Leveraging Binary Coverage for Effective Generation Guidance in Kernel Fuzzing
Jianzhong Liu, Yuheng Shen, Yiru Xu, Yu Jiang
摘要
State-of-the-art kernel fuzzers use edge-based code coverage metrics for novel behavior detection. However, code coverage is not sufficient for operating system kernels, for they contain many untracked but interesting features, such as comparison operands, kernel state identifiers, flags, and executable code, within its data segments, that reflects different execution patterns, and can profoundly increase the granularity and scope of the coverage metrics. This paper proposes the use of Kernel Binary Coverage Feedback, a comprehensive and effective execution feedback method that provides metrics reflecting the execution coverage status of the entire binary coverage to kernel fuzzers. Our approach abstracts program behavior as its memory access pattern during execution, and considers all such relevant behavior, including standard memory reads and writes, predicate comparisons, etc., to obtain a coverage metric on the whole kernel binary for input generation guidance. We implemented a prototype tool KBinCov and integrated it into a popular kernel fuzzer Syzkaller. We evaluated its effectiveness against vanilla Syzkaller, as well as certain other approaches, including StateFuzz and IJON. Our results show that KBinCov achieves code and binary coverage increases of 7%, 7%, 9%, and 87%, 34%, 61%, compared to Syzkaller (using kcov), StateFuzz, and IJON, on recent versions of the Linux kernels, respectively, while only incurring a 1.74× overhead increase, less than StateFuzz and IJON's 2.5× and 2.2× figures. In addition, we found 21 previously unknown bugs using KBinCov with Syzkaller, more than Syzkaller (with kcov), StateFuzz, and IJON, which found 4, 4, and 2 bugs, respectively.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper21
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 被引用 616 次
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang 等USENIX Security 2018 · 被引用 537 次
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik 等NDSS 2019 · 被引用 413 次
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel 等USENIX Security 2017 · 被引用 324 次
- Razzer: Finding Kernel Race Bugs through FuzzingDae R. Jeong, Kyungtae Kim, Basavesh Shivakumar, Byoungyoung Lee 等S&P 2019 · 被引用 202 次
相关 Paper
- StateFuzz: System Call-Based State-Aware Linux Driver FuzzingBodong Zhao, Zheming Li, Shisong Qin, Zheyu Ma 等USENIX Security 2022
- SyzVegas: Beating Kernel Fuzzing Odds with Reinforcement LearningDaimeng Wang, Zheng Zhang, Hang Zhang, Zhiyun Qian 等USENIX Security 2021 · 被引用 75 次
- ACTOR: Action-Guided Kernel FuzzingMarius Fleischer, Dipanjan Das, Priyanka Bose, Weiheng Bai 等USENIX Security 2023
- MOCK: Optimizing Kernel Fuzzing Mutation with Context-aware DependencyJiacheng Xu, Xuhong Zhang, Shouling Ji, Yuan Tian 等NDSS 2024
- SYSYPHUZZ: the Pressure of More CoverageZezhong Ren, Han Zheng, Zhiyao Feng, Qinying Wang 等NDSS 2026 · 被引用 1 次
