跳到主要导航 跳到搜索 跳到主要内容

RVFuzzer: Finding input validation bugs in robotic vehicles through control-guided testing

  • Taegyu Kim
  • , Chung Hwan Kim
  • , Junghwan Rhee
  • , Fan Fei
  • , Zhan Tu
  • , Gregory Walkup
  • , Xiangyu Zhang
  • , Xinyan Deng
  • , Dongyan Xu
  • Purdue University
  • NEC Corporation

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Robotic vehicles (RVs) are being adopted in a variety of application domains. Despite their increasing deployment, many security issues with RVs have emerged, limiting their wider deployment. In this paper, we address a new type of vulnerability in RV control programs, called input validation bugs, which involve missing or incorrect validation checks on control parameter inputs. Such bugs can be exploited to cause physical disruptions to RVs which may result in mission failures and vehicle damages or crashes. Furthermore, attacks exploiting such bugs have a very small footprint: just one innocent-looking ground control command, requiring no code injection, control flow hijacking or sensor spoofing. To prevent such attacks, we propose RVFUZZER, a vetting system for finding input validation bugs in RV control programs through control-guided input mutation. The key insight behind RVFUZZER is that the RV control model, which is the generic theoretical model for a broad range of RVs, provides helpful semantic guidance to improve bug-discovery accuracy and efficiency. Specifically, RVFUZZER involves a control instability detector that detects control program misbehavior, by observing (simulated) physical operations of the RV based on the control model. In addition, RVFUZZER steers the input generation for finding input validation bugs more efficiently, by leveraging results from the control instability detector as feedback. In our evaluation of RVFUZZER on two popular RV control programs, a total of 89 input validation bugs are found, with 87 of them being zero-day bugs.

源语言英语
主期刊名Proceedings of the 28th USENIX Security Symposium
出版商USENIX Association
425-442
页数18
ISBN(电子版)9781939133069
出版状态已出版 - 2019
已对外发布
活动28th USENIX Security Symposium, USENIX Security 2019 - Santa Clara, 美国
期限: 14 8月 201916 8月 2019

出版系列

姓名Proceedings of the 28th USENIX Security Symposium

会议

会议28th USENIX Security Symposium, USENIX Security 2019
国家/地区美国
Santa Clara
时期14/08/1916/08/19

学术指纹

探究 'RVFuzzer: Finding input validation bugs in robotic vehicles through control-guided testing' 的科研主题。它们共同构成独一无二的学术指纹。

引用此