SOURCE ARCHIVE
EXTRACTED CONTENT
10,092 charsDifuzzRTL: Differential Fuzz Testing to Find CPU Bugs
- 77 citations.
Abstract
Security bugs in CPUs have critical security impacts to all the computation related hardware and software components as it is the core of the computation. In spite of the fact that architecture and security communities have explored a vast number of static or dynamic analysis techniques to automatically identify such bugs, the problem remains unsolved and challenging largely due to the complex nature of CPU RTL designs.This paper proposes DIFUZZRTL, an RTL fuzzer to automatically discover unknown bugs in CPU RTLs. DIFUZZRTL develops a register-coverage guided fuzzing technique, which efficiently yet correctly identifies a state transition in the finite state machine of RTL designs. DIFUZZRTL also develops several new techniques in consideration of unique RTL design characteristics, including cycle-sensitive register coverage guiding, asynchronous interrupt events handling, a unified CPU input format with Tilelink protocols, and drop-in-replacement designs to support various CPU RTLs. We implemented DIFUZZRTL, and performed the evaluation with three real-world open source CPU RTLs: OpenRISC Mor1kx Cappuccino, RISC-V Rocket Core, and RISC-V Boom Core. During the evaluation, DIFUZZRTL identified 16 new bugs from these CPU RTLs, all of which were confirmed by the respective development communities and vendors. Six of those are assigned with CVE numbers, and to the best of our knowledge, we reported the first and the only CVE of RISC-V cores, demonstrating its strong practical impacts to the security community.
Authors
- Jaewon Hur (Seoul National University): h-index 7; 209 citations; corresponding author
- Suhwan Song (Seoul National University): h-index 5; 136 citations
- Dongup Kwon (Seoul National University): h-index 9; 392 citations
- Eunjin Baek (Seoul National University): h-index 6; 224 citations
- Jangwoo Kim (Seoul National University): h-index 26; 2,563 citations
- Byoungyoung Lee (Seoul National University): h-index 17; 985 citations
Topics
Security and Verification in Computing, Software Testing and Debugging Techniques, Advanced Malware Detection Techniques, Computer science, Fuzz testing
References
- Vineeth V. Acharya, Sharad Bagri, Michael S. Hsiao. Branch guided functional test generation at the RTL. 2015;1-6. doi:10.1109/ets.2015.7138737.
- Patrick E. McKnight, Julius Najab. Mann‐Whitney U Test. The Corsini Encyclopedia of Psychology. 2010;1. doi:10.1002/9780470479216.corpsy0524.
- Naveen Kumar N, Rohith S, H Venkatesh Kumar. The Verilog hardware description language. Choice Reviews Online. 1991;29(04):29-2154. doi:10.5860/choice.29-2154.
- András Vargha, Harold D. Delaney. A Critique and Improvement of the CL Common Language Effect Size Statistics of McGraw and Wong. Journal of Educational and Behavioral Statistics. 2000;25(2):101-132. doi:10.3102/10769986025002101.
- Jian Wang, Huawei Li, Tao Lv, Tiancheng Wang, Xiaowei Li, Sandip Kundu. Abstraction-Guided Simulation Using Markov Analysis for Functional Verification. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems. 2015;35(2):285-297. doi:10.1109/tcad.2015.2419622.
- Peter J. Ashenden. The Designer's Guide to VHDL. 1995.
- Serdar Taşiran, Kurt Keutzer. Coverage metrics for functional validation of hardware designs. IEEE Design & Test of Computers. 2001;18(4):36-45. doi:10.1109/54.936247.
- Changwoo Min, Sanidhya Kashyap, Byoungyoung Lee, Chengyu Song, Taesoo Kim. Cross-checking semantic correctness. 2015;361-377. doi:10.1145/2815400.2815422.
- Giovanni Squillero. MicroGP—An Evolutionary Assembly Program Generator. Genetic Programming and Evolvable Machines. 2005;6(3):247-263. doi:10.1007/s10710-005-2985-x.
- P. C. Consul, G. C. Jain. A Generalization of the Poisson Distribution. Technometrics. 1973;15(4):791-799. doi:10.1080/00401706.1973.10489112.
- Shai Fine, Avi Ziv. Coverage directed test generation for functional verification using bayesian networks. 2003;286-291. doi:10.1145/775832.775907.
- Michael Katrowitz, Lisa M. Noack. I'm done simulating; now what? Verification coverage analysis and correctness checking of the DEC chip 21164 Alpha microprocessor. 1996;325-330. doi:10.1145/240518.240580.
- Lingyi Liu, Shabha Vasudevan. STAR: Generating input vectors for design validation by static analysis of RTL. 2009;32-37. doi:10.1109/hldvt.2009.5340179.
- Kypros Constantinides, Onur Mutlu, Todd Austin. Online design bug detection: RTL analysis, flexible mechanisms, and evaluation. 2008;282-293. doi:10.1109/micro.2008.4771798.
- D. Moundanos, Jacob A. Abraham, Yatin Hoskote. Abstraction techniques for validation coverage analysis and test generation. IEEE Transactions on Computers. 1998;47(1):2-14. doi:10.1109/12.656068.
- Yanhong Zhou, Tiancheng Wang, Huawei Li, Tao Lv, Xiaowei Li. Functional Test Generation for Hard-to-Reach States Using Path Constraint Solving. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems. 2015;35(6):999-1011. doi:10.1109/tcad.2015.2481863.
- Yuting Chen, Ting Su, C. P. Sun, Zhendong Su, Jianjun Zhao. Coverage-directed differential testing of JVM implementations. 2016;85-99. doi:10.1145/2908080.2908095.
- Marcel Böhme, Van-Thuan Pham, Abhik Roychoudhury. Coverage-based Greybox Fuzzing as Markov Chain. 2016;1032-1043. doi:10.1145/2976749.2978428.
- Nick Stephens, John Grosen, Christopher Salls, Andrew Dutcher, Ruoyu Wang, Jacopo Corbetta, et al. Driller: Augmenting Fuzzing Through Selective Symbolic Execution. 2016. doi:10.14722/ndss.2016.23368.
- Sanjay Rawat, Vivek Jain, Ashish Kumar, Lucian Cojocar, Cristiano Giuffrida, Herbert Bos. VUzzer: Application-aware Evolutionary Fuzzing. 2017. doi:10.14722/ndss.2017.23404.
- Theofilos Petsios, Adrian Tang, Salvatore J. Stolfo, Angelos D. Keromytis, Suman Jana. NEZHA: Efficient Domain-Independent Differential Testing. 2017;615-632. doi:10.1109/sp.2017.27.
- Caroline Lemieux, Koushik Sen. FairFuzz: a targeted mutation strategy for increasing greybox fuzz testing coverage. 2018;475-485. doi:10.1145/3238147.3238176.
- Hyung-Seok Han, Sang Kil. IMF. 2017;2345-2358. doi:10.1145/3133956.3134103.
- Shuitao Gan, Chao Zhang, Xiaojun Qin, Xuwen Tu, Kang Li, Zhongyu Pei, et al. CollAFL: Path Sensitive Fuzzing. 2018;679-696. doi:10.1109/sp.2018.00040.
- Moritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher, Werner Haas, Anders Fogh, et al. Meltdown: reading kernel memory from user space. USENIX Security Symposium. 2018;973-990.
- Jo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin, Baris Kasikci, Frank Piessens, et al. Foreshadow: extracting the keys to the intel SGX kingdom with transient out-of-order execution. Lirias (KU Leuven). 2018;991-1008.
- Insu Yun, Sang-Ho Lee, Meng Xu, Yeongjin Jang, Taesoo Kim. QSYM: a practical concolic execution engine tailored for hybrid fuzzing. USENIX Security Symposium. 2018;745-761.
- Shankara Pailoor, Andrew Aday, Suman Jana. MoonShine: Optimizing OS Fuzzer Seed Selection with Trace Distillation. USENIX Security Symposium. 2018;729-743.
- Kevin Laeufer, Jack Koenig, Donggyu Kim, Jonathan Bachrach, Koushik Sen. RFUZZ. 2018;1-8. doi:10.1145/3240765.3240842.
- Cornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig, Ahmad‐Reza Sadeghi, Daniel Teuchert. NAUTILUS: Fishing for Deep Bugs with Grammars. 2019. doi:10.14722/ndss.2019.23412.
- Rui Zhang, Calvin Deutschbein, Peng Huang, Cynthia Sturton. End-to-End Automated Exploit Generation for Validating the Security of Processor Designs. 2018;815-827. doi:10.1109/micro.2018.00071.
- Wei You, Xueqiang Wang, Shiqing Ma, Jianjun Huang, Xiangyu Zhang, Xiaofeng Wang, et al. ProFuzzer: On-the-fly Input Type Probing for Better Zero-Day Vulnerability Discovery. 2019;769-786. doi:10.1109/sp.2019.00057.
- Dae R. Jeong, Kyungtae Kim, Basavesh Ammanaghatta Shivakumar, Byoungyoung Lee, Insik Shin. Razzer: Finding Kernel Race Bugs through Fuzzing. 2019;754-768. doi:10.1109/sp.2019.00017.
- Wen Xu, Hyungon Moon, Sanidhya Kashyap, Po-Ning Tseng, Taesoo Kim. Fuzzing File Systems via Two-Dimensional Input Space Exploration. 2019;818-834. doi:10.1109/sp.2019.00035.
- Cornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik, Thorsten Holz. REDQUEEN: Fuzzing with Input-to-State Correspondence. 2019. doi:10.14722/ndss.2019.23371.
- Yuting Chen, Ting Su, Zhendong Su. Deep Differential Testing of JVM Implementations. 2019;1257-1268. doi:10.1109/icse.2019.00127.
- Dongdong She, Kexin Pei, Dave Epstein, Junfeng Yang, Baishakhi Ray, Suman Jana. NEUZZ: Efficient Fuzzing with Neural Program Smoothing. 2019;803-817. doi:10.1109/sp.2019.00052.
- Peng Chen, Hao Chen. Angora: Efficient Fuzzing by Principled Search. 2018;711-725. doi:10.1109/sp.2018.00046.
- George Klees, Andrew Ruef, Benji Cooper, Shiyi Wei, Michael Hicks. Evaluating Fuzz Testing. 2018;2123-2138. doi:10.1145/3243734.3243804.
- Chenyang Lyu, Shouling Ji, Chao Zhang, Yuwei Li, Wei‐Han Lee, Yu Song, et al. {MOPT}: Optimized Mutation Scheduling for Fuzzers. 2019;1949-1966.
- Saad Islam, Daniel Moghimi, Ida Bruhns, Moritz Krebbel, Berk Gülmezoğlu, Thomas Eisenbarth, et al. SPOILER: Speculative Load Hazards Boost Rowhammer and Cache Attacks. 2019;621-637. doi:10.13140/rg.2.2.19122.15041.
- Xixing Li, Zehui Wu, Qiang Wei, Huangyue Wu. UISFuzz: An Efficient Fuzzing Method for CPU Undocumented Instruction Searching. IEEE Access. 2019;7:149224-149236. doi:10.1109/access.2019.2946444.
- The verilog hardware description language. Microelectronics Journal. 1992;23(4):316-317. doi:10.1016/0026-2692(92)90032-v.
- M. Kantrowitz, Lisa M. Noack. I'm done simulating; now what? Verification coverage analysis and correctness checking of the DECchip 21164 Alpha microprocessor. 33rd Design Automation Conference Proceedings, 1996. 2005;325-330. doi:10.1109/dac.1996.545595.
- András Vargha, Harold D. Delaney. A Critique and Improvement of the "CL" Common Language Effect Size Statistics of McGraw and Wong. Journal of Educational and Behavioral Statistics. 2000;25(2):101. doi:10.2307/1165329.