EmbedFuzz: High Speed Fuzzing Through Transplantation
Fuente:
arXiv
Guardado en:
| Autores principales: | , , , , , , , |
|---|---|
| Formato: | Preprint |
| Publicado: |
2024
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
| _version_ | 1866917870962737152 |
|---|---|
| author | Hofhammer, Florian Wang, Qinying Bhattacharyya, Atri Salehi, Majid Crispo, Bruno Egele, Manuel Payer, Mathias Busch, Marcel |
| author_facet | Hofhammer, Florian Wang, Qinying Bhattacharyya, Atri Salehi, Majid Crispo, Bruno Egele, Manuel Payer, Mathias Busch, Marcel |
| contents | Dynamic analysis and especially fuzzing are challenging tasks for embedded firmware running on modern low-end Microcontroller Units (MCUs) due to performance overheads from instruction emulation, the difficulty of emulating the vast space of available peripherals, and low availability of open-source embedded firmware. Consequently, efficient security testing of MCU firmware has proved to be a resource- and engineering-heavy endeavor.
EmbedFuzz introduces an efficient end-to-end fuzzing framework for MCU firmware. Our novel firmware transplantation technique converts binary MCU firmware to a functionally equivalent and fuzzing-enhanced version of the firmware which executes on a compatible high-end device at native performance. Besides the performance gains, our system enables advanced introspection capabilities based on tooling for typical Linux user space processes, thus simplifying analysis of crashes and bug triaging. In our evaluation against state-of-the-art MCU fuzzers, EmbedFuzz exhibits up to eight-fold fuzzing throughput while consuming at most a fourth of the energy thanks to its native execution. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2412_12746 |
| institution | arXiv |
| publishDate | 2024 |
| record_format | arxiv |
| spellingShingle | EmbedFuzz: High Speed Fuzzing Through Transplantation Hofhammer, Florian Wang, Qinying Bhattacharyya, Atri Salehi, Majid Crispo, Bruno Egele, Manuel Payer, Mathias Busch, Marcel Cryptography and Security Dynamic analysis and especially fuzzing are challenging tasks for embedded firmware running on modern low-end Microcontroller Units (MCUs) due to performance overheads from instruction emulation, the difficulty of emulating the vast space of available peripherals, and low availability of open-source embedded firmware. Consequently, efficient security testing of MCU firmware has proved to be a resource- and engineering-heavy endeavor. EmbedFuzz introduces an efficient end-to-end fuzzing framework for MCU firmware. Our novel firmware transplantation technique converts binary MCU firmware to a functionally equivalent and fuzzing-enhanced version of the firmware which executes on a compatible high-end device at native performance. Besides the performance gains, our system enables advanced introspection capabilities based on tooling for typical Linux user space processes, thus simplifying analysis of crashes and bug triaging. In our evaluation against state-of-the-art MCU fuzzers, EmbedFuzz exhibits up to eight-fold fuzzing throughput while consuming at most a fourth of the energy thanks to its native execution. |
| title | EmbedFuzz: High Speed Fuzzing Through Transplantation |
| topic | Cryptography and Security |
| url | https://arxiv.org/abs/2412.12746 |