Battling against Protocol Fuzzing: Protecting Networked Embedded Devices from Dynamic Fuzzers

模糊测试 计算机科学 协议(科学) 计算机安全 混淆 加密 编码(集合论) 架空(工程) 嵌入式系统 操作系统 程序设计语言 软件 集合(抽象数据类型) 医学 替代医学 病理
作者
Puzhuo Liu,Yaowen Zheng,C. P. Sun,Hong Li,Zhi Li,Limin Sun
出处
期刊:ACM Transactions on Software Engineering and Methodology [Association for Computing Machinery]
标识
DOI:10.1145/3641847
摘要

N etworked E mbedded D evices (NEDs) are increasingly targeted by cyberattacks, mainly due to their widespread use in our daily lives. Vulnerabilities in NEDs are the root causes of these cyberattacks. Although deployed NEDs go through thorough code audits, there can still be considerable exploitable vulnerabilities. Existing mitigation measures like code encryption and obfuscation adopted by vendors can resist static analysis on deployed NEDs, but are ineffective against protocol fuzzing. Attackers can easily apply protocol fuzzing to discover vulnerabilities and compromise deployed NEDs. Unfortunately, prior anti-fuzzing techniques are impractical as they significantly slow down NEDs, hampering NED availability. To address this issue, we propose Armor—the first anti-fuzzing technique specifically designed for NEDs. First, we design three adversarial primitives—delay, fake coverage, and forged exception—to break the fundamental mechanisms on which fuzzing relies to effectively find vulnerabilities. Second, based on our observation that inputs from normal users consistent with the protocol specification and certain program paths are rarely executed with normal inputs, we design static and dynamic strategies to decide whether to activate the adversarial primitives. Extensive evaluations show that Armor incurs negligible time overhead and effectively reduces the code coverage (e.g., line coverage by 22%-61%) for fuzzing, significantly outperforming the state-of-the-art.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
1秒前
1秒前
椰子完成签到 ,获得积分10
2秒前
2秒前
LL666完成签到 ,获得积分10
3秒前
3秒前
所所应助依依采纳,获得10
3秒前
愉快的犀牛完成签到 ,获得积分10
3秒前
月月发布了新的文献求助10
3秒前
儒雅猕猴桃完成签到 ,获得积分10
4秒前
CR完成签到 ,获得积分10
4秒前
sdfasde完成签到,获得积分10
5秒前
5秒前
瓦猫完成签到,获得积分10
5秒前
zl12345发布了新的文献求助10
5秒前
漏晨完成签到,获得积分10
6秒前
6秒前
科研小越发布了新的文献求助10
6秒前
zzx完成签到,获得积分10
7秒前
小小鱼儿完成签到,获得积分10
7秒前
wanci应助memory采纳,获得10
8秒前
bkagyin应助小了白了兔采纳,获得10
8秒前
辛夷完成签到,获得积分10
9秒前
惜曦完成签到 ,获得积分10
9秒前
搜集达人应助Harlotte采纳,获得10
10秒前
Maxpan发布了新的文献求助10
10秒前
唐文硕发布了新的文献求助10
10秒前
zhouyunan完成签到,获得积分10
10秒前
11秒前
11秒前
11秒前
11秒前
哈哈哈完成签到,获得积分10
11秒前
科研通AI5应助兔兔采纳,获得10
11秒前
huangbaba11发布了新的文献求助10
12秒前
研友_nPPzon完成签到,获得积分10
12秒前
星辰大海应助月月采纳,获得10
12秒前
完美世界应助科研通管家采纳,获得10
12秒前
12秒前
高分求助中
Technologies supporting mass customization of apparel: A pilot project 600
Chinesen in Europa – Europäer in China: Journalisten, Spione, Studenten 500
Arthur Ewert: A Life for the Comintern 500
China's Relations With Japan 1945-83: The Role of Liao Chengzhi // Kurt Werner Radtke 500
Two Years in Peking 1965-1966: Book 1: Living and Teaching in Mao's China // Reginald Hunt 500
材料概论 周达飞 ppt 500
Introduction to Strong Mixing Conditions Volumes 1-3 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 物理 生物化学 纳米技术 计算机科学 化学工程 内科学 复合材料 物理化学 电极 遗传学 量子力学 基因 冶金 催化作用
热门帖子
关注 科研通微信公众号,转发送积分 3808644
求助须知:如何正确求助?哪些是违规求助? 3353384
关于积分的说明 10364826
捐赠科研通 3069560
什么是DOI,文献DOI怎么找? 1685660
邀请新用户注册赠送积分活动 810653
科研通“疑难数据库(出版商)”最低求助积分说明 766233