Configuration-Sensitive Linux Kernel Fuzzing
Yuheng Shen, Jianzhong Liu, Yuhan Chen, Yifei Chu, Qiang Zhang, Guoyu Yin, Heyuan Shi, Yu Jiang
Abstract
Fuzzing operating system kernels to discover deep and complex bugs is difficult to accomplish, as kernels reside between hardware and user applications, exposing a variety of input vectors that affect their internal state. Previous approaches mainly use a kernel’s system call interface to deliver test payloads into the kernel, but reaching states and triggering bugs also require collaborative efforts from other input vectors, such as runtime parameters. Kernel runtime parameters greatly affect the execution behavior of the kernel under test, as they alter internal execution flows and thus require kernel fuzzers to manipulate them in conjunction with invoking system calls to effectively root out bugs. In this paper, we present CSGO, a kernel fuzzer that discovers more in-depth bugs through fuzzing kernel runtime parameters in conjunction with system calls. CSGO’s approach is achieved through the following designs. First, CSGO generates valid test case generation syntax for kernel configurations by extracting available parameters exposed by the kernel. Then, for the extracted parameters, CSGO statically deduces relations between the configurations and kernel system calls for initial generation guidance. Finally, during fuzzing, CSGO dynamically refines the relations between the configurations and system calls by interpreting execution feedback. We implemented CSGO and evaluated its approach on recent versions of the Linux kernel. Our results show that CSGO achieves an average of 21% improvement in overall coverage compared with existing state-of-the-art kernel fuzzers and triggers 22 previously unknown bugs, with 8 fixed by kernel maintainers.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 223385f1-fb35-4192-b3b5-fdaa3300df4aRelated papers
- KSG: Augmenting Kernel Fuzzing with System Call Specification GenerationHao Sun, Yuheng Shen, Jianzhong Liu, Yiru Xu et al.USENIX ATC 2022 · 45 citations
- MOCK: Optimizing Kernel Fuzzing Mutation with Context-aware DependencyJiacheng Xu, Xuhong Zhang, Shouling Ji, Yuan Tian et al.NDSS 2024
- ACTOR: Action-Guided Kernel FuzzingMarius Fleischer, Dipanjan Das, Priyanka Bose, Weiheng Bai et al.USENIX Security 2023
- SegFuzz: Segmentizing Thread Interleaving to Discover Kernel Concurrency Bugs through FuzzingDae R. Jeong, Byoungyoung Lee, Insik Shin, Youngjin KwonS&P 2023
- SyzDirect: Directed Greybox Fuzzing for Linux KernelXin Tan, Yuan Zhang, Jiadong Lu, Xin Xiong et al.CCS 2023 · 25 citations
