Montage: A Neural Network Language Model-Guided JavaScript Engine Fuzzer

Cited 33 time in webofscience Cited 0 time in scopus
  • Hit : 439
  • Download : 0
DC FieldValueLanguage
dc.contributor.authorLee, Suyoungko
dc.contributor.authorHan, HyungSeokko
dc.contributor.authorCha, Sang Kilko
dc.contributor.authorSon, Sooelko
dc.date.accessioned2020-07-02T01:20:35Z-
dc.date.available2020-07-02T01:20:35Z-
dc.date.created2020-05-19-
dc.date.created2020-05-19-
dc.date.created2020-05-19-
dc.date.created2020-05-19-
dc.date.created2020-05-19-
dc.date.created2020-05-19-
dc.date.issued2020-08-12-
dc.identifier.citation29th USENIX Security Symposium (USENIX Security 2020), pp.2613 - 2630-
dc.identifier.urihttp://hdl.handle.net/10203/275091-
dc.description.abstractJavaScript (JS) engine vulnerabilities pose significant security threats affecting billions of web browsers. While fuzzing is a prevalent technique for finding such vulnerabilities, there have been few studies that leverage the recent advances in neural network language models (NNLMs). In this paper, we present Montage, the first NNLM-guided fuzzer for finding JS engine vulnerabilities. The key aspect of our technique is to transform a JS abstract syntax tree (AST) into a sequence of AST subtrees that can directly train prevailing NNLMs. We demonstrate that Montage is capable of generating valid JS tests, and show that it outperforms previous studies in terms of finding vulnerabilities. Montage found 37 real-world bugs, including three CVEs, in the latest JS engines, demonstrating its efficacy in finding JS engine bugs.-
dc.languageEnglish-
dc.publisherUSENIX-
dc.titleMontage: A Neural Network Language Model-Guided JavaScript Engine Fuzzer-
dc.typeConference-
dc.identifier.wosid000668146200147-
dc.identifier.scopusid2-s2.0-85091006543-
dc.type.rimsCONF-
dc.citation.beginningpage2613-
dc.citation.endingpage2630-
dc.citation.publicationname29th USENIX Security Symposium (USENIX Security 2020)-
dc.identifier.conferencecountryUS-
dc.identifier.conferencelocationVirtual-
dc.contributor.localauthorCha, Sang Kil-
dc.contributor.localauthorSon, Sooel-
Appears in Collection
CS-Conference Papers(학술회의논문)
Files in This Item
There are no files associated with this item.
This item is cited by other documents in WoS
⊙ Detail Information in WoSⓡ Click to see webofscience_button
⊙ Cited 33 items in WoS Click to see citing articles in records_button

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0