Proceedings Article10.1145/3548606.3559367
SFuzz
Libo Chen,Quanpu Cai,Zhenbang Ma,Yanhao Wang,Ming Shen,Yue Liu,Shanqing Guo,Haixin Duan,Kaida Jiang,Zhi Xue +9 more
- 07 Nov 2022
8
Abstract: Real-Time Operating System (RTOS) has become the main category of embedded systems. It is widely used to support tasks requiring real-time response such as printers and switches. The security of RTOS has been long overlooked as it was running in special environments isolated from attackers. However, with the rapid development of IoT devices, tremendous RTOS devices are connected to the public network. Due to the lack of security mechanisms, these devices are extremely vulnerable to a wide spectrum of attacks. Even worse, the monolithic design of RTOS combines various tasks and services into a single binary, which hinders the current program testing and analysis techniques working on RTOS. In this paper, we propose SFuzz, a novel slice-based fuzzer, to detect security vulnerabilities in RTOS. Our insight is that RTOS usually divides a complicated binary into many separated but single-minded tasks. Each task accomplishes a particular event in a deterministic way and its control flow is usually straightforward and independent. Therefore, we identify such code from the monolithic RTOS binary and synthesize a slice for effective testing. Specifically, SFuzz first identifies functions that handle user input, constructs call graphs that start from callers of these functions, and leverages forward slicing to build the execution tree based on the call graphs and pruning the paths independent of external inputs. Then, it detects and handles roadblocks within the coarse-grain scope that hinder effective fuzzing, such as instructions unrelated to the user input. And then, it conducts coverage-guided fuzzing on these code snippets. Finally, SFuzz leverages forward and backward slicing to track and verify each path constraint and determine whether a bug discovered in the fuzzer is a real vulnerability. SFuzz successfully discovered 77 zero-day bugs on 35 RTOS samples, and 67 of them have been assigned CVE or CNVD IDs. Our empirical evaluation shows that SFuzz outperforms the state-of-the-art tools (e.g., UnicornAFL) on testing RTOS.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
SoK: Prudent Evaluation Practices for Fuzzing
Moritz Schloegel,Nils Bars,Nico Schiller,Lukas Bernhard,Tobias Scharnowski,Addison Crump,Arash Ale Ebrahim,Nicolai Bissantz,Marius Muench,Thorsten Holz +9 more
- 16 May 2024
TL;DR: The evaluation practices in fuzzing papers are often inadequate and lack reproducibility. Existing guidelines are not widely followed, and there is a need for more rigorous evaluation practices to ensure the validity of results.
13
Enhancing Function Name Prediction using Votes-Based Name Tokenization and Multi-Task Learning
Xiaoling Zhang,Zhengzi Xu,Shouguo Yang,Zhi Li,Zhiqiang Shi,Limin Sun +5 more
- 15 May 2024
TL;DR: Epitome enhances function name prediction using votes-based name tokenization and multi-task learning, improving the accuracy and generalizability of function name prediction in diverse optimized binaries.
Harnessing LLMs for Document-Guided Fuzzing of OpenCV Library
Bin Duan,Tarek Mahmud,Meiru Che,Yan Yan,Naipeng Dong,D. Kim,Guowei Yang +6 more
TL;DR: This paper introduces VISTAFUZZ, a novel technique using large language models for document-guided fuzzing of the OpenCV library, detecting 17 new bugs, including 10 confirmed and 5 fixed, through systematic testing of 330 APIs.
IEmu: Interrupt modeling from the logic hidden in the firmware
Yuan Wei,Xiaogang Wang,Lei Zhou,Xu Zhou,Zhiyuan Jiang +4 more
A Vulnerability Scanning Method for Web Services in Embedded Firmware
Xiaocheng Ma,Yunchao Wang,Qiang Wei,Yunfeng Wang +3 more
TL;DR: A lightweight vulnerability scanning approach, WFinder, designed for embedded firmware web services to perform vulnerability checks on backend binary files in firmware.
References
KLEE: unassisted and automatic generation of high-coverage tests for complex systems programs
Cristian Cadar,Daniel Dunbar,Dawson Engler +2 more
- 08 Dec 2008
TL;DR: A new symbolic execution tool, KLEE, capable of automatically generating tests that achieve high coverage on a diverse set of complex and environmentally-intensive programs, and significantly beat the coverage of the developers' own hand-written test suite is presented.
•Proceedings Article
StackGuard: automatic adaptive detection and prevention of buffer-overflow attacks
Crispin Cowan,Calton Pu,Dave Maier,Heather Hintony,Jonathan Walpole,Peat Bakke,Steve Beattie,Aaron Grier,Perry Wagle,Qian Zhang +9 more
- 26 Jan 1998
TL;DR: StackGuard is described: a simple compiler technique that virtually eliminates buffer overflow vulnerabilities with only modest performance penalties, and a set of variations on the technique that trade-off between penetration resistance and performance.
SOK: (State of) The Art of War: Offensive Techniques in Binary Analysis
Yan Shoshitaishvili,Ruoyu Wang,Christopher Salls,Nick Stephens,Mario Polino,Andrew Dutcher,John Grosen,Siji Feng,Christophe Hauser,Christopher Kruegel,Giovanni Vigna +10 more
- 22 May 2016
TL;DR: This paper presents a binary analysis framework that implements a number of analysis techniques that have been proposed in the past and implements these techniques in a unifying framework, which allows other researchers to compose them and develop new approaches.
Driller: Augmenting Fuzzing Through Selective Symbolic Execution.
Nick Stephens,John Grosen,Christopher Salls,Andrew Dutcher,Ruoyu Wang,Jacopo Corbetta,Yan Shoshitaishvili,Christopher Kruegel,Giovanni Vigna +8 more
- 01 Jan 2016
TL;DR: Driller is presented, a hybrid vulnerability excavation tool which leverages fuzzing and selective concolic execution in a complementary manner, to find deeper bugs and mitigate their weaknesses, avoiding the path explosion inherent in concolic analysis and the incompleteness of fuzzing.
1K
Directed Greybox Fuzzing
Marcel Böhme,Van-Thuan Pham,Manh-Dung Nguyen,Abhik Roychoudhury +3 more
- 30 Oct 2017
TL;DR: This paper introduces Directed Greybox Fuzzing (DGF) which generates inputs with the objective of reaching a given set of target program locations efficiently, and develops and evaluates a simulated annealing-based power schedule that gradually assigns more energy to seeds that are closer to the target locations while reducing energy for Seeds that are further away.
766