GLeeFuzz: Fuzzing WebGL Through Error Message Guided Mutation

GLeeFuzz: Fuzzing WebGL Through Error Message Guided Mutation
复制标题

DOI:
--
复制
发表时间:
2023
期刊:
--
影响因子:
--
通讯作者:
Hui Peng;Zhihao Yao;A. A. Sani-A.;D. Tian;Mathias Payer
Hui Peng;Zhihao Yao;A. A. Sani-A.;D. Tian;Mathias Payer
中科院分区:
其他
文献类型:
--
作者:
Hui Peng;Zhihao Yao;A. A. Sani-A.;D. Tian;Mathias Payer

文献摘要

相似文献

WebGL是一组用于GPU加速图形的标准化JavaScript API,因为它揭示了对基础图形堆栈(包括本机GL库和GPU驱动程序)的远程和未包装的访问漏洞发现的WebGL接口的最先进的模糊技术是具有挑战性的,因为(1)其巨大的输入状态空间,以及(2)跨并发过程,封闭式库和设备跨程序收集代码覆盖的不可行性内核中的驱动程序。 (例如,不完整的参数,无效的参数或api呼叫之间的依赖性)。发出错误的陈述并拒绝输入的部分,并使用此信息指导输入突变。野生动物园,1个在Firefox中。
WebGL is a set of standardized JavaScript APIs for GPU accelerated graphics. Security of the WebGL interface is paramount because it exposes remote and unsandboxed access to the underlying graphics stack (including the native GL libraries and GPU drivers) in the host OS. Unfortunately, applying state-of-the-art fuzzing techniques to the WebGL interface for vulnerability discovery is challenging because of (1) its huge input state space, and (2) the infeasibility of collecting code coverage across concurrent processes, closed-source libraries, and device drivers in the kernel. Our fuzzing technique, GLeeFuzz, guides input mutation by error messages instead of code coverage. Our key observation is that browsers emit meaningful error messages to aid developers in debugging their WebGL programs. Error messages indicate which part of the input fails (e.g., incomplete arguments, invalid arguments, or unsatisfied dependencies be-tween API calls). Leveraging error messages as feedback, the fuzzer effectively expands coverage by focusing mutation on erroneous parts of the input . We analyze Chrome’s WebGL implementation to identify the dependencies between error-emitting statements and rejected parts of the input, and use this information to guide input mutation. We evaluate our GLeeFuzz prototype on Chrome, Firefox, and Safari on diverse desktop and mobile OSes. We discovered 7 vulnerabilities, 4 in Chrome, 2 in Safari, and 1 in Firefox. The Chrome vulnerabilities allow a remote attacker to freeze the GPU and possibly execute remote code at the browser privilege.