ACTOR: Action-Guided Kernel Fuzzing

ACTOR: Action-Guided Kernel Fuzzing
复制标题

DOI:
--
复制
发表时间:
2023
期刊:
--
影响因子:
--
通讯作者:
Marius Fleischer;Dipanjan Das;Priyanka Bose;Weiheng Bai;Kangjie Lu;Mathias Payer;Christopher Kruegel;Giovanni Vigna
Marius Fleischer;Dipanjan Das;Priyanka Bose;Weiheng Bai;Kangjie Lu;Mathias Payer;Christopher Kruegel;Giovanni Vigna
中科院分区:
其他
文献类型:
--
作者:
Marius Fleischer;Dipanjan Das;Priyanka Bose;Weiheng Bai;Kangjie Lu;Mathias Payer;Christopher Kruegel;Giovanni Vigna

文献摘要

相似文献

Fuzzing可靠而有效地发现软件中的错误,包括操作系统内核。一般来说,较高的代码覆盖率会导致发现更多的bug。这就是为什么大多数现有的内核模糊器采用策略来生成一系列输入,这些输入试图最大限度地增加它们执行的代码量。然而,简单地执行代码可能不足以揭示需要特定操作序列的错误。合成输入以触发此类错误取决于两个方面:(i)执行的代码采取的操作,以及(ii)采取这些操作的顺序。操作是一种高级操作,如堆分配,由执行的代码执行,具有特定的语义含义。一个CTOR,我们的行动指导的内核模糊框架,偏离传统的方法。而不是专注于代码覆盖优化,我们的方法生成模糊程序(输入),利用我们的理解触发的动作和它们的时间关系。具体来说,我们首先捕获可能在不同时间对共享数据结构进行操作的操作。然后,我们合成程序使用这些动作作为构建块,由我们的领域特定语言表达的错误模板指导。我们在四个不同版本的Linux内核上评估了A CTOR,其中包括两个经过良好测试且经常更新的长期(5 .四、206,5。10 . 131)版本,一个稳定的(5 . 19),和最新的(6 . 2-rc 5)释放。我们的评估共发现了41个以前未知的bug,其中9个已经修复。有趣的是,15(36。其中59%)是在不到一天的时间内发现的
Fuzzing reliably and efficiently finds bugs in software, including operating system kernels. In general, higher code coverage leads to the discovery of more bugs. This is why most existing kernel fuzzers adopt strategies to generate a series of inputs that attempt to greedily maximize the amount of code that they exercise. However, simply executing code may not be sufficient to reveal bugs that require specific sequences of actions. Synthesizing inputs to trigger such bugs depends on two aspects: (i) the actions the executed code takes, and (ii) the order in which those actions are taken. An action is a high-level operation, such as a heap allocation, that is performed by the executed code and has a specific semantic meaning. A CTOR , our action-guided kernel fuzzing framework, deviates from traditional methods. Instead of focusing on code coverage optimization, our approach generates fuzzer programs (inputs) that leverage our understanding of triggered actions and their temporal relationships. Specifically, we first capture actions that potentially operate on shared data structures at different times. Then, we synthesize programs using those actions as building blocks, guided by bug templates expressed in our domain-specific language. We evaluated A CTOR on four different versions of the Linux kernel, including two well-tested and frequently updated long-term (5 . 4 . 206, 5 . 10 . 131) versions, a stable (5 . 19), and the latest (6 . 2-rc5) release. Our evaluation revealed a total of 41 previously unknown bugs, of which 9 have already been fixed. Interestingly, 15 (36 . 59%) of them were discovered in less than a day