Efficient fuzz testing of low-level virtual devices
Abstract
Examples described herein include systems and methods for fuzz testing low-level virtual devices and virtual devices with DMA write functionality. A fuzz tester includes components distributed across a virtual machine and its host system. The fuzz testing components in the virtual machine are implemented as firmware installed in the virtual machine's ROM. These components operate independent of data stored in the virtual machine's RAM and do not require an operating system to be installed on the virtual machine. As a result, any changes made to the virtual machine's RAM during the fuzzing process by low-level virtual devices or virtual devices with DMA write functionality cannot interrupt the fuzz testing or otherwise negatively impact the fuzz tester itself.
Claims
exact text as granted — not AI-modified1 .- 20 . (canceled)
21 . A method for fuzz testing virtual devices, the method including:
receiving, at a virtual machine hosted by a host system, a first operation to be performed against one or more virtual devices, the first operation populated with one or more parameters; executing, by a fuzzer module located at the virtual machine, the first operation against the one or more virtual devices using the populated parameters, the fuzzer module configured as firmware on the virtual machine operating independent of the virtual machine's random access memory (RAM); and sending a request, by the fuzzer module, to a hypervisor for a second operation to be performed against the one or more virtual devices, wherein an operation table is embedded in the fuzzer module, the operation table including a plurality of operations available to execute against the one or more virtual devices.
22 . The method of claim 21 , wherein the populated parameters are generated by a random or pseudorandom input generator.
23 . The method of claim 22 , wherein the random or pseudorandom input generator is a pseudorandom input generator.
24 . The method of claim 21 , further including, after execution of the first operation by the fuzzer module:
transmitting, from the virtual machine to the hypervisor, in-use space associated with the one or more virtual devices to obtain updated state information associated with the one or more virtual devices.
25 . The method of claim 24 , further including:
determining, at the hypervisor, the second operation based at least in part on the updated state information.
26 . The method of claim 21 , further including, before determining the first operation:
transmitting, from the virtual machine to the hypervisor, a copy of the operation table embedded in the fuzzer module.
27 . The method of claim 26 , wherein determining the first operation is based at least in part on the copy of the operation table.
28 . A non-transitory, computer-readable medium including instructions that, when executed by a processor, performs stages for fuzz testing virtual devices, the stages including:
initializing fuzzer firmware in a virtual machine that operates independent of the virtual machine's random access memory (RAM); receiving, at the virtual machine, an operation to be performed against one or more virtual devices, the first operation populated with one or more parameters; executing, by the fuzzer firmware, the operation against the one or more virtual devices using the populated parameters; and transmitting a request, by the fuzzer firmware, to a hypervisor for another operation to be performed against the one or more virtual devices, wherein an operation table is embedded in the fuzzer firmware, the operation table including a plurality of operations available to execute against the one or more virtual devices.
29 . The non-transitory, computer-readable medium of claim 28 , wherein the populated parameters are generated by a random or pseudorandom input generator.
30 . The non-transitory, computer-readable medium of claim 28 , further including, after executing the operation by the fuzzer firmware:
transmitting, from the virtual machine to the hypervisor, in-use space associated with the one or more virtual devices to obtain updated state information associated with the one or more virtual devices.
31 . The non-transitory, computer-readable medium of claim 30 , further including:
determining, at the hypervisor, the another operation based at least in part on the updated state information.
32 . The non-transitory, computer-readable medium of claim 28 , wherein the fuzzer firmware is implemented in the virtual machine's ROM.
33 . The non-transitory, computer-readable medium of claim 32 , wherein no operating system is installed on the virtual machine.
34 . (canceled)
34 . The non-transitory, computer-readable medium of claim 28 , wherein the operation received from the hypervisor by the fuzzer firmware is one of the available operations included in the operation table.
35 . A host system for fuzz testing virtual devices, the system including:
a memory storage including a non-transitory, computer-readable medium including instructions; and a computing device including a processor that executes the instructions to carry out stages including:
receiving, at a virtual machine hosted by a host system, a first operation to be performed against one or more virtual devices, the first operation populated with one or more parameters;
executing, by a fuzzer module located at the virtual machine, the first operation against the one or more virtual devices using the populated parameters, the fuzzer module configured as firmware on the virtual machine operating independent of the virtual machine's random access memory (RAM); and
sending a request, by the fuzzer module, to a hypervisor for a second operation to be performed against the one or more virtual devices,
wherein an operation table is embedded in the fuzzer module, the operation table including a plurality of operations available to execute against the one or more virtual devices.
36 . The system of claim 35 , wherein the populated parameters are generated by a random or pseudorandom input generator.
37 . The system of claim 35 , wherein the random or pseudorandom input generator includes a file containing random data for populating portions of the first operation.
38 . The system of claim 35 , wherein no operating system is installed on the virtual machine.
39 . The system of claim 35 , wherein the first operation is a read or write I/O operation.
40 . The system of claim 35 , further including transmitting, from the virtual machine to the hypervisor, a copy of the operation table embedded in the fuzzer module.Join the waitlist — get patent alerts
Track US2023128809A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.