Truman: Constructing Device Behavior Models from OS Drivers to Fuzz Virtual Devices
Zheyu Ma, Qiang Liu, Zheming Li, Tingting Yin, Wende Tan, Chao Zhang, Mathias Payer
Abstract
Virtual devices are a large attack surface of hypervisors. Vulnerabilities in virtual devices may enable attackers to jailbreak hypervisors or even endanger co-located virtual machines. While fuzzing has discovered vulnerabilities in virtual devices across both open-source and closed-source hypervisors, the efficiency of these virtual device fuzzers remains limited because they are unaware of the complex behaviors of virtual devices in general. We present Truman, a novel universal fuzzing engine that automatically infers dependencies from open-source OS drivers to construct device behavior models (DBMs) for virtual device fuzzing, regardless of whether target virtual devices are open-source or binaries. The DBM includes inter- and intra-message dependencies and fine-grained state dependency of virtual device messages. Based on the DBM, Truman generates and mutates quality seeds that satisfy the dependencies encoded in the DBM. We evaluate the prototype of Truman on the latest version of hypervisors. In terms of coverage, Truman outperformed start-of-the-art fuzzers for 19/29 QEMU devices and obtained a relative coverage boost of 34% compared to Morphuzz for virtio devices. Additionally, Truman discovered 54 new bugs in QEMU, VirtualBox, VMware Workstation Pro, and Parallels, with 6 CVEs assigned.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d0fba2d0-18a7-4e9b-9319-e7f93a91bff2Cited by top-tier papers5
- GDMA: Fully Automated DMA Rehosting via Iterative Type OverlaysTobias Scharnowski, Simeon Hoffmann, Moritz Bley, Simon Wörner et al.USENIX Security 2025
- Breaking Isolation: A New Perspective on Hypervisor Exploitation via Cross-Domain AttacksGaoning Pan, Yiming Tao, Qinying Wang, Chunming Wu et al.NDSS 2026
- HyperMirage: Direct State Manipulation in Hybrid Virtual CPU FuzzingManuel Andreas, Fabian Specht, Marius MomeuNDSS 2026
- Demystifying the Access Control Mechanism of ESXi VMKernelYue Liu, Zexiang Zhang, Jiaxun Zhu, Hao Zheng et al.NDSS 2026
- TETD: Trusted Execution in Trust DomainsZhanbo Wang, Jiaxin Zhan, Xuhua Ding, Fengwei Zhang et al.USENIX Security 2025
Builds on38
- CollAFL: Path Sensitive FuzzingShuitao Gan, Chao Zhang, Xiaojun Qin, Xuwen Tu et al.S&P 2018 · 426 citations
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel et al.USENIX Security 2017 · 324 citations
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo et al.NDSS 2018 · 311 citations
- DIFUZE: Interface Aware Fuzzing for Kernel DriversJake Corina, Aravind Machiry, Christopher Salls, Yan Shoshitaishvili et al.CCS 2017 · 195 citations
- Snipuzz: Black-box Fuzzing of IoT Firmware via Message Snippet InferenceXiaotao Feng, Ruoxi Sun, Xiaogang Zhu, Minhui Xue et al.CCS 2021 · 146 citations
Related papers
- Morphuzz: Bending (Input) Space to Fuzz Virtual DevicesAlexander Bulekov, Bandan Das, Stefan Hajnoczi, Manuel EgeleUSENIX Security 2022
- ViDeZZo: Dependency-aware Virtual Device FuzzingQiang Liu, Flavio Toffalini, Yajin Zhou, Mathias PayerS&P 2023
- VD-Guard: DMA Guided Fuzzing for Hypervisor Virtual DeviceYuwei Liu, Siqi Chen, Yuchong Xie, Yanhao Wang et al.ASE 2023 · 6 citations
- Insvdf: Interface-State-Aware Virtual Device FuzzingZexiang Zhang, Gaoning Pan, Ruipeng Wang, Yiming Tao et al.ICSE 2025 · 2 citations
- HYPER-CUBE: High-Dimensional Hypervisor FuzzingSergej Schumilo, Cornelius Aschermann, Ali Abbasi, Simon Wörner et al.NDSS 2020
