Data flow sensitive driver vulnerability mining method
Yechuan Bi, Jianshan Peng, Zhiqiang Lin · Proceedings of the 2021 5th International Conference on Electronic Information Technology and Computer Engineering · 2021
In 2017, the "Eternal Blue" vulnerability broke out, and people began to pay more attention to the vulnerabilities in the operating system itself. However, the complexity of the operating system determines that its vulnerability mining is difficult and inefficient. Driver vulnerabilities are as seriously harmful as system vulnerabilities. Currently, fuzzing is the most effective method of exploiting vulnerabilities for drivers without source code. Due to the hierarchical design of the system and the protection of the kernel of operating system, it is difficult to improve the efficiency of driver fuzzing. Based on the input and variable dependencies of the driver when passing parameters, the relationship model of seed and branch matching is established, and the seeds with different weights are sorted through the characteristics of the data flow. While guiding the direction of seed mutation, certain deep-seated vulnerabilities have also been touched. Experiments have proved that this method can greatly improve the module coverage of fuzz testing, thereby improving the efficiency of vulnerability discovery.