针对Linux内核漏洞的高精度崩溃分析技术研究
批准号:
62102154
项目类别:
青年科学基金项目(C类)
资助金额:
30.0 万元
负责人:
慕冬亮
依托单位:
学科分类:
网络与系统安全
结题年份:
2024
批准年份:
2021
项目状态:
已结题
项目参与者:
慕冬亮
中文摘要
操作系统内核是现代信息系统的核心组件之一,其安全性至关重要,作为基础支撑软件,没有及时修复会造成不可预料的灾难性结果。模糊测试是目前一种主流的软件漏洞发现方法,但内核软件的复杂性会导致模糊测试产生的内核崩溃难以精确分析,主要表现在:1)导致内核崩溃的测试样例难以精准调试;2)内核崩溃数据过于庞大,导致分析结果准确度过低;3)内核崩溃行为无法精确反映底层漏洞的真实危害。为此,本项目拟深入理解内核崩溃数据,并设计一种针对Linux内核漏洞的高精度崩溃分析技术,研究内容主要包含1)内核测试样例最小化,利用系统调用之间的数据依赖精简测试样例;2)内核崩溃去重与分组,基于大规模数据驱动设计去重策略并分组;3)内核漏洞严重性评估,利用模糊测试探索可能的崩溃行为评估漏洞危害性。本项目可以极大地辅助内核开发人员诊断内核漏洞、快速修复内核漏洞,增强Linux内核的安全性和可靠性。
英文摘要
Kernel program is one of the security-critical components in today’s networking and computation systems. As a basic foundation software, vulnerabilities can lead to catastrophic consequences if they are not timely patched. Fuzzing is one of the state-of-art approaches to discover vulnerabilities, but the complexity of kernel program leads to the imprecise triage on the kernel crashes, which manifests in several aspects: 1) The crash-inducing test cases can be difficult to precisely debug and analyze; 2) The sheer volume of crashes makes the trigger result extremely imprecisely; 3) The kernel crash behaviors cannot precisely reflect the actual risk of underlying vulnerabilities. Therefore, this research will deeply analyze the kernel crashes and aims to develop a solution of more precise crash triage for Linux kernel vulnerabilities. The main approach is to 1) take advantages of data dependency between system calls to minimize failure-inducing test cases; 2) conduct a data-driven analysis on crash deduplication and design deduplication strategies to group the kernel crashes; 3) design an object-oriented fuzzing to explore more possible crash behaviors which facilitates the severity assessment. This project could greatly facilitate kernel developers with the root cause diagnosis, quick fixing, and patch assurance of kernel vulnerabilities, to make Linux kernel more secure and reliable.
操作系统内核是现代信息系统的核心组件之一,其安全性至关重要,作为基础支撑软件,没有及时修复会造成不可预料的灾难性结果。模糊测试是目前一种主流的软件漏洞发现方法,但内核软件的复杂性会导致模糊测试产生的内核崩溃难以精确分析,主要表现在:1)导致内核崩溃的测试样例难以精准调试;2)内核崩溃数据过于庞大,导致分析结果准确度过低;3)内核崩溃行为无法精确反映底层漏洞的真实危害。为此,本项目拟深入理解内核崩溃数据,并设计一种针对Linux内核漏洞的高精度崩溃分析技术,研究内容主要包含1)内核测试样例最小化,利用系统调用之间的数据依赖精简测试样例;2)内核崩溃去重与分组,基于大规模数据驱动设计去重策略并分组;3)内核漏洞严重性评估,利用模糊测试探索可能的崩溃行为评估漏洞危害性。本项目可以极大地辅助内核开发人员诊断内核漏洞、快速修复内核漏洞,增强Linux内核的安全性和可靠性。
国内基金
海外基金