Evocatio: Conjuring Bug Capabilities from a Single PoC

Evocatio: Conjuring Bug Capabilities from a Single PoC
复制标题

DOI:
10.1145/3548606.3560575
复制
发表时间:
2022-11
期刊:
Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Z. Jiang;Shuitao Gan;Adrián Herrera;Flavio Toffalini;Lucio Romerio;Chaojing Tang;Manuel Egele;Chao Zhang;Mathias Payer
Z. Jiang;Shuitao Gan;Adrián Herrera;Flavio Toffalini;Lucio Romerio;Chaojing Tang;Manuel Egele;Chao Zhang;Mathias Payer
中科院分区:
其他
文献类型:
--
作者:
Z. Jiang;Shuitao Gan;Adrián Herrera;Flavio Toffalini;Lucio Romerio;Chaojing Tang;Manuel Egele;Chao Zhang;Mathias Payer

文献摘要

相似文献

覆盖率引导的灰盒模糊器的流行导致了开发人员必须优先考虑和修复的安全关键错误的海啸。了解bug暴露的功能(例如,漏洞类型、读取/写入的字节数),可以对错误修复进行优先级排序。不幸的是,了解一个错误的能力是一个耗时的过程,需要(a)了解错误的根本原因,(B)了解攻击者如何利用错误,以及(c)开发缓解这些威胁的补丁。这是一个定性和任意的大部分手动过程,可能导致对错误功能的误解。Evocatio会自动发现bug的功能。Evocatio分析崩溃测试用例(即,暴露错误的输入)以了解攻击者如何利用错误的全部程度。Evocatio利用一个功能引导的模糊器来有效地发现新的bug功能(而不是像传统的灰盒模糊器那样,只为给定的bug生成一个崩溃的测试用例)。我们评估了Evocatio在8个开源应用程序中的38个错误(34个CVE和4个错误报告)。从这些bug中,Evocatio:(i)发现10倍以上的能力(也就是说,由一组崩溃引起的独特功能的数量是AFL++的崩溃探索模式的10倍);(ii)将38个错误中的19个转换为新的错误类型(说明手工定性分析的局限性);以及(iii)生成了新的概念验证(Proof-of-Concept,简称CVE)测试用例,违反了16个测试CVE中7个的补丁,其中一个在软件的最新版本中仍然触发。
The popularity of coverage-guided greybox fuzzers has led to a tsunami of security-critical bugs that developers must prioritize and fix. Knowing the capabilities a bug exposes (e.g., type of vulnerability, number of bytes read/written) enables prioritization of bug fixes. Unfortunately, understanding a bug's capabilities is a time consuming process, requiring (a) an understanding of the bug's root cause, (b) an understanding how an attacker may exploit the bug, and (c) the development of a patch mitigating these threats. This is a mostly-manual process that is qualitative and arbitrary, potentially leading to a misunderstanding of the bug's capabilities. Evocatio automatically discovers a bug's capabilities. Evocatio analyzes a crashing test case (i.e., an input exposing a bug) to understand the full extent of how an attacker can exploit a bug. Evocatio leverages a capability-guided fuzzer to efficiently uncover new bug capabilities (rather than only generating a single crashing test case for a given bug, as a traditional greybox fuzzer does). We evaluate Evocatio on 38 bugs (34 CVEs and four bug reports) across eight open-source applications. From these bugs, Evocatio: (i) discovered 10× more capabilities (that is, the number of unique capabilities induced by a set of crashes was 10× higher) than AFL++'s crash exploration mode; (ii) converted 19 of the 38 bugs to new bug types (demonstrating the limitations of manual qualitative analysis); and (iii) generated new proof-of-concept (PoC) test cases violating patches for 7 out of 16 tested CVEs, one of which still triggers in the latest version of the software.