SyzGen: Automated Generation of Syscall Specification of Closed-Source macOS Drivers

SyzGen: Automated Generation of Syscall Specification of Closed-Source macOS Drivers
复制标题

DOI:
10.1145/3460120.3484564
复制
发表时间:
2021-11
期刊:
Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Weiteng Chen;Yu Wang;Zheng Zhang;Zhiyun Qian
Weiteng Chen;Yu Wang;Zheng Zhang;Zhiyun Qian
中科院分区:
其他
文献类型:
--
作者:
Weiteng Chen;Yu Wang;Zheng Zhang;Zhiyun Qian

文献摘要

相似文献

内核驱动程序是攻击面的关键部分,因为它们构成了内核代码库的很大一部分,并且通常缺乏适当的审查,特别是对于那些封闭源代码的驱动程序。不幸的是,复杂的输入结构和接口之间未知的关系/依赖关系使它们非常难以理解。因此,安全分析师主要依靠人工审计接口恢复生成有意义的模糊测试用例。在本文中,我们介绍了SyzGen,这是第一次尝试自动生成闭源macOS驱动程序的系统调用规范,并促进接口感知模糊。我们利用两个见解来克服二进制分析的挑战:(1)系统调用知识的迭代细化和(2)从少量执行跟踪中提取和外推依赖关系。我们对25个目标进行了评估。结果表明,SyzGen可以有效地生成高质量的规范,导致34个错误,包括攻击者可以利用来提升权限的一个错误,以及迄今为止的2个CVE。
Kernel drivers are a critical part of the attack surface since they constitute a large fraction of kernel codebase and oftentimes lack proper vetting, especially for those closed-source ones. Unfortunately, the complex input structure and unknown relationships/dependencies among interfaces make them very challenging to understand. Thus, security analysts primarily rely on manual audit for interface recovery to generate meaningful fuzzing test cases. In this paper, we present SyzGen, a first attempt to automate the generation of syscall specifications for closed-source macOS drivers and facilitate interface-aware fuzzing. We leverage two insights to overcome the challenges of binary analysis: (1) iterative refinement of syscall knowledge and (2) extraction and extrapolation of dependencies from a small number of execution traces. We evaluated our approach on 25 targets. The results show that SyzGen can effectively produce high-quality specifications, leading to 34 bugs, including one that attackers can exploit to escalate privilege, and 2 CVEs to date.