today-0day
NotionGithubSiteContact
Korean
Korean
  • Introduction
    • ๐ŸšฉWindows Driver 0-day Research
    • ๐Ÿซ‚Team. ์šฐ๋ฆฌ ์˜ค๋Š˜๋ถ€ํ„ฐ 0-day
  • backgrounds
    • Windows Driver
    • Related Works
  • Our Approach
    • ๊ฐœ์š”
    • ๐Ÿ‡Init Analyzer
    • ๐Ÿ˜กangr-PT
    • ๐ŸฅŒMS Fuzzer
      • Playmaker mode
      • Qemu-nyx
      • Redqueen
      • Multiple Driver Tracing
      • Call Stack Parser
    • How to Use
  • Appendix
    • References
    • Achievments
    • ๐Ÿ”—Team page
    • ๐Ÿ”—CODE BLUE 2024
Powered by GitBook
On this page
  1. Our Approach
  2. MS Fuzzer

Qemu-nyx

PreviousPlaymaker modeNextRedqueen

Last updated 2 months ago

์œ„์™€ ๊ฐ™์€ Play maker mode๋ฅผ ์œ„ํ•ด์„œ๋Š” Fuzzing Campaign๊ณผ์ •์ด ๊ฐ๊ฐ ๋…๋ฆฝ์‹คํ–‰์ด ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

๋˜ํ•œ Kernel Fuzzing์— ์žˆ์–ด์„œ ๋‹ค๋ฅธ ๋ฌธ์ œ์ ์€ ๋ณ‘ํ–‰์„ฑ์— ๋Œ€ํ•ด์„œ ๊ณ ๋ ค๊ฐ€ ์–ด๋ ต๋‹ค๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.

์ด๋Ÿฐ ๋ฌธ์ œ๋“ค์„ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•ด Nyx: Greybox Hypervisor Fuzzing using Fast Snapshots and Affine Types ( Usenix Security 2021 )์— ์†Œ๊ฐœ๋œ Nyx-Qemu๋ฅผ ํ™œ์šฉํ•˜์—ฌ ๊ฐ ์‹คํ–‰์˜ ๋…๋ฆฝ์„ฑ์„ ํ•ด๊ฒฐํ•ด์ฃผ์—ˆ์Šต๋‹ˆ๋‹ค.

Qemu-nyx๋Š” ๋งค ์‹คํ–‰๋งˆ๋‹ค RAM, Disk, vCPU๋ฅผ ์ดˆ๊ธฐ ์Šค๋ƒ…์ƒท ์ƒํƒœ๋กœ ๋˜๋Œ๋ฆฝ๋‹ˆ๋‹ค.

RAM, Disk, vCPU๋Š” Dirty Page Logging์„ ํ†ตํ•ด Dirty๋œ ๋ถ€๋ถ„๋งŒ ๋ถ€๋ถ„์ ์œผ๋กœ ๋ณต๊ตฌํ•˜์—ฌ ๋น ๋ฅธ ์†๋„๋กœ ๋ณต๊ตฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๐ŸฅŒ