DevFuzz: Automatic Device Model-Guided Device Driver Fuzzing
Yilun Wu, Tong Zhang, Changhee Jung, Dongyoon Lee
Abstract
The security of device drivers is critical for the entire operating system’s reliability. Yet, it remains very challenging to validate if a device driver can properly handle potentially malicious input from a hardware device. Unfortunately, existing symbolic execution-based solutions often do not scale, while fuzzing solutions require real devices or manual device models, leaving many device drivers under-tested and insecure.This paper presents DevFuzz, a new model-guided device driver fuzzing framework that does not require a physical device. DevFuzz uses symbolic execution to automatically generate the probe model that can guide a fuzzer to properly initialize a device driver under test. DevFuzz also leverages both static and dynamic program analyses to construct MMIO, PIO, and DMA device models to improve the effectiveness of fuzzing further. DevFuzz successfully tested 191 device drivers of various bus types (PCI, USB, RapidIO, I2C) from different operating systems (Linux, FreeBSD, and Windows) and detected 72 bugs, 41 of which have been patched and merged into the mainstream.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7cecaef9-725b-47ba-8444-2e70e8eb8061Cited by top-tier papers10
- A Little Goes a Long Way: Tuning Configuration Selection for Continuous Kernel FuzzingSanan Hasanov, Stefan Nagy, Paul GazzilloICSE 2025 · 6 citations
- Metis: File System Model Checking via Versatile Input and State ExplorationYifei Liu, Manish Adkar, Gerard J. Holzmann, Geoff Kuenning et al.FAST 2024 · 6 citations
- ChoiceJacking: Compromising Mobile Devices through Malicious Chargers like a Decade agoFlorian Draschbacher, Lukas Maar, Mathias Oberhuber, Stefan MangardUSENIX Security 2025
- GDMA: Fully Automated DMA Rehosting via Iterative Type OverlaysTobias Scharnowski, Simeon Hoffmann, Moritz Bley, Simon Wörner et al.USENIX Security 2025
- Dynamic Detection of Vulnerable DMA Race ConditionsBrian Johannesmeyer, Raphael Isemann, Cristiano Giuffrida, Herbert BosCCS 2025
Builds on21
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik et al.NDSS 2019 · 413 citations
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel et al.USENIX Security 2017 · 324 citations
- DIFUZE: Interface Aware Fuzzing for Kernel DriversJake Corina, Aravind Machiry, Christopher Salls, Yan Shoshitaishvili et al.CCS 2017 · 195 citations
- MoonShine: Optimizing OS Fuzzer Seed Selection with Trace DistillationShankara Pailoor, Andrew Aday, Suman JanaUSENIX Security 2018 · 180 citations
Related papers
- USBFuzz: A Framework for Fuzzing USB Drivers by Device EmulationHui Peng, Mathias PayerUSENIX Security 2020
- PrIntFuzz: fuzzing Linux drivers via automated virtual device simulationZheyu Ma, Bodong Zhao, Letu Ren, Zheming Li et al.ISSTA 2022 · 23 citations
- Semantic-Informed Driver Fuzzing Without Both the Hardware Devices and the EmulatorsWenjia Zhao, Kangjie Lu, Qiushi Wu, Yong QiNDSS 2022
- SyzParam: Incorporating Runtime Parameters into Kernel Driver FuzzingYue Sun, Yan Kang, Chenggang Wu, Kangjie Lu et al.CCS 2025
- Drifuzz: Harvesting Bugs in Device Drivers from Golden SeedsZekun Shen, Ritik Roongta, Brendan Dolan-GavittUSENIX Security 2022
