USBFuzz: A Framework for Fuzzing USB Drivers by Device Emulation
Hui Peng, Mathias Payer
摘要
The Universal Serial Bus (USB) connects external devices to a host. This interface exposes the OS kernels and device drivers to attacks by malicious devices. Unfortunately, kernels and drivers were developed under a security model that implicitly trusts connected devices. Drivers expect faulty hardware but not malicious attacks. Similarly, security testing drivers is challenging as input must cross the hardware/software barrier. Fuzzing, the most widely used bug finding technique, relies on providing random data to programs. However, fuzzing device drivers is challenging due to the difficulty in crossing the hardware/software barrier and providing random device data to the driver under test. We present USBFuzz, a portable, flexible, and modular framework for fuzz testing USB drivers. At its core, USB-Fuzz uses a software-emulated USB device to provide random device data to drivers (when they perform IO operations). As the emulated USB device works at the device level, porting it to other platforms is straight-forward. Using the USBFuzz framework, we apply (i) coverage-guided fuzzing to a broad range of USB drivers in the Linux kernel; (ii) dumb fuzzing in FreeBSD, MacOS, and Windows through cross-pollination seeded by the Linux inputs; and (iii) focused fuzzing of a USB webcam driver. USBFuzz discovered a total of 26 new bugs, including 16 memory bugs of high security impact in various Linux subsystems (USB core, USB sound, and network), one bug in FreeBSD, three in MacOS (two resulting in an unplanned reboot and one freezing the system), and four in Windows 8 and Windows 10 (resulting in Blue Screens of Death), and one bug in the Linux USB host controller driver and another one in a USB camera driver. From the Linux bugs, we have fixed and upstreamed 11 bugs and received 10 CVEs.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper47
- Nyx: Greybox Hypervisor Fuzzing using Fast Snapshots and Affine TypesSergej Schumilo, Cornelius Aschermann, Ali Abbasi, Simon Wörner 等USENIX Security 2021 · 被引用 102 次
- Nyx-net: network fuzzing with incremental snapshotsSergej Schumilo, Cornelius Aschermann, Andrea Jemmett, Ali Abbasi 等EuroSys 2022 · 被引用 76 次
- The Use of Likely Invariants as Feedback for FuzzersAndrea Fioraldi, Daniele Cono D'Elia, Davide BalzarottiUSENIX Security 2021 · 被引用 67 次
- FuzzUSB: Hybrid Stateful Fuzzing of USB Gadget StacksKyungtae Kim, Taegyu Kim, Ertza Warraich, Byoungyoung Lee 等S&P 2022 · 被引用 32 次
- Static Detection of Unsafe DMA Accesses in Device DriversJia-Ju Bai, Tuo Li, Kangjie Lu, Shi-Min HuUSENIX Security 2021 · 被引用 28 次
它引用的顶会 Paper8
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel 等USENIX Security 2017 · 被引用 324 次
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo 等NDSS 2018 · 被引用 311 次
- Razzer: Finding Kernel Race Bugs through FuzzingDae R. Jeong, Kyungtae Kim, Basavesh Shivakumar, Byoungyoung Lee 等S&P 2019 · 被引用 202 次
- DIFUZE: Interface Aware Fuzzing for Kernel DriversJake Corina, Aravind Machiry, Christopher Salls, Yan Shoshitaishvili 等CCS 2017 · 被引用 195 次
- PeriScope: An Effective Probing and Fuzzing Framework for the Hardware-OS BoundaryDokyung Song, Felicitas Hetzelt, Dipanjan Das, Chad Spensky 等NDSS 2019 · 被引用 114 次
相关 Paper
- DevFuzz: Automatic Device Model-Guided Device Driver FuzzingYilun Wu, Tong Zhang, Changhee Jung, Dongyoon LeeS&P 2023
- Saturn: Host-Gadget Synergistic USB Driver FuzzingYiru Xu, Hao Sun, Jianzhong Liu, Yuheng Shen 等S&P 2024 · 被引用 13 次
- ReUSB: Replay-Guided USB Driver FuzzingJisoo Jang, Minsuk Kang, Dokyung SongUSENIX Security 2023
- DNAFuzz: Descriptor-Aware Fuzzing for USB DriversZhengshu Wang, Peng He, Fuchen Ma, Yuanliang Chen 等ASE 2025
- PrIntFuzz: fuzzing Linux drivers via automated virtual device simulationZheyu Ma, Bodong Zhao, Letu Ren, Zheming Li 等ISSTA 2022 · 被引用 23 次
