Firmware Fuzzy Test System Oriented to New Generation Firmware Interface Standard

Jia-min MA,Li PAN,Jie-wen YAO
DOI: https://doi.org/10.3969/j.issn.1000-3428.2014.07.057
2014-01-01
Abstract:With the increase of code vulnerabilities in Unified Extensible Firmware Interface(UEFI) firmware and the lack of effective vulnerability detection systems, this paper develops a fuzzy test system for UEFI firmware. It applies fuzzy test technique to UEFI firmware vulnerability detection. The system reuses test framework of Self Certification Test(SCT) system, generates test data through a special subsystem to ensure the quality and provides APIs for creating test cases. Also, the vulnerability detection capability of the system is revealed through real security vulnerability in UEFI firmware. Experimental results show that, test cases can be written more easily but with 15%higher code coverage than the SCT system based on this system, which ensures the ability to detect deep, high risk security vulnerabilities.
What problem does this paper attempt to address?