Abstract
Recent attacks on modern processors have demonstrated the severe consequences of discovering and exploiting hardware vulnerabilities. Simultaneously, the increasing complexity of modern chip designs and the ever-limited testing time presents numerous challenges to existing pre-silicon hardware-design verification tools.
Fuzzing is increasingly the technique of choice for discovering software vulnerabilities, but the same cannot be said about fuzzing for hardware designs vulnerabilities. Due to the data-flow nature of how hardware is designed, existing software fuzzing solutions cannot be readily applied in the hardware context, and the performance of the proposed hardware fuzzing solutions suffers from state explosion when applied on complex hardware designs.
In this work, we present BugsBunny, a feedback-guided directed hardware-design fuzzer which aims to reduce the costs of pre-silicon validation. BugsBunny focusses the testing resources only on the relevant parts of the design-under-test (DUT), by fuzzing towards a certain target state of the DUT and eliminating irrelevant parts of the design. We propose a novel distance-to-target feedback metric, capable of directing and guiding the fuzzer towards the desired target state, which is based on lightweight data-flow analysis and instrumentation of the DUT. By running the DUT on an FPGA, BugsBunny achieves high fuzzing throughput, outperforming existing simulation-based solutions.
We perform an end-to-end evaluation of BugsBunny on complex SoC designs (e.g., the RISC-V BOOM), where preliminary experiments demonstrate a significant reduction in the number of fuzzing seeds that are required before the DUT reaches the target state.
Fuzzing is increasingly the technique of choice for discovering software vulnerabilities, but the same cannot be said about fuzzing for hardware designs vulnerabilities. Due to the data-flow nature of how hardware is designed, existing software fuzzing solutions cannot be readily applied in the hardware context, and the performance of the proposed hardware fuzzing solutions suffers from state explosion when applied on complex hardware designs.
In this work, we present BugsBunny, a feedback-guided directed hardware-design fuzzer which aims to reduce the costs of pre-silicon validation. BugsBunny focusses the testing resources only on the relevant parts of the design-under-test (DUT), by fuzzing towards a certain target state of the DUT and eliminating irrelevant parts of the design. We propose a novel distance-to-target feedback metric, capable of directing and guiding the fuzzer towards the desired target state, which is based on lightweight data-flow analysis and instrumentation of the DUT. By running the DUT on an FPGA, BugsBunny achieves high fuzzing throughput, outperforming existing simulation-based solutions.
We perform an end-to-end evaluation of BugsBunny on complex SoC designs (e.g., the RISC-V BOOM), where preliminary experiments demonstrate a significant reduction in the number of fuzzing seeds that are required before the DUT reaches the target state.
| Original language | English |
|---|---|
| Title of host publication | Fourth Workshop on the Security of Software/Hardware Interfaces |
| Publisher | SILM |
| Pages | 1-7 |
| Number of pages | 7 |
| Publication status | Published - 2022 |
Fingerprint
Dive into the research topics of 'BugsBunny: Hopping to RTL Targets with a Directed Hardware-Design Fuzzer'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver