Boosting Grey-box Fuzzing for Connected Autonomous Vehicle Systems

Lama J. Moukahal, Mohammad Zulkernine, Martin Soukup · 2021 IEEE 21st International Conference on Software Quality, Reliability and Security Companion (QRS-C) · 2021

Assuring the cybersecurity of Connected Autonomous Vehicles (CAVs) entails protecting the data, devices, network connectivity, and, most importantly, autonomous vehicles' software. Software security testing aims to minimize the attack surface of CAVs by identifying security vulnerabilities at an early stage. One of the most robust and efficient security testing methods is fuzzing. Though fuzz testing can validate the system with various scenarios, its blindness prevents it from exploring the deep paths of the system. Hence, the automotive industry needs a reliable security testing tool that dynamically explores the system and assures a comprehensive evaluation. This paper presents a hybrid fuzz testing framework (VulFuzz++) that unites the efficiency of fuzzing and the precision of concolic execution to provide the automotive industry a reliable security testing tool. VulFuzz++offloads most of the exploration process to the vulnerability-oriented fuzzer (VulFuzz) explicitly designed for automotive systems. When the fuzzer halts failing to explore different paths, VulFuzz++examines the untraversed branches and prioritizes them based on their potential to expose vulnerabilities. It utilizes a tailored, targeted concolic engine that limits the symbolic exploration to only specific functions. When the concolic engine discovers new system inputs, testing is handed over again to the fuzzer to perform a quick and efficient evaluation of the newly explored region. We implemented and experimented with the VulfFuzz++framework on a driving assistance system. VulFuzz++boosted the vulnerability exposure process of grey-box fuzzing, increasing the obtained crashes by 50%. It dramatically outperforms traditional concolic engines in assisting fuzzers, exposing 50 times more unique crashes. VulFuzz++extends the testing time moderately but assures a comprehensive examination covering 96.7% of the automotive system branches.

Read the paper · More papers on PaperTik