PCPFuzz: Path Coverage Protocol Based Firmware Fuzzing System

Lin Li, Ruoran Xu, Leran Chen, Bin Dong, Wei Chen, Xiaotian Xu · 2023

With the development of 5G technology, Internet of thing (IoT) devices are widely used and the exposed number in the network is growing. IoT devices bring many security issues and mature security analysis techniques cannot be applied because of its poor performance and diverse architecture, which makes vulnerability mining less efficient for IoT devices.This paper proposes a firmware fuzzing system based on path coverage protocol (PCPFuzz) to solve vulnerability mining problem for binary program of IoT devices. The main works include: 1) A firmware program instrumentation method is proposed based on virtual operating environment to run target program on x86 host without real device. And realizing dynamic instrumentation of target program with remote debugging technology. 2) A basic block-based firmware program instrumentation strategy is proposed and dynamic insertion and cleanup of instrumentation points is realized by constructing control flow graph (CFG). And using dynamic instrumentation algorithm to reduce unnecessary instrumentation points to improve the program execution efficiency. 3) A test case mutation strategy based on path feedback is proposed with feedback fuzzing technology. Based on generating fuzzing seeds constrained, obtaining program execution information with instrumentation technology and calculating path coverage as feedback information to guide fuzzing seed mutation process, which can quickly improve path coverage to make program execution path closer to dangerous path. Through experimental comparison, PCPFuzz system proposed can achieve higher path coverage and improve fuzzing efficiency compared with current common protocol fuzzing tools, Peach and boofuzz.

Read the paper · More papers on PaperTik