{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,20]],"date-time":"2026-07-20T10:08:13Z","timestamp":1784542093779,"version":"3.55.0"},"reference-count":39,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2023,6,1]],"date-time":"2023-06-01T00:00:00Z","timestamp":1685577600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,6,1]],"date-time":"2023-06-01T00:00:00Z","timestamp":1685577600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100014718","name":"Innovative Research Group Project of the National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62032010"],"award-info":[{"award-number":["62032010"]}],"id":[{"id":"10.13039\/100014718","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Mutation-based greybox fuzzing has been one of the most prevalent techniques for security vulnerability discovery and a great deal of research work has been proposed to improve both its efficiency and effectiveness. Mutation-based greybox fuzzing generates input cases by mutating the input seed, i.e., applying a sequence of mutation operators to randomly selected mutation positions of the seed. However, existing fruitful research work focuses on scheduling mutation operators, leaving the schedule of mutation positions as an overlooked aspect of fuzzing efficiency. This paper proposes a novel greybox fuzzing method, PosFuzz, that statistically schedules mutation positions based on their historical performance. PosFuzz makes use of a concept of effective position distribution to represent the semantics of the input and to guide the mutations. PosFuzz first utilizes Good-Turing frequency estimation to calculate an effective position distribution for each mutation operator. It then leverages two sampling methods in different mutating stages to select the positions from the distribution. We have implemented PosFuzz on top of AFL, AFLFast and MOPT, called Pos-AFL, -AFLFast and -MOPT respectively, and evaluated them on the UNIFUZZ benchmark (20 widely used open source programs) and LAVA-M dataset. The result shows that, under the same testing time budget, the Pos-AFL, -AFLFast and -MOPT outperform their counterparts in code coverage and vulnerability discovery ability. Compared with AFL, AFLFast, and MOPT, PosFuzz gets 21% more edge coverage and finds 133% more paths on average. It also triggers 275% more unique bugs on average.<\/jats:p>","DOI":"10.1186\/s42400-023-00143-2","type":"journal-article","created":{"date-parts":[[2023,6,1]],"date-time":"2023-06-01T03:38:02Z","timestamp":1685590682000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["PosFuzz: augmenting greybox fuzzing with effective position distribution"],"prefix":"10.1186","volume":"6","author":[{"given":"Yanyan","family":"Zou","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wei","family":"Zou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"JiaCheng","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nanyu","family":"Zhong","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yu","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ji","family":"Shi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wei","family":"Huo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,6,1]]},"reference":[{"key":"143_CR1","unstructured":"A Security Oriented, Feedback-driven, Evolutionary, Easy-to-use Fuzzer with Interesting Analysis Options. https:\/\/honggfuzz.dev\/"},{"key":"143_CR2","unstructured":"American Fuzzy Lop. https:\/\/lcamtuf.coredump.cx\/afl\/"},{"key":"143_CR3","doi-asserted-by":"crossref","unstructured":"Andronidis A, Cadar C (2022) Snapfuzz: high-throughput fuzzing of network applications","DOI":"10.1145\/3533767.3534376"},{"key":"143_CR4","doi-asserted-by":"crossref","unstructured":"Aschermann C, Schumilo S, Blazytko T, Gawlik R, Holz T (2019) Redqueen: fuzzing with input-to-state correspondence. In: NDSS, vol 19, pp 1\u201315","DOI":"10.14722\/ndss.2019.23371"},{"key":"143_CR5","doi-asserted-by":"crossref","unstructured":"B\u00f6hme M, Pham V-T, Roychoudhury A (2016) Coverage-based greybox fuzzing as markov chain. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pp 1032\u20131043","DOI":"10.1145\/2976749.2978428"},{"key":"143_CR6","doi-asserted-by":"crossref","unstructured":"B\u00f6hme M, Pham V-T, Nguyen M-D, Roychoudhury A (2017) Directed greybox fuzzing. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security, pp 2329\u20132344","DOI":"10.1145\/3133956.3134020"},{"key":"143_CR7","doi-asserted-by":"crossref","unstructured":"Chen P, Chen H (2018) Angora: Efficient fuzzing by principled search. In: 2018 IEEE symposium on security and privacy (SP). IEEE, pp 711\u2013725","DOI":"10.1109\/SP.2018.00046"},{"key":"143_CR8","unstructured":"Chen Y, Jiang Y, Ma F, Liang J, Wang M, Zhou C, Jiao X, Su Z (2019) Enfuzz: Ensemble fuzzing with seed synchronization among diverse fuzzers. In: 28th USENIX Security Symposium (USENIX Security 19), pp 1967\u20131983"},{"key":"143_CR9","doi-asserted-by":"crossref","unstructured":"Chen H, Xue Y, Li Y, Chen B, Xie X, Wu X, Liu Y (2018) Hawkeye: towards a desired directed grey-box fuzzer. In: Proceedings of the 2018 ACM SIGSAC conference on computer and communications security, pp 2095\u20132108","DOI":"10.1145\/3243734.3243849"},{"issue":"3","key":"143_CR10","doi-asserted-by":"publisher","first-page":"474","DOI":"10.1137\/1032082","volume":"32","author":"BD Flury","year":"1990","unstructured":"Flury BD (1990) Acceptance-rejection sampling made easy. SIAM Rev 32(3):474\u2013476","journal-title":"SIAM Rev"},{"issue":"3","key":"143_CR11","doi-asserted-by":"publisher","first-page":"217","DOI":"10.1080\/09296179508590051","volume":"2","author":"WA Gale","year":"1995","unstructured":"Gale WA, Sampson G (1995) Good-turing frequency estimation without tears. J Quant Linguist 2(3):217\u2013237","journal-title":"J Quant Linguist"},{"key":"143_CR12","unstructured":"Gan S, Zhang C, Chen P, Zhao B, Qin X, Wu D, Chen Z (2020) GREYONE: Data flow sensitive fuzzing. In: 29th USENIX security symposium (USENIX Security 20), pp 2577\u20132594"},{"key":"143_CR13","doi-asserted-by":"crossref","unstructured":"Gan S, Zhang C, Qin X, Tu X, Li K, Pei Z, Chen Z (2018) Collafl: Path sensitive fuzzing. In: 2018 IEEE symposium on security and privacy (SP). IEEE, pp 679\u2013696","DOI":"10.1109\/SP.2018.00040"},{"key":"143_CR14","doi-asserted-by":"crossref","unstructured":"Herrera A, Gunadi H, Magrath S, Norrish M, Payer M, Hosking AL (2021) Seed selection for successful fuzzing. In: Proceedings of the 30th ACM SIGSOFT international symposium on software testing and analysis, pp 230\u2013243","DOI":"10.1145\/3460319.3464795"},{"key":"143_CR15","doi-asserted-by":"crossref","unstructured":"Lemieux C, Sen K (2018) Fairfuzz: a targeted mutation strategy for increasing greybox fuzz testing coverage. In: Proceedings of the 33rd ACM\/IEEE international conference on automated software engineering, pp 475\u2013485","DOI":"10.1145\/3238147.3238176"},{"issue":"1","key":"143_CR16","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s42400-018-0002-y","volume":"1","author":"J Li","year":"2018","unstructured":"Li J, Zhao B, Zhang C (2018) Fuzzing: a survey. Cybersecurity 1(1):1\u201313","journal-title":"Cybersecurity"},{"issue":"3","key":"143_CR17","doi-asserted-by":"publisher","first-page":"1199","DOI":"10.1109\/TR.2018.2834476","volume":"67","author":"H Liang","year":"2018","unstructured":"Liang H, Pei X, Jia X, Shen W, Zhang J (2018) Fuzzing: state of the art. IEEE Trans Reliab 67(3):1199\u20131218","journal-title":"IEEE Trans Reliab"},{"key":"143_CR18","doi-asserted-by":"crossref","unstructured":"Liang J, Jiang Y, Chen Y, Wang M, Zhou C, Sun J (2018) Pafl: extend fuzzing optimizations of single mode to industrial parallel mode. In: Proceedings of the 2018 26th ACM joint meeting on European software engineering conference and symposium on the foundations of software engineering, pp 809\u2013814","DOI":"10.1145\/3236024.3275525"},{"key":"143_CR19","doi-asserted-by":"crossref","unstructured":"Liang J, Wang M, Zhou C, Wu Z, Jiang Y, Liu J, Liu Z, Sun J (2022) Pata: Fuzzing with path aware taint analysis. In: 2022 2022 IEEE symposium on security and privacy (SP). IEEE Computer Society, Los Alamitos, CA, USA, pp 154\u2013170","DOI":"10.1109\/SP46214.2022.9833594"},{"key":"143_CR20","unstructured":"LibFuzzer - a Library for Coverage-guided Fuzz Testing. https:\/\/llvm.org\/docs\/LibFuzzer.html"},{"key":"143_CR21","doi-asserted-by":"crossref","unstructured":"Li Y, Chen B, Chandramohan M, Lin S-W, Liu Y, Tiu A (2017) Steelix: program-state based binary fuzzing. In: Proceedings of the 2017 11th joint meeting on foundations of software engineering, pp 627\u2013637","DOI":"10.1145\/3106237.3106295"},{"key":"143_CR22","unstructured":"Li Y, Ji S, Chen Y, Liang S, Lee W-H, Chen Y, Lyu C, Wu C, Beyah R, Cheng P et al. (2021) Unifuzz: A holistic and pragmatic metrics-driven platform for evaluating fuzzers. In: 30th USENIX security symposium (USENIX Security 21). USENIX Association"},{"key":"143_CR23","unstructured":"Lyu C, Ji S, Zhang C, Li Y, Lee W-H, Song Y, Beyah R (2019) MOPT: Optimized mutation scheduling for fuzzers. In: 28th USENIX security symposium (USENIX security 19), pp 1949\u20131966"},{"key":"143_CR24","unstructured":"Man\u00e8s VJM, Han H, Han C, Cha SK, Egele M, Schwartz EJ, Woo M (2019) The art, science, and engineering of fuzzing: a survey. IEEE Trans Softw Eng"},{"key":"143_CR25","doi-asserted-by":"crossref","unstructured":"Nagy S, Hicks M (2019) Full-speed fuzzing: reducing fuzzing overhead through coverage-guided tracing. In: 2019 IEEE symposium on security and privacy (SP). IEEE, pp 787\u2013802","DOI":"10.1109\/SP.2019.00069"},{"key":"143_CR26","doi-asserted-by":"crossref","unstructured":"Petsios T, Zhao J, Keromytis AD, Jana S (2017) Slowfuzz: automated domain-independent detection of algorithmic complexity vulnerabilities. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security, pp 2155\u20132168","DOI":"10.1145\/3133956.3134073"},{"key":"143_CR27","unstructured":"Rajpal M, Blum W, Singh R (2017) Not all bytes are equal: neural byte sieve for fuzzing. arXiv preprint arXiv:1711.04596"},{"key":"143_CR28","doi-asserted-by":"crossref","unstructured":"Rawat S, Jain V, Kumar A, Cojocar L, Giuffrida C, Bos H (2017) Vuzzer: Application-aware evolutionary fuzzing. In: NDSS, vol 17, pp 1\u201314","DOI":"10.14722\/ndss.2017.23404"},{"key":"143_CR29","unstructured":"Schumilo S, Aschermann C, Gawlik R, Schinzel S, Holz T (2017) kafl: Hardware-assisted feedback fuzzing for OS kernels. In: 26th USENIX security symposium (USENIX Security 17), pp 167\u2013182"},{"key":"143_CR30","unstructured":"Serebryany K (2017) Oss-fuzz-google\u2019s continuous fuzzing service for open source software"},{"key":"143_CR31","unstructured":"Serebryany K, Bruening D, Potapenko A, Vyukov D (2012) AddressSanitizer: a fast address sanity checker. In: 2012 USENIX annual technical conference (USENIX ATC 12), pp 309\u2013318"},{"issue":"2","key":"143_CR32","doi-asserted-by":"publisher","first-page":"225","DOI":"10.1137\/0108013","volume":"8","author":"HS Shapiro","year":"1960","unstructured":"Shapiro HS, Silverman RA (1960) Alias-free sampling of random noise. J Soc Ind Appl Math 8(2):225\u2013248","journal-title":"J Soc Ind Appl Math"},{"key":"143_CR33","doi-asserted-by":"crossref","unstructured":"She D, Shah A, Jana S (2022) Effective seed scheduling for fuzzing with graph centrality analysis. In: 2022 2022 IEEE symposium on security and privacy (SP) (SP). IEEE Computer Society, Los Alamitos, CA, USA, pp 1558\u20131558","DOI":"10.1109\/SP46214.2022.9833761"},{"key":"143_CR34","doi-asserted-by":"crossref","unstructured":"Sundermeyer M, Schl\u00fcter R, Ney H (2012) LSTM neural networks for language modeling. In: Thirteenth annual conference of the international speech communication association","DOI":"10.21437\/Interspeech.2012-65"},{"key":"143_CR35","doi-asserted-by":"crossref","unstructured":"Wang J, Chen B, Wei L, Liu Y (2017) Skyfire: Data-driven seed generation for fuzzing. In: 2017 IEEE symposium on security and privacy (SP). IEEE, pp 579\u2013594","DOI":"10.1109\/SP.2017.23"},{"key":"143_CR36","doi-asserted-by":"crossref","unstructured":"Xu W, Kashyap S, Min C, Kim T (2017) Designing new operating primitives to improve fuzzing performance. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security, pp 2313\u20132328","DOI":"10.1145\/3133956.3134046"},{"key":"143_CR37","doi-asserted-by":"crossref","unstructured":"You W, Wang X, Ma S, Huang J, Zhang X, Wang X, Liang B (2019) Profuzzer: On-the-fly input type probing for better zero-day vulnerability discovery. In: 2019 IEEE symposium on security and privacy (SP). IEEE, pp 769\u2013786","DOI":"10.1109\/SP.2019.00057"},{"key":"143_CR38","unstructured":"Yun I, Lee S, Xu M, Jang Y, Kim T (2018) Qsym: a practical concolic execution engine tailored for hybrid fuzzing. In: 27th USENIX Security Symposium (USENIX Security 18). USENIX Association, Baltimore, MD, pp 745\u2013761"},{"key":"143_CR39","unstructured":"Zong P, Lv T, Wang D, Deng Z, Liang R, Chen K (2020) Fuzzguard: filtering out unreachable inputs in directed grey-box fuzzing through deep learning"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-023-00143-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-023-00143-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-023-00143-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,6,1]],"date-time":"2023-06-01T03:38:28Z","timestamp":1685590708000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-023-00143-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,6,1]]},"references-count":39,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2023,12]]}},"alternative-id":["143"],"URL":"https:\/\/doi.org\/10.1186\/s42400-023-00143-2","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,6,1]]},"assertion":[{"value":"6 August 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 February 2023","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 June 2023","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"11"}}