NetPanic: the Attack Surface You Can't Syscall
Tianshuo Han, Zong Cao, Zhen Dong, Xiapu Luo, Zhenyu Song, Jian Liu
摘要
The Linux kernel network stack exposes a critical remote attack surface, yet kernel security research has historically focused on the local attack surface, especially the post-breach local privilege escalation attacks. This has left a direct, pre-authentication attack vector dangerously overlooked. To address this gap, we present the first systematic, fuzzing-based audit of this attack surface. Our work first identifies the unique challenges that render existing fuzzers ineffective for this task: Extreme Input Complexity and the challenge of Dual-channel Input Coordination. To overcome them, we present NetPanic, a novel fuzzer built on a Fuzzer-in-the-Middle architecture. This design inherently solves the coordination challenge by orchestrating real communication between two network stack instances. Simultaneously, it provides a stream of valid packets that serves as a highquality baseline for our execution-guided structure-mutation strategy, which addresses the input complexity challenge. Our evaluation of NetPanic on the latest Linux kernel yielded significant results. It discovered 15 new, remotely triggerable vulnerabilities, none of which could be found or reproduced by the state-of-the-art kernel fuzzer Syzkaller. In direct comparison, NetPanic demonstrated vastly superior performance, achieving over 100 times the execution throughput and an average code coverage improvement of over 400 %. This performance gap, combined with a targeted ablation study, provides a dual validation: it confirms the correctness of our insight in identifying the unique challenges and proves the effectiveness of our solutions in addressing them. Our work provides concrete evidence that the kernel's remote attack surface is a potent and immediate threat, and we provide the community with the first effective methodology and a practical tool to begin securing it.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper20
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel 等USENIX Security 2017 · 被引用 324 次
- MoonShine: Optimizing OS Fuzzer Seed Selection with Trace DistillationShankara Pailoor, Andrew Aday, Suman JanaUSENIX Security 2018 · 被引用 180 次
- Krace: Data Race Fuzzing for Kernel File SystemsMeng Xu, Sanidhya Kashyap, Hanqing Zhao, Taesoo KimS&P 2020 · 被引用 131 次
- FUZE: Towards Facilitating Exploit Generation for Kernel Use-After-Free VulnerabilitiesWei Wu, Yueqi Chen, Jun Xu, Xinyu Xing 等USENIX Security 2018 · 被引用 124 次
- Fuzzing File Systems via Two-Dimensional Input Space ExplorationWen Xu, Hyungon Moon, Sanidhya Kashyap, Po-Ning Tseng 等S&P 2019 · 被引用 117 次
相关 Paper
- HFL: Hybrid Fuzzing on the Linux KernelKyungtae Kim, Dae R. Jeong, Chung Hwan Kim, Yeongjin Jang 等NDSS 2020
- SYSYPHUZZ: the Pressure of More CoverageZezhong Ren, Han Zheng, Zhiyao Feng, Qinying Wang 等NDSS 2026 · 被引用 1 次
- Thunderkaller: Profiling and Improving the Performance of SyzkallerYang Lan, Di Jin, Zhun Wang, Wende Tan 等ASE 2023 · 被引用 2 次
- A Little Goes a Long Way: Tuning Configuration Selection for Continuous Kernel FuzzingSanan Hasanov, Stefan Nagy, Paul GazzilloICSE 2025 · 被引用 6 次
- SyzDirect: Directed Greybox Fuzzing for Linux KernelXin Tan, Yuan Zhang, Jiadong Lu, Xin Xiong 等CCS 2023 · 被引用 25 次
