Application of Domain-aware Binary Fuzzing to Aid Android Virtual Machine Testing

Stephen C. Kyle, Hugh Leather, Björn Franke, D. Butcher, Stuart Monteith
{"title":"Application of Domain-aware Binary Fuzzing to Aid Android Virtual Machine Testing","authors":"Stephen C. Kyle, Hugh Leather, Björn Franke, D. Butcher, Stuart Monteith","doi":"10.1145/2731186.2731198","DOIUrl":null,"url":null,"abstract":"The development of a new application virtual machine (VM), like the creation of any complex piece of software, is a bug-prone process. In version 5.0, the widely-used Android operating system has changed from the Dalvik VM to the newly-developed ART VM to execute Android applications. As new iterations of this VM are released, how can the developers aim to reduce the number of potentially security-threatening bugs that make it into the final product? In this paper we combine domain-aware binary fuzzing and differential testing to produce DexFuzz, a tool that exploits the presence of multiple modes of execution within a VM to test for defects. These modes of execution include the interpreter and a runtime that executes ahead-of-time compiled code. We find and present a number of bugs in the in-development version of ART in the Android Open Source Project. We also assess DexFuzz's ability to highlight defects in the experimental version of ART released in the previous version of Android, 4.4, finding 189 crashing programs and 15 divergent programs that indicate defects after only 5,000 attempts.","PeriodicalId":186972,"journal":{"name":"Proceedings of the 11th ACM SIGPLAN/SIGOPS International Conference on Virtual Execution Environments","volume":"78 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-03-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"13","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 11th ACM SIGPLAN/SIGOPS International Conference on Virtual Execution Environments","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/2731186.2731198","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 13

Abstract

The development of a new application virtual machine (VM), like the creation of any complex piece of software, is a bug-prone process. In version 5.0, the widely-used Android operating system has changed from the Dalvik VM to the newly-developed ART VM to execute Android applications. As new iterations of this VM are released, how can the developers aim to reduce the number of potentially security-threatening bugs that make it into the final product? In this paper we combine domain-aware binary fuzzing and differential testing to produce DexFuzz, a tool that exploits the presence of multiple modes of execution within a VM to test for defects. These modes of execution include the interpreter and a runtime that executes ahead-of-time compiled code. We find and present a number of bugs in the in-development version of ART in the Android Open Source Project. We also assess DexFuzz's ability to highlight defects in the experimental version of ART released in the previous version of Android, 4.4, finding 189 crashing programs and 15 divergent programs that indicate defects after only 5,000 attempts.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
领域感知二进制模糊测试在Android虚拟机测试中的应用
新应用程序虚拟机(VM)的开发,就像任何复杂软件的创建一样,是一个容易出现错误的过程。在5.0版本中,广泛使用的Android操作系统从Dalvik VM改为新开发的ART VM,用于执行Android应用程序。随着该VM的新迭代的发布,开发人员如何才能减少最终产品中潜在的安全威胁错误的数量?在本文中,我们结合了域感知二进制模糊测试和差分测试来生成DexFuzz,这是一种利用VM中存在的多种执行模式来测试缺陷的工具。这些执行模式包括解释器和执行预先编译代码的运行时。我们在Android开源项目的ART开发版本中发现并呈现了一些bug。我们还评估了DexFuzz在上一版本Android 4.4中发布的ART实验版本中突出缺陷的能力,仅在5000次尝试后就发现了189个崩溃程序和15个显示缺陷的分歧程序。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Supporting High Performance Molecular Dynamics in Virtualized Clusters using IOMMU, SR-IOV, and GPUDirect Migration of Web Applications with Seamless Execution A-DRM: Architecture-aware Distributed Resource Management of Virtualized Clusters HeteroVisor: Exploiting Resource Heterogeneity to Enhance the Elasticity of Cloud Platforms PEMU: A Pin Highly Compatible Out-of-VM Dynamic Binary Instrumentation Framework
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1