PeriScope: An Effective Probing and Fuzzing Framework for the Hardware-OS Boundary
Dokyung Song, Felicitas Hetzelt, Dipanjan Das, Chad Spensky, Yeoul Na, Stijn Volckaert, Giovanni Vigna, Christopher Kruegel, Jean-Pierre Seifert, Michael Franz
Abstract
The OS kernel is an attractive target for remote attackers. If compromised, the kernel gives adversaries full system access, including the ability to install rootkits, extract sensitive information, and perform other malicious actions, all while evading detection. Most of the kernel's attack surface is situated along the system call boundary. Ongoing kernel protection efforts have focused primarily on securing this boundary; several capable analysis and fuzzing frameworks have been developed for this purpose. However, there are additional paths to kernel compromise that do not involve system calls, as demonstrated by several recent exploits. For example, by compromising the firmware of a peripheral device such as a Wi-Fi chipset and subsequently sending malicious inputs from the Wi-Fi chipset to the Wi-Fi driver, adversaries have been able to gain control over the kernel without invoking a single system call. Unfortunately, there are currently no practical probing and fuzzing frameworks that can help developers find and fix such vulnerabilities occurring along the hardware-OS boundary. We present PERISCOPE, a Linux kernel based probing framework that enables fine-grained analysis of device-driver interactions. PERISCOPE hooks into the kernel's page fault handling mechanism to either passively monitor and log traffic between device drivers and their corresponding hardware, or mutate the data stream on-the-fly using a fuzzing component, PERIFUZZ, thus mimicking an active adversarial attack. PER-IFUZZ accurately models the capabilities of an attacker on peripheral devices, to expose different classes of bugs including, but not limited to, memory corruption bugs and double-fetch bugs. To demonstrate the risk that peripheral devices pose, as well as the value of our framework, we have evaluated PERIFUZZ on the Wi-Fi drivers of two popular chipset vendors, where we discovered 15 unique vulnerabilities, 9 of which were previously unknown.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1d095ec6-5e15-44f2-b030-b31744c3f97aCited by top-tier papers59
- DICE: Automatic Emulation of DMA Input Channels for Dynamic Firmware AnalysisAlejandro Mera, Bo Feng, Long Lu, Engin KirdaS&P 2021 · 81 citations
- SyzVegas: Beating Kernel Fuzzing Odds with Reinforcement LearningDaimeng Wang, Zheng Zhang, Hang Zhang, Zhiyun Qian et al.USENIX Security 2021 · 75 citations
- GREBE: Unveiling Exploitation Potential for Linux Kernel BugsZhenpeng Lin, Yueqi Chen, Yuhang Wu, Dongliang Mu et al.S&P 2022 · 47 citations
- FirmXRay: Detecting Bluetooth Link Layer Vulnerabilities From Bare-Metal FirmwareHaohuang Wen, Zhiqiang Lin, Yinqian ZhangCCS 2020 · 47 citations
- Ex-vivo dynamic analysis framework for Android device driversIvan Pustogarov, Qian Wu, David LieS&P 2020 · 32 citations
Builds on20
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 836 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- CollAFL: Path Sensitive FuzzingShuitao Gan, Chao Zhang, Xiaojun Qin, Xuwen Tu et al.S&P 2018 · 426 citations
- Hawkeye: Towards a Desired Directed Grey-box FuzzerHongxu Chen, Yinxing Xue, Yuekang Li, Bihuan Chen et al.CCS 2018 · 335 citations
Related papers
- PrIntFuzz: fuzzing Linux drivers via automated virtual device simulationZheyu Ma, Bodong Zhao, Letu Ren, Zheming Li et al.ISSTA 2022 · 23 citations
- DIFUZE: Interface Aware Fuzzing for Kernel DriversJake Corina, Aravind Machiry, Christopher Salls, Yan Shoshitaishvili et al.CCS 2017 · 195 citations
- DevFuzz: Automatic Device Model-Guided Device Driver FuzzingYilun Wu, Tong Zhang, Changhee Jung, Dongyoon LeeS&P 2023
- Drifuzz: Harvesting Bugs in Device Drivers from Golden SeedsZekun Shen, Ritik Roongta, Brendan Dolan-GavittUSENIX Security 2022
- SyzParam: Incorporating Runtime Parameters into Kernel Driver FuzzingYue Sun, Yan Kang, Chenggang Wu, Kangjie Lu et al.CCS 2025
