PeriScope: An Effective Probing and Fuzzing Framework for the Hardware-OS Boundary

Опубликовано: 11 Октябрь 2024
на канале: Black Hat
487
11

In this talk, I will present PeriScope, a Linux-kernel-based in-kernel probing framework that enables fine-grained analysis of device-driver interactions. PeriScope hooks into the kernel's page fault handling mechanism to either passively monitor and log traffic between device drivers and their corresponding hardware, or mutate the data stream on-the-fly using a fuzzing component, PeriFuzz, thus mimicking an active adversarial attack.

By Dokyung Song

Full Abstract & Presentation Materials: https://www.blackhat.com/us-19/briefi...