NIFuzz: Estimating Quantified Information Flow with a Fuzzer

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Blackwell, Daniel, Becker, Ingolf, Clark, David
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909465440157696
author Blackwell, Daniel
Becker, Ingolf
Clark, David
author_facet Blackwell, Daniel
Becker, Ingolf
Clark, David
contents This paper presents a scalable, practical approach to quantifying information leaks in software; these errors are often overlooked and downplayed, but can seriously compromise security mechanisms such as address space layout randomisation (ASLR) and Pointer Authentication (PAC). We introduce approaches for three different metrics to estimate the size of information leaks, including a new derivation for the calculation of conditional mutual information. Together, these metrics can inform of the relative safety of the target program against different threat models and provide useful details for finding the source of any leaks. We provide an implementation of a fuzzer, NIFuzz, which is capable of dynamically computing these metrics with little overhead and has several strategies to optimise for the detection and quantification of information leaks. We evaluate NIFuzz on a set of 14 programs -- including 8 real-world CVEs and ranging up to 278k lines of code in size -- where we find that it is capable of detecting and providing good estimates for all of the known information leaks.
format Preprint
id arxiv_https___arxiv_org_abs_2501_14500
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle NIFuzz: Estimating Quantified Information Flow with a Fuzzer
Blackwell, Daniel
Becker, Ingolf
Clark, David
Cryptography and Security
Software Engineering
This paper presents a scalable, practical approach to quantifying information leaks in software; these errors are often overlooked and downplayed, but can seriously compromise security mechanisms such as address space layout randomisation (ASLR) and Pointer Authentication (PAC). We introduce approaches for three different metrics to estimate the size of information leaks, including a new derivation for the calculation of conditional mutual information. Together, these metrics can inform of the relative safety of the target program against different threat models and provide useful details for finding the source of any leaks. We provide an implementation of a fuzzer, NIFuzz, which is capable of dynamically computing these metrics with little overhead and has several strategies to optimise for the detection and quantification of information leaks. We evaluate NIFuzz on a set of 14 programs -- including 8 real-world CVEs and ranging up to 278k lines of code in size -- where we find that it is capable of detecting and providing good estimates for all of the known information leaks.
title NIFuzz: Estimating Quantified Information Flow with a Fuzzer
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2501.14500