arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.17729cs.CR

BullsEye:定向固件模糊测试

BullsEye: Directed Firmware Fuzzing

Lorenzo Ralli, Emilio Coppa

首次发表
浏览论文内容

中文总结 AI 辅助

本文提出首个基于基本块级距离调度闭源Linux固件模糊测试的定向灰盒模糊测试框架BULLSEYE,在40个漏洞位点上的漏洞暴露时间较基线缩短9.5至72.5倍,性能优于对比框架。

中文摘要 AI 辅助

物联网(IoT)设备的广泛应用扩大了数字攻击面,使得固件分析对现代软件安全至关重要。一个关键的安全问题源于第三方软件组件的频繁复用,这种做法常将已知漏洞引入固件镜像中。给定镜像是否实际暴露此类漏洞是一个悬而未决的问题,而公开的概念验证漏洞利用使得回答该问题变得紧迫。定向灰盒模糊测试(Directed Greybox Fuzzing, DGF)是一种能对特定二进制位置进行定向探索的技术,为检测此类漏洞提供了有前景的解决方案。然而,DGF在固件领域仅达到函数粒度,过于粗糙,无法瞄准漏洞块本身。本文提出BULLSEYE,这是首个通过与用户指定目标的基本块级距离来调度基于Linux的闭源固件模糊测试的DGF框架。我们的方法结合静态与动态分析,以在受限的固件领域实现DGF,重点关注复用第三方组件中的漏洞。我们引入新颖的DGF启发式方法,解决传统方法的局限性。我们将BULLSEYE与共享其执行后端的四个灰盒模糊测试基线(包括AFLGO和WINDRANGER的重新实现)以及最先进的固件重托管框架GREENHOUSE进行对比。在32个固件镜像的40个漏洞位点上,BULLSEYE在预算内复现了所有目标,而四个基线中最强者仅复现35个;与它们相比,BULLSEYE将漏洞暴露时间(Time-to-Exposure)的几何平均值缩短了9.5倍至72.5倍;对于GREENHOUSE的流水线支持的18个目标,BULLSEYE的速度几何平均值快9.8倍。

英文摘要

The widespread adoption of Internet of Things (IoT) devices has expanded the digital attack surface, making firmware analysis critical for modern software security. A key security concern stems from the frequent reuse of third-party software components, a practice that often introduces known vulnerabilities into firmware images. Whether a given image actually exposes such a flaw is an open question, and public proof-of concept exploits make answering it urgent. Directed Greybox Fuzzing (DGF), a technique that enables targeted exploration of specific binary locations, offers a promising solution for detecting such vulnerabilities. However, DGF has reached firmware only at function granularity, too coarse to aim at the vulnerable block itself. This article presents BULLSEYE, the first DGF framework to schedule closed-source Linux-based firmware fuzzing by basic-block-level distance to user-specified targets. Our methodology combines static and dynamic analysis to enable DGF in the constrained firmware domain, focusing on vulnerabilities in reused third-party components. We introduce novel DGF heuristics that address limitations of traditional approaches. We compare BULLSEYE against four greybox-fuzzing baselines sharing its execution back-end, including reimplementations of AFLGO and WINDRANGER, and against GREENHOUSE, a state-of-the-art firmware re-hosting framework. On 40 vulnerability sites across 32 firmware images, BULLSEYE reproduces every target within budget, against 35 for the strongest of the four baselines, and reduces Time-to-Exposure by a geometric mean of 9.5x to 72.5x over them; against GREENHOUSE, on the 18 targets its pipeline supports, BULLSEYE is faster by a geometric mean of 9.8x.

↑