HYPER-CUBE: High-Dimensional Hypervisor Fuzzing
Sergej Schumilo, Cornelius Aschermann, Ali Abbasi, Simon Wörner, Thorsten Holz
Abstract
—Virtual machine monitors (VMMs, also called hy-pervisors ) represent a very critical part of a modern software stack: compromising them could allow an attacker to take full control of the whole cloud infrastructure of any cloud provider. Hence their security is critical for many applications, especially in the context of Infrastructure-as-a-Service. In this paper, we present the design and implementation of H YPER -C UBE , a novel fuzzer that aims explicitly at testing hypervisors in an efficient, effective, and precise way. Our approach is based on a custom operating system that implements a custom bytecode interpreter. This high-throughput design for long-running, interactive targets allows us to fuzz a large number of both open source and proprietary hypervisors. In contrast to one-dimensional fuzzers such as AFL, H YPER -C UBE can interact with any number of interfaces in any order. Our evaluation results show that we can find more bugs (over 2 × ) and coverage (as much as 2 × ) than state-of-the-art hypervisor fuzzers. In most cases, we were even able to do so using multiple orders of magnitude less time than comparable fuzzers. H YPER -C UBE was also able to rediscover a set of well-known hypervisor vulnerabilities, such as VENOM, in less than five minutes. In total, we found 54 novel bugs, and so far obtained 43 CVEs. Our evaluation results demonstrate that next-generation coverage-guided fuzzers should incorporate a higher-throughput design for long-running targets such as hypervisors.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bcd61840-77ea-46d6-84f4-1ab8f6678e11Cited by top-tier papers30
- Boosting fuzzer efficiency: an information theoretic perspectiveMarcel Böhme, Valentin J. M. Manès, Sang Kil ChaFSE 2020 · 115 citations
- Nyx: Greybox Hypervisor Fuzzing using Fast Snapshots and Affine TypesSergej Schumilo, Cornelius Aschermann, Ali Abbasi, Simon Wörner et al.USENIX Security 2021 · 102 citations
- Nyx-net: network fuzzing with incremental snapshotsSergej Schumilo, Cornelius Aschermann, Andrea Jemmett, Ali Abbasi et al.EuroSys 2022 · 76 citations
- SoK: Prudent Evaluation Practices for FuzzingMoritz Schloegel, Nils Bars, Nico Schiller, Lukas Bernhard et al.S&P 2024 · 69 citations
- V-Shuttle: Scalable and Semantics-Aware Hypervisor Virtual Device FuzzingGaoning Pan, Xingwei Lin, Xuhong Zhang, Yongkang Jia et al.CCS 2021 · 23 citations
Builds on15
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 836 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang et al.USENIX Security 2018 · 537 citations
Related papers
- MundoFuzz: Hypervisor Fuzzing with Statistical Coverage Testing and Grammar InferenceCheolwoo Myung, Gwangmu Lee, Byoungyoung LeeUSENIX Security 2022
- HyperMirage: Direct State Manipulation in Hybrid Virtual CPU FuzzingManuel Andreas, Fabian Specht, Marius MomeuNDSS 2026
- HyperFuzzer: An Efficient Hybrid Fuzzer for Virtual CPUsXinyang Ge, Ben Niu, Robert Brotzman, Yaohui Chen et al.CCS 2021 · 9 citations
- Truman: Constructing Device Behavior Models from OS Drivers to Fuzz Virtual DevicesZheyu Ma, Qiang Liu, Zheming Li, Tingting Yin et al.NDSS 2025
- HYPERPILL: Fuzzing for Hypervisor-bugs by leveraging the Hardware Virtualization InterfaceAlexander Bulekov, Qiang Liu, Manuel Egele, Mathias PayerUSENIX Security 2024 · 15 citations
