DevFuzz: Automatic Device Model-Guided Device Driver Fuzzing

DevFuzz: Automatic Device Model-Guided Device Driver Fuzzing
复制标题

DOI:
10.1109/sp46215.2023.10179293
复制
发表时间:
2023-05
期刊:
2023 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Yilun Wu;Tong Zhang;Changhee Jung;Dongyoon Lee
Yilun Wu;Tong Zhang;Changhee Jung;Dongyoon Lee
中科院分区:
其他
文献类型:
--
作者:
Yilun Wu;Tong Zhang;Changhee Jung;Dongyoon Lee

文献摘要

相似文献

设备驱动程序的安全性对整个操作系统的可靠性至关重要。然而,验证设备驱动程序是否能够正确处理来自硬件设备的潜在恶意输入仍然非常具有挑战性。不幸的是,现有的基于符号执行的解决方案通常无法扩展,而模糊测试解决方案需要实际设备或手动设备模型,导致许多设备驱动程序未经过测试且不安全。本文提出了一种新的模型导向设备驱动模糊测试框架DevFuzz,它不需要物理设备。DevFuzz使用符号执行来自动生成探测模型,该模型可以指导fuzzer正确初始化被测设备驱动程序。DevFuzz还利用静态和动态程序分析来构建MMIO, PIO和DMA设备模型,以进一步提高模糊测试的有效性。DevFuzz在不同的操作系统(Linux、FreeBSD、Windows)上成功测试了191种不同总线类型(PCI、USB、RapidIO、I2C)的设备驱动程序,检测出72个bug,其中41个已经被修补并合并为主流。
The security of device drivers is critical for the entire operating system’s reliability. Yet, it remains very challenging to validate if a device driver can properly handle potentially malicious input from a hardware device. Unfortunately, existing symbolic execution-based solutions often do not scale, while fuzzing solutions require real devices or manual device models, leaving many device drivers under-tested and insecure.This paper presents DevFuzz, a new model-guided device driver fuzzing framework that does not require a physical device. DevFuzz uses symbolic execution to automatically generate the probe model that can guide a fuzzer to properly initialize a device driver under test. DevFuzz also leverages both static and dynamic program analyses to construct MMIO, PIO, and DMA device models to improve the effectiveness of fuzzing further. DevFuzz successfully tested 191 device drivers of various bus types (PCI, USB, RapidIO, I2C) from different operating systems (Linux, FreeBSD, and Windows) and detected 72 bugs, 41 of which have been patched and merged into the mainstream.