FUZE: Towards Facilitating Exploit Generation for Kernel Use-After-Free Vulnerabilities

FUZE: Towards Facilitating Exploit Generation for Kernel Use-After-Free Vulnerabilities
复制标题

DOI:
--
复制
发表时间:
2018
期刊:
--
影响因子:
--
通讯作者:
Wei Wu;Yueqi Chen;Jun Xu;Xinyu Xing;Xiaorui Gong;Wei Zou
Wei Wu;Yueqi Chen;Jun Xu;Xinyu Xing;Xiaorui Gong;Wei Zou
中科院分区:
其他
文献类型:
--
作者:
Wei Wu;Yueqi Chen;Jun Xu;Xinyu Xing;Xiaorui Gong;Wei Zou

文献摘要

被引文献

相似文献

软件供应商通常根据漏洞利用的难易程度来优先考虑他们的漏洞修复。然而,准确地确定可利用性通常需要花费大量的时间,并且需要大量的手动工作。为了解决这个问题,可以采用自动漏洞利用生成技术。然而,在实践中,它们表现出评估可利用性的能力不足,特别是对于内核释放后修复(UAF)漏洞。这主要是因为UAF开发的复杂性以及操作系统内核的可伸缩性。因此,在本文中,我们提出了FUZE,一个新的框架,以促进内核UAF开发的过程。这种技术背后的设计原则是,我们希望制作漏洞的容易性可以增强安全分析师评估内核UAF漏洞可利用性的能力。在技术上,FUZE利用内核模糊技术沿着符号执行来识别、分析和评估对内核UAF开发有价值和有用的系统调用。此外,它利用动态跟踪和现成的约束求解器来指导易受攻击对象的操作。为了演示FUZE的实用性,我们在64位Linux系统上通过扩展二进制分析框架和内核模糊器实现了FUZE。在Linux系统上使用15个真实的内核UAF漏洞,我们证明了FUZE不仅可以提高内核UAF的可利用性,而且可以使工作漏洞多样化。此外,我们还证明了FUZE可以促进安全缓解绕过,使可利用性评估更具挑战性和更有效。?这项工作是在宾夕法尼亚州立大学学习时完成的。网络安全与防护技术北京市重点实验室
Software vendors usually prioritize their bug remediation based on ease of their exploitation. However, accurately determining exploitability typically takes tremendous hours and requires significant manual efforts. To address this issue, automated exploit generation techniques can be adopted. In practice, they however exhibit an insufficient ability to evaluate exploitability particularly for the kernel Use-After-Free (UAF) vulnerabilities. This is mainly because of the complexity of UAF exploitation as well as the scalability of an OS kernel. In this paper, we therefore propose FUZE, a new framework to facilitate the process of kernel UAF exploitation. The design principle behind this technique is that we expect the ease of crafting an exploit could augment a security analyst with the ability to evaluate the exploitability of a kernel UAF vulnerability. Technically, FUZE utilizes kernel fuzzing along with symbolic execution to identify, analyze and evaluate the system calls valuable and useful for kernel UAF exploitation. In addition, it leverages dynamic tracing and an off-the-shelf constraint solver to guide the manipulation of vulnerable object. To demonstrate the utility of FUZE, we implement FUZE on a 64-bit Linux system by extending a binary analysis framework and a kernel fuzzer. Using 15 realworld kernel UAF vulnerabilities on Linux systems, we then demonstrate FUZE could not only escalate kernel UAF exploitability but also diversify working exploits. In addition, we show that FUZE could facilitate security mitigation bypassing, making exploitability evaluation less challenging and more efficient. ?The work was done while studying at Pennsylvania State University. †Key Laboratory of Network Assessment Technology, CAS ‡Beijing Key Laboratory of Network Security and Protection Technology