Fuzzing Embedded (Trusted) Operating Systems Using AFL | Martijn Bogaard | nullcon Goa 2019
About this talk
This talk covers the increasing role of Trusted Execution Environments (TEEs) in the security of embedded systems, highlighting the complexity and risks associated with vulnerabilities as more security-critical tasks are moved to TEEs. The speaker presents a fuzzing framework inspired by syzkaller, designed for OP-TEE, utilizing an unmodified version of AFL with integrated coverage tracking in the TEE kernel through compile-time injected hooks. This framework can effectively test kernel code, trusted applications, and system call interfaces by providing coverage data to the non-secure world. The discussion also addresses the challenges of fuzzing non-virtualized trusted operating systems on actual devices and details the innovative methods used to create initial input sets for AFL. The strategies outlined are applicable beyond OP-TEE, making them relevant for any trusted operating system. Martijn Bogaard, a Senior Security Analyst at Riscure, presents his insights based on extensive experience in analyzing low-level embedded software security.
More from this event
See all 40 talks →
Interview with Robert Baptiste aka Elliot Alderson [@fs0c131y] by Antriksh Shah | nullcon Goa 2019
25:01
Getting to $10,000 – the variables at play in determining bounty awards by Jarek Stanley
20:08
A Hacker Walks Into A Co-Working Space | Rahul Binjve (@c0dist) | nullcon Goa 2019
33:10
Andromeda- GUI based Dynamic Instrumentation Toolkit powered by Frida | Shivang Desai | nullcon 2019
21:08