This report outlines the objectives, methodology, challenges, and results of the first Fuzzing Competition held at SBFT 2023. The competition utilized FuzzBench to assess the code-coverage performance and bug-finding efficacy of eight participating fuzzers over 23 hours. The competition was organized in three phases. In the first phase, participants were asked to integrate their fuzzers into FuzzBench and allowed them to privately run local experiments against the publicly available benchmarks. In the second phase, we publicly ran all submitted fuzzers on the publicly available benchmarks and allowed participants to fix any remaining bugs in their fuzzers. In the third phase, we publicly ran all submitted fuzzers plus three widely-used baseline fuzzers on a hidden set and the publicly available set of benchmark programs to establish the final results.
翻译:本报告概述了SBFT 2023首届模糊测试竞赛的目标、方法、挑战及结果。本次竞赛使用FuzzBench评估八款参赛模糊测试工具在23小时内的代码覆盖率性能与漏洞发现效率。竞赛分三个阶段组织:第一阶段要求参赛者将其模糊测试工具集成至FuzzBench,并允许其针对公开基准程序私下运行本地实验;第二阶段,我们公开运行所有提交的模糊测试工具于公开基准程序,并允许参赛者修复工具中存在的残留缺陷;第三阶段,我们针对隐藏基准程序及公开基准程序集,公开运行所有提交的模糊测试工具及三款广泛使用的基线模糊测试工具,以确立最终结果。