MoonShine: Optimizing OS Fuzzer Seed Selection with Trace Distillation
Shankara Pailoor, Andrew Aday, Suman Jana
摘要
OS fuzzers primarily test the system-call interface between the OS kernel and user-level applications for security vulnerabilities. The effectiveness of all existing evolutionary OS fuzzers depends heavily on the quality and diversity of their seed system call sequences. However, generating good seeds for OS fuzzing is a hard problem as the behavior of each system call depends heavily on the OS kernel state created by the previously executed system calls. Therefore, popular evolutionary OS fuzzers often rely on hand-coded rules for generating valid seed sequences of system calls that can bootstrap the fuzzing process. Unfortunately, this approach severely restricts the diversity of the seed system call sequences and therefore limits the effectiveness of the fuzzers. In this paper, we develop MoonShine, a novel strategy for distilling seeds for OS fuzzers from system call traces of real-world programs while still preserving the dependencies across the system calls. MoonShine leverages light-weight static analysis for efficiently detecting dependencies across different system calls. We designed and implemented MoonShine as an extension to Syzkaller, a state-of-the-art evolutionary fuzzer for the Linux kernel. Starting from traces containing 2.8 million system calls gathered from 3,220 real-world programs, MoonShine distilled down to just over 14,000 calls while preserving 86% of the original code coverage. Using these distilled seed system call sequences, MoonShine was able to improve Syzkaller's achieved code coverage for the Linux kernel by 13% on average. MoonShine also found 17 new vulnerabilities in the Linux kernel that were not found by Syzkaller.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper91
- CodeAlchemist: Semantics-Aware Code Generation to Find Vulnerabilities in JavaScript EnginesHyungSeok Han, DongHyeon Oh, Sang Kil ChaNDSS 2019 · 被引用 178 次
- SMARTIAN: Enhancing Smart Contract Fuzzing with Static and Dynamic Data-Flow AnalysesJaeseung Choi, Doyeon Kim, Soomin Kim, Gustavo Grieco 等ASE 2021 · 被引用 164 次
- Where Does It Go?: Refining Indirect-Call Targets with Multi-Layer Type AnalysisKangjie Lu, Hong HuCCS 2019 · 被引用 142 次
- Krace: Data Race Fuzzing for Kernel File SystemsMeng Xu, Sanidhya Kashyap, Hanqing Zhao, Taesoo KimS&P 2020 · 被引用 131 次
- ProFuzzer: On-the-fly Input Type Probing for Better Zero-Day Vulnerability DiscoveryWei You, Xueqiang Wang, Shiqing Ma, Jianjun Huang 等S&P 2019 · 被引用 130 次
它引用的顶会 Paper5
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel 等USENIX Security 2017 · 被引用 324 次
- SlowFuzz: Automated Domain-Independent Detection of Algorithmic Complexity VulnerabilitiesTheofilos Petsios, Jason Zhao, Angelos D. Keromytis, Suman JanaCCS 2017 · 被引用 214 次
- IMF: Inferred Model-based FuzzerHyungSeok Han, Sang Kil ChaCCS 2017 · 被引用 139 次
- NEZHA: Efficient Domain-Independent Differential TestingTheofilos Petsios, Adrian Tang, Salvatore J. Stolfo, Angelos D. Keromytis 等S&P 2017 · 被引用 132 次
- Digtool: A Virtualization-Based Framework for Detecting Kernel VulnerabilitiesJianfeng Pan, Guanglu Yan, Xiaocao FanUSENIX Security 2017 · 被引用 44 次
相关 Paper
- KSG: Augmenting Kernel Fuzzing with System Call Specification GenerationHao Sun, Yuheng Shen, Jianzhong Liu, Yiru Xu 等USENIX ATC 2022 · 被引用 45 次
- HEALER: Relation Learning Guided Kernel FuzzingHao Sun, Yuheng Shen, Cong Wang, Jianzhong Liu 等SOSP 2021 · 被引用 59 次
- HFL: Hybrid Fuzzing on the Linux KernelKyungtae Kim, Dae R. Jeong, Chung Hwan Kim, Yeongjin Jang 等NDSS 2020
- SyzVegas: Beating Kernel Fuzzing Odds with Reinforcement LearningDaimeng Wang, Zheng Zhang, Hang Zhang, Zhiyun Qian 等USENIX Security 2021 · 被引用 75 次
- SyzDescribe: Principled, Automated, Static Generation of Syscall Descriptions for Kernel DriversYu Hao, Guoren Li, Xiaochen Zou, Weiteng Chen 等S&P 2023
