Black Hat USA 2018 - AFLs Blindspot and How to Resist AFL Fuzzing for Arbitrary ELF Binaries @HackersOnBoard
Black Hat USA 2018 - AFLs Blindspot and How to Resist AFL Fuzzing for Arbitrary ELF Binaries  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 4 days ago
AFL has claimed many successes on fuzzing a wide range of applications. In the past few years, researchers have continuously generated new improvements to enhance AFL's ability to find bugs. However, less attentions were given on how to hide bugs from AFL.

This talk is about AFL's blindspot — a limitation about AFL and how to use this limitation to resist AFL from finding specific bugs. AFL tracks code coverage through instrumentations and it uses coverage information to guide input mutations. Instead of fully recording the complete execution paths, AFL uses a compact hash bitmap to store code coverage. This compact bitmap brings high execution speed but also a constraint: new path can be masked by previous paths in the compact bitmap due to hash conflicts. The inaccuracy and incompleteness in coverage information sometimes prevents an AFL fuzzer from discovering potential paths that lead to new crashes.

This presentation demonstrates such limitations with examples showing how the blindspot limits AFL's ability to find bugs, and how it prevents AFL from taking seeds generated from complementary approaches such as symbolic execution.

To further illustrate this limitation, we build a software prototype called DeafL, which transforms and rewrites EFL binaries for the purpose of resisting AFL fuzzing. Without changing the functionality of a given ELF binary, the DeafL tool rewrites the input binary to a new EFL executable, so that an easy to find bug by AFL in the original binary becomes difficult to find in the rewritten binary.
Black Hat USA 2018 - AFLs Blindspot and How to Resist AFL Fuzzing for Arbitrary ELF BinariesBlack Hat USA 2018 - DeepLocker - Concealing Targeted Attacks with AI LocksmithingDEF CON 27 - Bill Swearingen - HAKC THE POLICEDEF CON 27 - Breaking The Back End It Is Not Always A Bug Sometimes It Is Just Bad DesignDEF CON 27 - 100 Seconds of Solitude Defeating Cisco Trust Anchor With FPGA Bitstream ShenanigansDEF CON 27 - Panel - DEF CON to help hackers anonymously submit bugs to the government discussDEF CON 27 - Alvaro Munoz - SSO Wars The Token MenaceBlack Hat USA 2018 - Fire & Ice Making and Breaking macOS FirewallsDEF CON 27 - smea - Adventures In Smart Buttplug Penetration testingDEF CON 27 - Unpacking Pkgs A Look Inside Macos Installer Packages And Common Security FlawsBlack Hat USA 2018 - Dissecting Non Malicious Artifacts One IP at a TimeDEF CON 27 - Brent Stone - Reverse Engineering 17 plus Cars in Less Than 10 Minutes
HackersOnBoard |

Black Hat USA 2018 - AFL's Blindspot and How to Resist AFL Fuzzing for Arbitrary ELF Binaries

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER