ProcessorFuzz: Processor Fuzzing with Control and Status Registers Guidance

ProcessorFuzz: Processor Fuzzing with Control and Status Registers Guidance
复制标题

DOI:
10.1109/host55118.2023.10133714
复制
发表时间:
2023-05
期刊:
2023 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)
影响因子:
--
通讯作者:
Sadullah Canakci;Chathura Rajapaksha;Leila Delshadtehrani;A. Nataraja;Michael B. Taylor;Manuel Egele;Ajay Joshi
Sadullah Canakci;Chathura Rajapaksha;Leila Delshadtehrani;A. Nataraja;Michael B. Taylor;Manuel Egele;Ajay Joshi
中科院分区:
其他
文献类型:
--
作者:
Sadullah Canakci;Chathura Rajapaksha;Leila Delshadtehrani;A. Nataraja;Michael B. Taylor;Manuel Egele;Ajay Joshi

文献摘要

被引文献

相似文献

随着现代处理器的复杂性在过去几年中不断增加,开发有效的验证策略以在制造之前识别错误已经变得至关重要。受软件模糊测试(一种常用于软件测试的技术)的启发,最近的多项工作使用硬件模糊测试来验证寄存器传输级(RTL)设计。然而,这些作品受到一些限制,如缺乏对广泛使用的硬件描述语言(HDL)的支持和误导性的覆盖信号,错误地识别“有趣”的输入。为了克服这些缺点,我们提出了ProcessorFuzz,一个处理器模糊,指导模糊与一个新的CSR过渡覆盖度量。ProcessorFuzz监控控制和状态寄存器(CSR)中的转换,因为CSR负责控制和保持处理器的状态。因此,CSR中的转换指示新的处理器状态,并且基于该反馈引导模糊器使得ProcessorFuzz能够探索新的处理器状态。我们用三个真实的开源处理器-- Rocket、BOOM和BlackParrot--评估了ProcessorFuzz。ProcessorFuzz触发一组地面事实错误的速度比DIFUZZRTL快1.23倍。此外,我们的实验在三个RISC-V内核中发现了8个新错误,在参考模型中发现了一个新错误。所有九个bug都得到了相应项目开发人员的确认。
As the complexity of modern processors has increased over the years, developing effective verification strategies to identify bugs prior to manufacturing has become critical. Inspired by software fuzzing, a technique commonly used for software testing, multiple recent works use hardware fuzzing for the verification of Register-Transfer Level (RTL) designs. However, these works suffer from several limitations such as lack of support for widelyused Hardware Description Languages (HDLs) and misleading coverage-signals that misidentify ‘‘interesting’’ inputs. Towards overcoming these shortcomings, we present ProcessorFuzz, a processor fuzzer that guides the fuzzer with a novel CSR-transition coverage metric. ProcessorFuzz monitors the transitions in Control and Status Registers (CSRs) as CSRs are in charge of controlling and holding the state of the processor. Therefore, transitions in CSRs indicate a new processor state, and guiding the fuzzer based on this feedback enables ProcessorFuzz to explore new processor states. We evaluated ProcessorFuzz with three real-world opensource processors — Rocket, BOOM, and BlackParrot. ProcessorFuzz triggered a set of ground-truth bugs $1.23 \times$ faster (on average) than DIFUZZRTL. Moreover, our experiments exposed 8 new bugs across the three RISC-V cores and one new bug in a reference model. All nine bugs were confirmed by the developers of the corresponding projects.