arrow
Return

Evaluating Code Coverage for Kernel Fuzzers via Function Call Graph

delete2021-01-01
delete4
delete
OA
AI
M
Mingi Cho
H
Hoyong Jin
D
Dohyeon An
T
Taekyoung Kwon *
DOI:10.1109/ACCESS.2021.3129062delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The OS kernel, which has full system privileges, is an attractive attack surface. A kernel fuzzer that targets system calls in fuzzing is a popular tool for discovering kernel bugs that can induce kernel privilege escalation attacks. To the best of our knowledge, the relevance of code coverage, which is obtained by fuzzing, to the system call has not been studied yet. For instance, modern coverage-guided kernel fuzzers, such as Syzkaller, estimate code coverage by comparing the entire set of executed basic blocks (or edges) regardless of the system call relevancy. Our insight is that the system call relevancy could be an essential performance indicator for realizing kernel fuzzing. In this regard, this study aims to assess the system call-related code coverage of kernel fuzzers. For this purpose, we have developed a practical assessment system that leverages the Intel PT and KCOV and assessed the Linux kernel fuzzers, such as Syzkaller, Trinity, and ext4 fuzzer. The experiments on different kernel versions demonstrated that approximately 32,000-47,000 functions are implemented in the Linux kernel, and approximately 9.7-15.2% are related to the system call. Our finding is that fuzzers that achieve higher code coverage in conventional metrics do not execute more basic blocks related to system calls. Thus, we recommend that kernel fuzzers use both system call-related functions and regular basic blocks in coverage metrics to assess fuzzing performance or to improve coverage feedback.
Keywords:
Kernel
Codes
Computer bugs
Fuzzing
Linux
Tools
Licenses
Fuzzing
kernel fuzzing
evaluation
system call
code coverage

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.8W
Citations:
29.4W

Organization

Y
Yonsei University
Scholars:
4.8W
Papers: 4.6W
Citations: 5.2W
Cited Papers

Cited Papers

The Art, Science, and Engineering of Fuzzing: A Survey
err2021-11-01
err306
errOAAI
errManes, Valentin J. M.; Han, HyungSeok; Han, Choongwoo; Cha, Sang Kil; Egele, Manuel; Schwartz, Edward J.; Woo, Maverick
errShare
errSave
errShare
errSave
The Salmonella enterica sv. Typhimurium smvA, yddG and ompD (porin) genes are required for the efficient efflux of methyl viologen
err2002-10-31
err0
errOAAI
errCarlos A. Santiviago; Juan A. Fuentes; Susan M. Bueno; A. Nicole Trombert; Alejandro A. Hildago; L. Teresa Socias; Philip Youderian; Guido C. Mora
errShare
errSave
A Survey of Symbolic Execution Techniques
err2018-05-23
err410
errOAAI
errBaldoni, Roberto; Coppa, Emilio; D'Elia, Daniele Cono; Demetrescu, Camil; Finocchi, Irene
errShare
errSave
All-screen-printed Dopant Paste Interdigitated Back Contact Solar Cell
err2015-08-01
err0
errOAAI
errGiuseppe Scardera; Daniel Inns; Gonghou Wang; Shannon Dugan; Jeffrey Dee; Thomas Dang; Karim Bendimerad; Francesco Lemmi; Homer Antoniadis
errShare
errSave
α-Taxilin Interacts with Sorting Nexin 4 and Participates in the Recycling Pathway of Transferrin Receptor
err2014-04-01
err0
errOAAI
errHiroshi Sakane; Yukimi Horii; Satoru Nogami; Yoji Kawano; Takako Kaneko-Kawano; Hiromichi Shirataki
errShare
errSave
Pharmacogenomic identification of small molecules for lineage specific manipulation of subventricular zone germinal activity
err2017-03-28
err0
errOAAI
errKasum Azim; Diane Angonin; Guillaume Marcy; Francesca Pieropan; Andrea Rivera; Vanessa Donega; Claudio Cantù; Gareth Williams; Benedikt Berninger; Arthur M. Butt; Olivier Raineteau
errShare
errSave
NeuFuzz: Efficient Fuzzing With Deep Neural Network
err2019-01-01
err49
errOAAI
errWang, Yunchao; Wu, Zehui; Wei, Qiang; Wang, Qingxian
errShare
errSave
researcher View more