zuo F, Luo Z, Yu J, Liu Z, Jiang Y (2021) Pavfuzz: State-sensitive fuzz testing of protocols in autonomous vehicles. In: 2021 58th ACM\/IEEE Design Automation Conference (DAC). IEEE, San Francisco, pp 823\u2013828","DOI":"10.1109\/DAC18074.2021.9586321"},{"key":"681_CR50","doi-asserted-by":"crossref","unstructured":"Lemieux C, Sen K (2018) Fairfuzz: A targeted mutation strategy for increasing greybox fuzz testing coverage. In: 2018 33rd IEEE\/ACM International Conference on Automated Software Engineering (ASE), ACM, Montpellier, pp 475\u2013485","DOI":"10.1145\/3238147.3238176"},{"key":"681_CR51","unstructured":"Lyu C, Ji S, Zhang C, Li Y, Lee WH, Song Y, Beyah R (2019) Mopt: Optimized mutation scheduling for fuzzers. In: 28th USENIX Security Symposium (USENIX Security 19). USENIX Association, Santa Clara, pp 1949\u20131966"},{"key":"681_CR52","doi-asserted-by":"crossref","unstructured":"Woo M, Cha SK, Gottlieb S, Brumley D (2013) Scheduling black-box mutational fuzzing. In: Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security. Association for Computing Machinery, New York, pp 511\u2013522","DOI":"10.1145\/2508859.2516736"}],"container-title":["Journal of Cloud Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13677-024-00681-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s13677-024-00681-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13677-024-00681-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,26]],"date-time":"2024-06-26T17:04:42Z","timestamp":1719421482000},"score":1,"resource":{"primary":{"URL":"https:\/\/journalofcloudcomputing.springeropen.com\/articles\/10.1186\/s13677-024-00681-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,6,26]]},"references-count":52,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2024,12]]}},"alternative-id":["681"],"URL":"https:\/\/doi.org\/10.1186\/s13677-024-00681-1","relation":{},"ISSN":["2192-113X"],"issn-type":[{"value":"2192-113X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,6,26]]},"assertion":[{"value":"19 February 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 June 2024","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 June 2024","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"This article does not contain any studies with human participants or animals performed by any of the authors.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval and consent to participate"}},{"value":"The authors read and approved the final manuscript.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}},{"value":"The authors declare no competing interests.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"118"}}