Fuzzing Embedded (Trusted) Operating Systems Using AFL | Martijn Bogaard | nullcon Goa 2019

57:41 · 01 Mar 2019 – 02 Mar 2019 · YouTube

About this talk

This talk covers the increasing role of Trusted Execution Environments (TEEs) in the security of embedded systems, highlighting the complexity and risks associated with vulnerabilities as more security-critical tasks are moved to TEEs. The speaker presents a fuzzing framework inspired by syzkaller, designed for OP-TEE, utilizing an unmodified version of AFL with integrated coverage tracking in the TEE kernel through compile-time injected hooks. This framework can effectively test kernel code, trusted applications, and system call interfaces by providing coverage data to the non-secure world. The discussion also addresses the challenges of fuzzing non-virtualized trusted operating systems on actual devices and details the innovative methods used to create initial input sets for AFL. The strategies outlined are applicable beyond OP-TEE, making them relevant for any trusted operating system. Martijn Bogaard, a Senior Security Analyst at Riscure, presents his insights based on extensive experience in analyzing low-level embedded software security.

From event

nullcon Goa 2019

01 Mar 2019 – 02 Mar 2019

All event videos
Back to Watch