节点文献

一种UEFI DXE驱动二进制模糊测试方法

A Binary Fuzzy Test Method for UEFI DXE Drivers

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 龙翔崔宝江吴佳桐

【Author】 LONG Xiang;CUI Baojiang;WU Jiatong;School of Cyber Security, Beijing University of Posts and Telecommunications;

【通讯作者】 崔宝江;

【机构】 北京邮电大学网络空间安全学院

【摘要】 为了简化现有统一可扩展固件接口驱动执行环境(UEFI DXE)驱动的二进制安全分析流程,提出了一种基于依赖分析和调用劫持的UEFI DXE驱动仿真技术和基于调用引导和即时检测的灰盒模糊测试方法。实验结果证明,所提方法在公开评测样本集上可以检出全部种类的漏洞,并在已知公开漏洞披露的UEFI DXE固件上得到验证,所提方法可以达到更高的代码覆盖率,且需要的前置条件更少。

【Abstract】 To simplify the binary security analysis process of existing unified extensible firmware interface driver execution environment(UEFI DXE) driver, a fuzzing method for UEFI DXE binary based on dependency analysis and call hijacking is proposed. A driver emulation technology and a gray-box fuzzing method based on call guidance and on-the-fly detection is also proposed. The experiment results show that all types of vulnerabilities can be detected on the public evaluation sample set and verified on the UEFI DXE firmware with known common vulnerabilities & exposures. Moreover, the proposed method can achieve higher code coverage with fewer pre-requisites.

【基金】 中央高校基本科研业务费专项项目(2019XD-A19)
  • 【文献出处】 北京邮电大学学报 ,Journal of Beijing University of Posts and Telecommunications , 编辑部邮箱 ,2023年01期
  • 【分类号】TP311.53;TP309
  • 【下载频次】23
节点文献中: 

本文链接的文献网络图示:

本文的引文网络