Leveraging Binary Coverage for Effective Generation Guidance in Kernel Fuzzing
Jianzhong Liu, Yuheng Shen, Yiru Xu, Yu Jiang · 2024
State-of-the-art kernel fuzzers use edge-based code coverage metrics for novel behavior detection. However, code coverage is not sufficient for operating system kernels, for they contain many untracked but interesting features, such as comparison operands, kernel state identifiers, flags, and executable code, within its data segments, that reflects different execution patterns, and can profoundly increase the granularity and scope of the coverage metrics.