Guangming Gao

dblp:257/0071 · DBLP profile ↗
← Back
2ranked-venue papers
1as first author
2since 2021 · last 2024
0000-0002-7565-9526ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2024 Labrador: Response Guided Directed Fuzzing for Black-box IoT Devices
abstract
Fuzzing is a popular solution to finding vulnerabilities in software including IoT firmware. However, due to the challenges of emulating or rehosting firmware, some IoT devices (e.g., enterprise-level devices) can only be fuzzed in a black-box manner, which makes fuzzers blind and inefficient due to missing feedbacks (e.g., code coverage or distance). In this paper, we present a novel response guided directed fuzzing solution Labrador, able to test black-box IoT devices efficiently. Specifically, we leverage the network response to infer the execution trace of firmware and deduce the code coverage of testing. Second, we leverage the test case (i.e., request) and its response to estimate the distance to the target sensitive code (i.e., sink). Lastly, we further leverage the distance to guide test case mutation, which efficiently drives directed fuzzing toward candidate vulnerable code. We have implemented a prototype of Labrador and evaluated it on 14 different enterprise-level IoT devices. Results showed that Labrador significantly outperforms state-of-the-art (SOTA) solutions. It finds 44X more vulnerabilities than SNIPUZZ, BOOFUZZ and FIRM-AFL and 8.57X more vulnerabilities than SaTC. In total, it discovered 79 unknown vulnerabilities, of which 61 were assigned with CVEs.
Hangtian Liu, Shuitao Gan, Chao Zhang 0008, Zicong Gao, Xiangzhi Wang, Guangming Gao
SP7
2024 LLMUZZ: LLM-based seed optimization for black-box device fuzzing
abstract
As an increasing number of Internet of Things (IoT) devices are being deployed, the threat from vulnerabilities inside these devices is growing. Fuzzing is a primary method used for discovering vulnerabilities in IoT devices. The quality of the initial seeds and the seed mutation strategy are two crucial components of fuzzing that largely determine the effectiveness of the fuzzing process. However, owing to the diversity of IoT devices and the highly structured nature of inputs, designing universal seed generation and mutation strategies is extremely challenging. In this paper, we propose LLMUZZ, which is a large language model (LLM)-based black-box fuzzing approach for IoT devices. Specifically, we employ prompt engineering techniques in few-shot learning, using HTML form data from frontend files and an example HTTP request as inputs to LLMs to generate initial seeds. Then, we input the requests to be mutated into LLMs to identify the fields requiring mutation, thereby assisting in the seed mutation process. This approach ensures that the mutated seeds remain valid. Additionally, static analysis methods are utilized to discover hidden keywords within the firmware, thereby further expanding the initial seeds. In the experiments, we implement a prototype of LLMUZZ and evaluate it on 8 different IoT devices. A total of 16 previously unknown vulnerabilities are found, for which we have received 4 CVEs; the remaining vulnerabilities still under review, demonstrating that LLMUZZ has a strong capacity for vulnerability discovery.
Guangming Gao, Shuitao Gan, Shengkai Zhu
TrustCom1