Methodology for fuzzing Linux kernel system calls using large language models

DOI: 10.21293/1818-0442-2024-27-3-85-91

Download article in PDF format

JATS xml

Abstract: A pressing issue in organizing Linux kernel fuzzing testing is creating system call specifications – special declarative descriptions that are subsequently used by a fuzzer to generate system call sequences. This is mostly manual work that requires deep knowledge, takes a lot of time, and does not exclude the error factor. Research is currently underway to automate the process of creating such specifications. The paper considers approaches to generate system call specifications KSG, SyzDescribe, and KernelGPT that have proven themselves in detecting unique kernel crashes during fuzz testing. A methodology to organize Linux kernel fuzzing testing is proposed, that includes a stage of automatic generation of system call specifications based on large language models (Large Language Model – LLM).

Keywords: operating system, Linux kernel, fuzzing, Syzkaller, system call specification, LLM

Funding: This study was supported by the Ministry of Digital Development, Communications and Mass Media of the Russian Federation (IB grant). Project No. 26/23-K.

For citation:
Teplyuk P. A., Yakunin A. G. Methodology for fuzzing Linux kernel system calls using large language models. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki, 2024, vol. 27, no. 3, pp. 85–91. DOI: 10.21293/1818-0442-2024-27-3-85-91

Authors and copyright holders:

  • Teplyuk P. A. , Polzunov Altai State Technical University (Barnaul, Russia)
  • Yakunin A. G. , Polzunov Altai State Technical University (Barnaul, Russia)

  • 1. Khoroshilov A. [International Linux Kernel Development Project]. Sistemnyj Administrator, 2022, no. 3 (232), pp. 32–37 (in Russ.).
  • 2. Informacionnoe soobshchenie FSTEK Rossii ot 10 fevralya 2021 g. [Information message from FSTEC of Russia dated February 10, 2021] (in Russ.). Available at: https://fstec.ru/dokumenty/vse-dokumenty/informatsionnye-ianaliticheskie-materialy/informationnoe-soobshchenie-fstekrossii-ot-10-fevralya-2021-g-n-240-24-647, free (Accessed: August 28, 2023).
  • 3. Teplyuk P.A., Yakunin A.G. Models and approaches to attack surface analysis for fuzz testing of the Linux kernel. It Security (Russia), 2024, vol. 31, no. 1, pp. 135–145. DOI: 10.26583/bit.2024.1.08.
  • 4. Teplyuk P.A., Yakunin A.G. Identifying security flaws in the Linux Kernel using system call fuzzing. Information Security Problems. Computer Systems, 2024, no. 2 (59), pp. 138–151. DOI: 10.48612/jisp/pdp9-d25r-g6eu.
  • 5. Syzkaller – kernel fuzzer. Available at: https://github.com/google/syzkaller, free (Accessed: September 7, 2024).
  • 6. Syscall description language. Available at: https://github.com/google/syzkaller/blob/master/docs/syscall_descriptions_syntax.md, free (Accessed: September 07, 2024).
  • 7. MIDI system calls specifications. Available at: https://github.com/google/syzkaller/blob/master/sys/linux/dev_snd_midi.txt, free (Accessed: September 07, 2024).
  • 8. Sun H., Shen Y., Liu J., Xu Y., Jiang Y. KSG: Augmenting Kernel Fuzzing with System Call Specification Generation. Proceedingsof the 2022 USENIX Annual Technical Conference (USENIX ATC 22), 2022, pp. 351–365.
  • 9. Hao Y., Li G., Zou X., Chen W., Zhi S., Qian Z., Sani A. SyzDescribe: Principled, Automated, Static Generation of Syscall Descriptions for Kernel Drivers. Proceedings of 2023 IEEE Symposium on Security and Privacy (SP), 2023, pp. 3262–3278. DOI: 10.1109/SP46215.2023.10179298.
  • 10. Yang C., Zhao Z., Zhang L. KernelGPT: Enhanced Kernel Fuzzing via Large Language Models. arXiv:2401.00563 [cs.CR], 2023, 13 p. DOI: 10.48550/arXiv.2401.00563.
  • 11. Patsakis C., Casino F., Lykousas N. Assessing LLMs in malicious code deobfuscation of real-world malware campaigns. Expert Systems with Applications, 2024, vol. 256, 13 p. DOI: 10.1016/j.eswa.2024.124912.
  • 12. Ye J., Fei X., de Carne de Carnavalet X., Zhao L. Detecting command injection vulnerabilities in Linux-based embedded firmware with LLM-based taint analysis of library functions. Computers & Security, 2024, vol. 144. DOI: 10.1016/j.cose.2024.103971.
  • 13. Lu G., Ju X., Chen X., Pei W., Cai Z. GRACE: Empowering LLM-based software vulnerability detection with graph structure and in-context learning. Journal of Systems and Software, 2024, vol. 212. DOI: 10.1016/j.jss.2024.112031.
  • 14. Sufi F. An innovative GPT-based open-source intelligence using historical cyber incident reports. Natural Language Processing Journal, 2024, vol. 7, 17 p. DOI: 10.1016/j.nlp.2024.100074.
  • 15. GPT4 / OpenAI. Available at: https://openai.com/index/gpt-4/, free (Accessed: September 09, 2024).
  • 16. Bavendiek S. Attack surface analysis of the Linux kernel based on complexity metrics. Master’s Thesis in the study course «Applied Informatics / Software Engineering», 2021, 88 p. DOI: 10.13140/RG.2.2.29943.70561.
  • 17. Dovgalyuk P.M., Klimushenkova M.A., Fursova N.I., Stepanov V.M., Vasiliev I.A., Ivanov A.A., Ivanov A.V., Bakulin M.G., Egorov D.I. [Natch: using virtual machine introspection and taint analysis for detection attack surface of the software]. Trudy ISP RAN [Proceedings of ISP RAS], 2022, vol. 34, no. 5, pp. 89–110 (in Russ.).
  • 18. Tomilov I.O., Karmanov I.N., Zvyagintseva P.A., Gritskevich E.V. Development of fuzzing application technique for software vulnerabilities analysis. Systems of Control, Communication and Security, 2018, no. 4, pp. 48–63.
Editorial office address

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 701-582

  journal@tusur.ru

 

Viktor N. Maslennikov

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 51-21-21 / 51-43-02

Subscription for updates