SyzGen++: Dependency Inference for Augmenting Kernel Driver Fuzzing
Weiteng Chen, Yu Hao, Zheng Zhang, Xiaochen Zou, Dhilung Kirat, Shachee Mishra, Douglas Lee Schales, Jiyong Jang, Zhiyun Qian
Abstract
In recent years, kernel fuzzing research has experienced a significant surge. Among various kernel fuzzers, Syzkaller stands out as the state-of-the-art tool, having identified over 5,000 bugs in the Linux kernel. Syzkaller’s success can be attributed to its utilization of manually-curated syscall specifications provided by kernel experts. However, this process is time-consuming and not scalable due to complex input structures and unknown dependencies among syscalls. Consequently, a substantial portion of the kernel codebase, specifically kernel drivers, lacks specifications, posing a significant security risk.In this paper, we introduce SyzGen++, an innovative approach for automatically inferring dependencies between syscalls and generating specifications without relying on existing test suites. Specifically, we define two fundamental building blocks of insertion and lookup operations and their pairing to accurately identify dependencies. We evaluated SyzGen++ against existing state-of-the-art techniques on both Linux and macOS drivers. Our results demonstrate that SyzGen++ uncovered 245 more dependencies. Furthermore, SyzGen++ outperforms DIFUZE, KSG, and SyzDescribe in terms of code coverage, achieving 71%, 67%, and 39% improvement on average, respectively. Notably, our evaluation discovered 10 previously unknown bugs in Linux Kernel 6.2 using specifications generated by SyzGen++, resulting in 6 CVEs, which demonstrates its effectiveness in identifying vulnerabilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e5bce23c-5cba-485d-9412-1ffa00c34189Cited by top-tier papers11
- Snowplow: Effective Kernel Fuzzing with a Learned White-box Test MutatorSishuai Gong, Wang Rui, Deniz Altinbüken, Pedro Fonseca et al.ASPLOS 2025 · 5 citations
- CountDown: Refcount-guided Fuzzing for Exposing Temporal Memory Errors in Linux KernelShuangpeng Bai, Zhechang Zhang, Hong HuCCS 2024 · 4 citations
- Revealing the Unstable Foundations of eBPF-Based Kernel ExtensionsShawn Wanxiang Zhong, Jing Liu, Andrea C. Arpaci-Dusseau, Remzi H. Arpaci-DusseauEuroSys 2025 · 4 citations
- Unlocking Low Frequency Syscalls in Kernel Fuzzing with Dependency-Based RAGZhiyu Zhang, Longxing Li, Ruigang Liang, Kai ChenISSTA 2025 · 3 citations
- SyzSpec: Specification Generation for Linux Kernel Fuzzing via Under-Constrained Symbolic ExecutionYu Hao, Juefei Pu, Xingyu Li, Zhiyun Qian et al.CCS 2025 · 2 citations
Builds on21
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- DIFUZE: Interface Aware Fuzzing for Kernel DriversJake Corina, Aravind Machiry, Christopher Salls, Yan Shoshitaishvili et al.CCS 2017 · 195 citations
- MoonShine: Optimizing OS Fuzzer Seed Selection with Trace DistillationShankara Pailoor, Andrew Aday, Suman JanaUSENIX Security 2018 · 180 citations
- IMF: Inferred Model-based FuzzerHyungSeok Han, Sang Kil ChaCCS 2017 · 139 citations
- Precise and Scalable Detection of Double-Fetch Bugs in OS KernelsMeng Xu, Chenxiong Qian, Kangjie Lu, Michael Backes et al.S&P 2018 · 95 citations
Related papers
- KSG: Augmenting Kernel Fuzzing with System Call Specification GenerationHao Sun, Yuheng Shen, Jianzhong Liu, Yiru Xu et al.USENIX ATC 2022 · 45 citations
- SyzGen: Automated Generation of Syscall Specification of Closed-Source macOS DriversWeiteng Chen, Yu Wang, Zheng Zhang, Zhiyun QianCCS 2021 · 25 citations
- SyzDescribe: Principled, Automated, Static Generation of Syscall Descriptions for Kernel DriversYu Hao, Guoren Li, Xiaochen Zou, Weiteng Chen et al.S&P 2023
- KernelGPT: Enhanced Kernel Fuzzing via Large Language ModelsChenyuan Yang, Zijie Zhao, Lingming ZhangASPLOS 2025 · 45 citations
- A Little Goes a Long Way: Tuning Configuration Selection for Continuous Kernel FuzzingSanan Hasanov, Stefan Nagy, Paul GazzilloICSE 2025 · 6 citations
