Investigating a Project �& Picking a Function to Fuzz
Fuzz Dojo
Steven Wirsz
Arizona State University
Start with a Simple Project
Fuzz driver difficulty is determined by more than the rated difficulty!
Difficulty Factors:
Any project you are personally familiar with!
#
Picking a Function to Fuzz
Important Criteria:
#
Fuzz Driver Creation Process
Target Identification
Program Analysis
�Fuzz Driver Creation
#
Good Fuzz Driver Development Methodology
A good harness achieves both high code coverage and a high rate of bug identification.
To achieve this, you need:
#
New Fuzz Driver or Expand Existing Driver?
New Fuzz Driver:
Expand Existing Fuzz Driver:
#
Improving Your Fuzz Driver [1/3]
Checklist:
#
Improving Your Fuzz Driver [2/3]
Checklist:
#
Improving Your Fuzz Driver [3/3]
Checklist:
#
Other Tricks
Search GitHub or blog posts for different projects with a similar theme or structure and adopt their fuzz drivers for your project
Search existing OSS-Fuzz drivers:
#
More Time-Saving Tricks
Tweaking code and then regenerating coverage reports can be slow.
Compiling and then running your fuzz driver is much faster.
�The project source code is always available in the Fuzz Dojo under “Workspace”, or in the shell under /src-{sanitizer}
#
Online Reports
Browse code online on:
https://introspector.oss-fuzz.com/projects-overview
Github repository links
Project statistics
Code coverage of existing fuzz drivers
Browse source code coverage reports
#
Fuzz Introspector
Static analysis tools are useful to analyze source code complexity, function parameters, and finding functions high in the call tree to fuzz�
Fuzz Introspector reports can be generated manually or viewed online
#