Automated Bug Detection and Replay for COTS Linux Kernel Modules with Concolic Execution

Automated Bug Detection and Replay for COTS Linux Kernel Modules with Concolic Execution
复制标题

DOI:
10.1109/saner48275.2020.9054797
复制
发表时间:
2020-02
期刊:
2020 IEEE 27th International Conference on Software Analysis, Evolution and Reengineering (SANER)
影响因子:
--
通讯作者:
Bo Chen;Zhenkun Yang;Li Lei;Kai Cong;Fei Xie
Bo Chen;Zhenkun Yang;Li Lei;Kai Cong;Fei Xie
中科院分区:
其他
文献类型:
--
作者:
Bo Chen;Zhenkun Yang;Li Lei;Kai Cong;Fei Xie

文献摘要

被引文献

相似文献

Linux内核在云中、移动的平台和超级计算机上无处不在。为了支持这些不同的计算环境,Linux内核通过可加载内核模块(LKM)提供了可扩展性和模块化,同时以单片体系结构为特征以提高执行效率。这种架构设计给Linux内核的安全性带来了重大挑战。如果LKM与Ring 0上的基本内核运行在相同的内存空间中,则LKM的单个缺陷可能会危及整个系统,例如,获取root访问权限。然而,LKM的验证和调试本质上是具有挑战性的,因为它的特殊接口深埋在内核中,以及来自中断的非确定性。此外,LKM由不同的供应商提供,公众可能无法访问其源代码,这使得验证更加困难。在本文中,我们提出了一个框架,有效的错误检测和重放的商业现货(COTS)Linux内核模块的基础上concolic执行。我们的框架自动生成紧凑的COTS LKM测试用例集,主动检查常见的内核错误,并允许重复报告的错误与可操作的测试用例。我们评估我们的方法超过20 LKM涵盖主要模块的网络和健全的子系统的Linux内核。结果表明,我们的方法可以有效地检测各种内核错误,并报告了5个新的漏洞,包括一个未知的缺陷,允许非特权用户触发内核恐慌。通过利用我们的框架的重放功能,我们修补了上游Linux内核中报告的所有错误,包括3个补丁,这些补丁被选择用于Linux内核的稳定版本,并向后移植到许多生产内核版本。我们还比较了我们的原型与KAFL,国家的最先进的内核模糊,并证明了concolic执行模糊内核级的有效性。
Linux kernel is pervasive in the cloud, on mobile platforms, and on supercomputers. To support these diverse computing environments, the Linux kernel provides extensibility and modularity through Loadable Kernel Modules (LKM), while featuring a monolithic architecture for execution efficiency. This architecture design brings a major challenge to the security of Linux kernel. Having LKMs run in the same memory space as the base kernel on Ring 0, a single flaw from LKMs may compromise the entire system, e.g., gaining root access. However, validation and debugging of LKMs are inherently challenging, because of its special interface buried deeply in the kernel, and non-determinism from interrupts. Also, LKMs are shipped by various vendors and the public may not have access to their source code, making the validation even harder. In this paper, we propose a framework for efficient bug detection and replay of commercial off-the-shelf (COTS) Linux kernel modules based on concolic execution. Our framework automatically generates compact sets of test cases for COTS LKMs, proactively checks for common kernel bugs, and allows to reproduce reported bugs repeatedly with actionable test cases. We evaluate our approach on over 20 LKMs covering major modules from the network and sound subsystems of Linux kernel. The results show that our approach can effectively detect various kernel bugs, and reports 5 new vulnerabilities including an unknown flaw that allows non-privileged users to trigger a kernel panic. By leveraging the replay capability of our framework, we patched all the reported bugs in the Linux kernel upstream, including 3 patches that were selected to the stable release of Linux kernel and back-ported to numerous production kernel versions. We also compare our prototype with kAFL, the state-of-the-art kernel fuzzer, and demonstrate the effectiveness of concolic execution over fuzzing on the kernel level.