arrow
返回

Evaluating Code Coverage for Kernel Fuzzers via Function Call Graph

delete2021-01-01
delete4
delete
OA
AI
M
Mingi Cho
H
Hoyong Jin
D
Dohyeon An
T
Taekyoung Kwon *
DOI:10.1109/ACCESS.2021.3129062delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
The OS kernel, which has full system privileges, is an attractive attack surface. A kernel fuzzer that targets system calls in fuzzing is a popular tool for discovering kernel bugs that can induce kernel privilege escalation attacks. To the best of our knowledge, the relevance of code coverage, which is obtained by fuzzing, to the system call has not been studied yet. For instance, modern coverage-guided kernel fuzzers, such as Syzkaller, estimate code coverage by comparing the entire set of executed basic blocks (or edges) regardless of the system call relevancy. Our insight is that the system call relevancy could be an essential performance indicator for realizing kernel fuzzing. In this regard, this study aims to assess the system call-related code coverage of kernel fuzzers. For this purpose, we have developed a practical assessment system that leverages the Intel PT and KCOV and assessed the Linux kernel fuzzers, such as Syzkaller, Trinity, and ext4 fuzzer. The experiments on different kernel versions demonstrated that approximately 32,000-47,000 functions are implemented in the Linux kernel, and approximately 9.7-15.2% are related to the system call. Our finding is that fuzzers that achieve higher code coverage in conventional metrics do not execute more basic blocks related to system calls. Thus, we recommend that kernel fuzzers use both system call-related functions and regular basic blocks in coverage metrics to assess fuzzing performance or to improve coverage feedback.
Keyword:
Kernel
Codes
Computer bugs
Fuzzing
Linux
Tools
Licenses
Fuzzing
kernel fuzzing
evaluation
system call
code coverage

期刊

IEEE Access 封面图
IEEE Access
IF:
3.6
论文数:
9.8W
被引数:
29.4W

机构

Y
Yonsei University
学者数:
4.8W
论文数: 4.6W
被引数: 5.2W
引用论文

引用论文

The Art, Science, and Engineering of Fuzzing: A Survey模糊测试的艺术,科学和工程: 一项调查
err2021-11-01
err306
errOAAI
errManes, Valentin J. M.; Han, HyungSeok; Han, Choongwoo; Cha, Sang Kil; Egele, Manuel; Schwartz, Edward J.; Woo, Maverick
err分享
err收藏
err分享
err收藏
The Salmonella enterica sv. Typhimurium smvA, yddG and ompD (porin) genes are required for the efficient efflux of methyl viologen
err2002-10-31
err0
errOAAI
errCarlos A. Santiviago; Juan A. Fuentes; Susan M. Bueno; A. Nicole Trombert; Alejandro A. Hildago; L. Teresa Socias; Philip Youderian; Guido C. Mora
err分享
err收藏
A Survey of Symbolic Execution Techniques符号执行技术综述
err2018-05-23
err410
errOAAI
errBaldoni, Roberto; Coppa, Emilio; D'Elia, Daniele Cono; Demetrescu, Camil; Finocchi, Irene
err分享
err收藏
All-screen-printed Dopant Paste Interdigitated Back Contact Solar Cell
err2015-08-01
err0
errOAAI
errGiuseppe Scardera; Daniel Inns; Gonghou Wang; Shannon Dugan; Jeffrey Dee; Thomas Dang; Karim Bendimerad; Francesco Lemmi; Homer Antoniadis
err分享
err收藏
Pharmacogenomic identification of small molecules for lineage specific manipulation of subventricular zone germinal activity用于谱系特异性操纵脑室下区生发活动的小分子的药物基因组学鉴定
err2017-03-28
err0
errOAAI
errKasum Azim; Diane Angonin; Guillaume Marcy; Francesca Pieropan; Andrea Rivera; Vanessa Donega; Claudio Cantù; Gareth Williams; Benedikt Berninger; Arthur M. Butt; Olivier Raineteau
err分享
err收藏
err分享
err收藏
学者 查看更多内容