SyzScope: Revealing High-Risk Security Impacts of Fuzzer-Exposed Bugs in Linux kernel

SyzScope: Revealing High-Risk Security Impacts of Fuzzer-Exposed Bugs in Linux kernel
复制标题

DOI:
--
复制
发表时间:
2021-11
期刊:
ArXiv
影响因子:
--
通讯作者:
Xiaochen Zou;Guoren Li;Weiteng Chen;Hang Zhang;Zhiyun Qian
Xiaochen Zou;Guoren Li;Weiteng Chen;Hang Zhang;Zhiyun Qian
中科院分区:
其他
文献类型:
--
作者:
Xiaochen Zou;Guoren Li;Weiteng Chen;Hang Zhang;Zhiyun Qian

文献摘要

被引文献

相似文献

模糊测试已成为最有效的软件错误查找方法之一。近年来,出现了 24*7 连续模糊测试平台来测试关键软件,例如 Linux 内核。尽管能够发现许多错误并提供重现器(例如概念验证),但一个主要问题是它们忽略了本应内置的关键功能,即评估错误的安全影响。众所周知,缺乏对安全影响的了解可能会导致错误修复和补丁传播延迟。在本文中,我们开发了 SyzScope,这是一个系统,可以在看似“低风险”影响的错误的情况下自动发现新的“高风险”影响。通过分析 syzbot 上千多个低风险 bug,SyzScope 成功确定 183 个低风险 bug(超过 15%)实际上包含高风险影响,例如控制流劫持和任意内存写入,其中一些尚无可用补丁。
Fuzzing has become one of the most effective bug finding approach for software. In recent years, 24*7 continuous fuzzing platforms have emerged to test critical pieces of software, e.g., Linux kernel. Though capable of discovering many bugs and providing reproducers (e.g., proof-of-concepts), a major problem is that they neglect a critical function that should have been built-in, i.e., evaluation of a bug's security impact. It is well-known that the lack of understanding of security impact can lead to delayed bug fixes as well as patch propagation. In this paper, we develop SyzScope, a system that can automatically uncover new"high-risk"impacts given a bug with seemingly"low-risk"impacts. From analyzing over a thousand low-risk bugs on syzbot, SyzScope successfully determined that 183 low-risk bugs (more than 15%) in fact contain high-risk impacts, e.g., control flow hijack and arbitrary memory write, some of which still do not have patches available yet.