ADDFuzzer: A New Fuzzing Framework of Android Device Drivers

Baojiang Cui, Yunze Ni, Yilun Fu · 2015

Fuzzing has been widely used to discovery vulnerabilities in practice. Despite many linux system call fuzzers, few fuzzers of Android device drivers. In this paper, we research attack surface to Android device and present ADDFuzzer, a fuzz testing framework, especially for hunting Android device drivers' bugs and security issues. This fuzzing framework has two novel features: a flexible generator module for changing fuzzing strategy easily, and a unique mechanism for stably replaying a crash. Through a week's experiment, we also find some bugs which can cause denial-of-service attacks.

Read the paper · More papers on PaperTik