arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

POZZER:面向黑盒嵌入式系统的功率侧信道引导模糊测试器

POZZER: A Power Side Channel-guided Fuzzer for Black-Box Embedded Systems

Pouya Narimani, Kseniia Rogova, Addison Crump, Martin Mohl, Meng Wang, Ulysse Planta, Pansilu Pitigalaarachchi, Ali Abbasi

arXiv 2609.23583首次发表:更新:

发表机构

CISPA Helmholtz Center for Information Security(CISPA赫尔霍兹信息安全中心)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

POZZER利用功率侧信道轨迹作为反馈,通过图表示引导黑盒嵌入式系统模糊测试,无需固件源码或调试接口,在30个目标-平台组合中26个优于盲模糊测试,并发现两个已确认漏洞。

AI 中文摘要

固件模糊测试是发现嵌入式系统漏洞的有效技术。然而,现有的覆盖率引导固件模糊测试器通常通过固件插桩、硬件调试接口或固件重托管来获取反馈,这需要访问固件源代码或二进制镜像。对于现成的嵌入式设备,这些要求往往不可行,因为其固件二进制文件不可访问、不可重托管、不可修改或不可调试,因此必须在黑盒条件下进行模糊测试。在本文中,我们提出了POZZER,一种面向黑盒嵌入式系统的功率侧信道引导模糊测试器。POZZER使用功率轨迹作为反馈,通过增量构建的、基于图的观测执行表示来识别未见过的行为,从而引导模糊测试器探索未执行的路径。其非剖析设计既不需要先验固件知识,也不需要克隆设备,仅从每次执行的单条功率轨迹中提取有效反馈,同时对测量噪声具有鲁棒性。我们在两个平台上的15个固件目标以及两个真实世界的商业嵌入式设备上评估了POZZER。在由此产生的目标-平台组合中,POZZER在相同时间预算下,在30个目标-平台组合中的26个上优于盲模糊测试器。此外,POZZER在一个商业设备中发现了两个先前未知的漏洞,且均已被供应商确认,展示了其在黑盒嵌入式系统中识别漏洞的潜力。

英文摘要

Firmware fuzzing is an effective technique for discovering vulnerabilities in embedded systems. However, existing coverage-guided firmware fuzzers typically obtain feedback through firmware instrumentation, hardware debug interfaces, or firmware rehosting, which requires access to the firmware source code or binary image. Such requirements are often infeasible for off-the-shelf embedded devices, where firmware binaries are inaccessible, unrehostable, immodifiable, or undebuggable, necessitating fuzzing under black-box conditions. In this paper, we present POZZER, a power side-channel-guided fuzzer for black-box embedded systems. POZZER uses power traces as feedback to identify previously unseen behavior via an incrementally constructed graph-based representation of observed executions, guiding the fuzzer toward unexplored execution paths. Its non-profiling design requires neither prior firmware knowledge nor a clone device, extracting meaningful feedback from a single power trace per execution while remaining robust to measurement noise. We evaluate POZZER on 15 firmware targets across two platforms and two real-world commercial embedded devices. Across the resulting target-platform combinations, POZZER outperforms a blind fuzzer under the same time budget in 26 out of 30 target-platform combinations. Furthermore, POZZER discovers two previously unknown vulnerabilities in one of the commercial devices, both confirmed by the vendor, demonstrating its potential for identifying vulnerabilities in black-box embedded systems.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑