IntraFuzz: Coverage-Guided Intra-Enclave Fuzzing for Intel SGX Applications
Jinhua Cui, Qiao Peng, Yiwen Yao, Ke Ye, Jiliang Zhang
Abstract
Intel SGX is susceptible to intra-enclave software vulnerabilities. Existing automated bug-finding methods primarily focus on fuzzing enclave boundaries for SGX applications in simulated, rather than actual hardware-protected enclaves. This limits the ability to identify potential security violations originating from within SGX application code. This paper presents IntraFuzz, the first system that enables efficient fuzzing of SGX applications inside actual hardware enclaves. We evaluated IntraFUZZ with 21 real-world SGX applications, running on Intel Xeon scalable processors with up to 256 GB of enclave page cache. IntraFuzz successfully detected all vulnerabilities in SGX application code previously identified by the state-of-the-art tool EnclaveFuzz, as well as 6 previously undiscovered vulnerabilities. These results highlight the importance of hardware-based fuzzing in securing SGX applications.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get aff928c9-1666-4d6a-8456-63f0a778c3bcRelated papers
- SGXFuzz: Efficiently Synthesizing Nested Structures for SGX Enclave FuzzingTobias Cloosters, Johannes Willbold, Thorsten Holz, Lucas DaviUSENIX Security 2022
- EnclaveFuzz: Finding Vulnerabilities in SGX ApplicationsLiheng Chen, Zheming Li, Zheyu Ma, Yuan Li et al.NDSS 2024
- TeeRex: Discovery and Exploitation of Memory Corruption Vulnerabilities in SGX EnclavesTobias Cloosters, Michael Rodler, Lucas DaviUSENIX Security 2020
- SGXLock: Towards Efficiently Establishing Mutual Distrust Between Host Application and Enclave for SGXYuan Chen, Jiaqi Li, Guorui Xu, Yajin Zhou et al.USENIX Security 2022
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
