SEnFuzzer: Detecting SGX Memory Corruption via Information Feedback and Tailored Interface Analysis
Donghui Yu, Jianqiang Wang, Haoran Fang, Ya Fang, Yuanyuan Zhang · 2023
Intel SGX provides protected memory called enclave to secure the private user data against corrupted or malicious OS environment. However, several researches have shown that the SGX applications suffer from memory corruption vulnerabilities, thus leading to critical information leakage. Detecting memory corruption vulnerability in SGX applications can be cumbersome. Existing works either use symbolic execution or formal methods to analyze the enclave library, which is known to be inefficient and errors prone. Fuzzing, an effective and efficient vulnerability detection method is rarely used in SGX and has limitations.