Skip to content

Adding muttfuzz and requesting an experiment - #1967

Open
kjain14 wants to merge 10 commits into
google:masterfrom
kjain14:master
Open

kjain14 wants to merge 10 commits into
google:masterfrom
kjain14:master

Conversation

@kjain14

@kjain14 kjain14 commented Apr 13, 2024

Copy link
Copy Markdown
Contributor

Adding MuttFuzz (a binary fuzzing alternative to our "First, Fuzz the Mutants" paper). This will likely integrate better with fuzzbench and thus work on experiments, as we are mutating binaries rather than source code.

@DonggeLiu

Copy link
Copy Markdown
Contributor

Hi, @kjain14, long time no see!
Thanks for updating the experiment request file.

We have changed our way of running experiments, hope this suits you:

  1. Would you mind making a trivial modification to service/gcbrun_experiment.py?
    This will allow me to launch experiments in this PR before merging.
    Here is an example to add a dummy comment, thanks!

  2. Could you please write your experiment request in this format?
    You can swap the --experiment-name and --fuzzers parameters with your values.
    For example, in your case, the request command this time is

/gcbrun run_experiment.py -a --experiment-config /opt/fuzzbench/service/experiment-config.yaml --experiment-name 2024-04-23-aflpp-muttfuzz --fuzzers aflplusplus_muttfuzz
  1. You no longer have to edit service/experiment-requests.yaml in the future : )

@DonggeLiu

Copy link
Copy Markdown
Contributor

/gcbrun run_experiment.py -a --experiment-config /opt/fuzzbench/service/experiment-config.yaml --experiment-name 2024-04-23-aflpp-muttfuzz --fuzzers aflplusplus_muttfuzz

@DonggeLiu

DonggeLiu commented Apr 23, 2024 •

Copy link
Copy Markdown
Contributor

Experiment 2024-04-23-aflpp-muttfuzz data and results will be available later at:
The experiment data.
The experiment report.

@kjain14

kjain14 commented Apr 23, 2024

Copy link
Copy Markdown
Contributor Author

We accidentally only ran muttfuzz, we also want to compare against aflplusplus

@kjain14

kjain14 commented Apr 23, 2024 via email

Copy link
Copy Markdown
Contributor Author

@kjain14

kjain14 commented Apr 23, 2024

Copy link
Copy Markdown
Contributor Author

/gcbrun run_experiment.py -a --experiment-config /opt/fuzzbench/service/experiment-config.yaml --experiment-name 2024-04-23-full-muttfuzz --fuzzers aflplusplus_muttfuzz aflplusplus aflsmart_muttfuzz aflsmart libfuzzer libfuzzer_muttfuzz libafl libafl_muttfuzz honggfuzz honggfuzz_muttfuzz

@DonggeLiu

DonggeLiu commented Apr 23, 2024 •

Copy link
Copy Markdown
Contributor

Thanks for providing us with the experiment request command, @kjain14!

I noticed that the experiment requires 10 fuzzers, which may overwhelm FuzzBench due to its current bottleneck in the measurement stage. Empirically, it's safer to keep the number under 8.
Meanwhile, this config enables FuzzBench to merge fuzzers' results from past experiments into your report when your experiment completes so that we don't have to re-run them in every new experiment.
For example, your previous experiment report should have data of other fuzzers (including afl++) once it completes.
Here is another example command and its report. The report merges core fuzzers' results from past experiments even though they were not explicitly mentioned in the command.

I will revise the new command below, please let me know if they work for you.

@kjain14

kjain14 commented Apr 23, 2024

Copy link
Copy Markdown
Contributor Author

Thanks! Yes merging them should work!

@DonggeLiu

Copy link
Copy Markdown
Contributor

/gcbrun run_experiment.py -a --experiment-config /opt/fuzzbench/service/experiment-config.yaml --experiment-name 2024-04-23-full-muttfuzz --fuzzers aflplusplus_muttfuzz aflsmart_muttfuzz libfuzzer_muttfuzz libafl_muttfuzz honggfuzz_muttfuzz

@DonggeLiu

Copy link
Copy Markdown
Contributor

The request failed because the fuzzer name is libafl_muttfuzz but its directory name is libafll_muttfuzz (with two ls in afll), is this a typo?
Would you like to change it or it's ok to use that name?

@kjain14

kjain14 commented Apr 24, 2024

Copy link
Copy Markdown
Contributor Author

Apologies for the typo, this should be fixed now

@DonggeLiu

Copy link
Copy Markdown
Contributor

/gcbrun run_experiment.py -a --experiment-config /opt/fuzzbench/service/experiment-config.yaml --experiment-name 2024-04-24-full-muttfuzz --fuzzers aflplusplus_muttfuzz aflsmart_muttfuzz libfuzzer_muttfuzz libafl_muttfuzz honggfuzz_muttfuzz

@DonggeLiu

Copy link
Copy Markdown
Contributor

Experiment 2024-04-24-full-muttfuzz data and results will be available later at:
The experiment data.
The experiment report.
The experiment report(experimental).

@kjain14

kjain14 commented May 2, 2024

Copy link
Copy Markdown
Contributor Author

/gcbrun run_experiment.py -a --experiment-config /opt/fuzzbench/service/experiment-config.yaml --experiment-name 2024-05-02-full-muttfuzz --fuzzers aflplusplus_muttfuzz aflsmart_muttfuzz libfuzzer_muttfuzz libafl_muttfuzz honggfuzz_muttfuzz

@DonggeLiu

Copy link
Copy Markdown
Contributor

Hi @kjain14, would you mind if I start this experiment next week?

We were trying to investigate this failure and it would be great if we could avoid starting another large experiment at the meantime.

Thanks!

@kjain14

kjain14 commented May 3, 2024

Copy link
Copy Markdown
Contributor Author

Sure, we can start it next week

@DonggeLiu

Copy link
Copy Markdown
Contributor

/gcbrun run_experiment.py -a --experiment-config /opt/fuzzbench/service/experiment-config.yaml --experiment-name 2024-05-06-full-muttfuzz --fuzzers aflplusplus_muttfuzz aflsmart_muttfuzz libfuzzer_muttfuzz libafl_muttfuzz honggfuzz_muttfuzz

@DonggeLiu

Copy link
Copy Markdown
Contributor

Experiment 2024-05-06-full-muttfuzz data and results will be available later at:
The experiment data.
The experiment report.
The experiment report(experimental).

@vanhauser-thc

Copy link
Copy Markdown
Collaborator

@kjain14 fyi I saw your experiments. if you did not integrate muttfuzz on the same commit as aflplusplus that you fuzzbench is using, you will be comparing apples with oranges because there were significant advances. same if your muttfuzz afl++ commit is newer than the one on fuzzbench. I didnt check your setup. just in case: better add an aflplusplus variant that has the exact same commit id you have based your muttfuzz integration on.
comparing against honggfuzz looks good, so I would expect it should also improve afl++.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants