Главная
Study mode:
on
1
Intro
2
Kernel Vulnerability
3
Inefficient Fuzzing for Race Bugs
4
Our approach: Razzer
5
Design Overview
6
Static Analysis: Example
7
Single-thread Fuzzing
8
Transformation to Multi-thread Input
9
Multi-thread Fuzzing
10
Implementation
11
Evaluation: Comparison with Syzkaller
12
Conclusion
Description:
Explore a cutting-edge approach to identifying kernel race bugs through fuzzing in this 20-minute IEEE conference talk. Delve into the innovative Razzer tool, designed to efficiently detect data races in kernel systems. Learn how static analysis and deterministic thread interleaving techniques are combined to guide fuzz testing towards potential race conditions. Discover the impact of Razzer's implementation on the latest Linux kernel versions, uncovering 30 new races with 16 confirmed and patched by developers. Gain insights into the tool's design, implementation, and evaluation, including a comparison with Syzkaller. Understand the critical importance of addressing kernel race bugs for system reliability and security, including their potential for privilege escalation attacks.

Razzer - Finding Kernel Race Bugs through Fuzzing

IEEE
Add to list
0:00 / 0:00