NDFuzz: a non-intrusive coverage-guided fuzzing framework for virtualized network devices

نویسندگان

چکیده

Abstract Network function virtualization provides programmable in-network middlewares by leveraging technologies and commodity hardware has gained popularity among all mainstream network device manufacturers. Yet it is challenging to apply coverage-guided fuzzing, one of the state-of-the-art vulnerability discovery approaches, those virtualized devices, due inevitable integrity protection adopted devices. In this paper, we propose a fuzzing framework NDFuzz for devices with novel bypassing method, which able distinguish processes from hypervisors carefully designed non-intrusive page global directory inference technique. We implement atop two black-box fuzzers evaluate three representative protocols, SNMP , DHCP NTP on nine popular obtains an average 36% coverage improvement in comparison its counterparts. discovers 2 0-Day vulnerabilities 1 1-Day guidance while fuzzer can find only them. All discovered are confirmed corresponding vendors.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

INSTRIM: Lightweight Instrumentation for Coverage-guided Fuzzing

Empowered by instrumentation, coverage-guided fuzzing monitors the program execution path taken by an input, and prioritizes inputs based on their contribution to code coverage. Although instrumenting every basic block ensures full visibility, it slows down the fuzzer and thus the speed of vulnerability discovery. This paper shows that thanks to common program structures (e.g., directed acyclic...

متن کامل

Code Coverage Measurement Framework for Android Devices

Software testing is a very important activity in the software development life cycle. Numerous general blackand white-box techniques exist to achieve different goals and there are a lot of practices for different kinds of software. The testing of embedded systems, however, raises some very special constraints and requirements in software testing. Special solutions exist in this field, but there...

متن کامل

A Power Benchmarking Framework for Network Devices

Energy efficiency is becoming increasingly important in the operation of networking infrastructure, especially in enterprise and data center networks. Researchers have proposed several strategies for energy management of networking devices. However, we need a comprehensive characterization of power consumption by a variety of switches and routers to accurately quantify the savings from the vari...

متن کامل

An Active Learning Framework for Non-Intrusive Load Monitoring: Preprint

Non-Intrusive Load Monitoring (NILM) is a set of techniques that estimates the electricity usage of individual appliances from power measurements taken at a limited number of locations in a building. One of the key challenges in NILM is having too many data lacking class labels, but being unable to label the data manually for cost or time constraints. This paper presents an active learning fram...

متن کامل

OpenVanilla - A Non-Intrusive Plug-In Framework of Text Services

Input method (IM) is a sine qua non for text entry of many Asian languages, but its potential applications on other languages remain under-explored. This paper proposes a philosophy of input method design by seeing it as a nonintrusive plug-in text service framework. Such design allows new functionalities of text processing to be attached onto a running application without any tweaking of code....

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: Cybersecurity

سال: 2022

ISSN: ['2523-3246']

DOI: https://doi.org/10.1186/s42400-022-00120-1