Repository logo

Infoscience

  • English
  • French
Log In
Logo EPFL, École polytechnique fédérale de Lausanne

Infoscience

  • English
  • French
Log In
  1. Home
  2. Academic and Research Output
  3. Conferences, Workshops, Symposiums, and Seminars
  4. Truman: Constructing Device Behavior Models from OS Drivers to Fuzz Virtual Devices
 
conference paper

Truman: Constructing Device Behavior Models from OS Drivers to Fuzz Virtual Devices

Ma, Zhao
•
Liu, Qiang
•
Li, Zheming
Show more
2025
Proceedings 2025 Network and Distributed System Security Symposium
Network and Distributed System Security Symposium 2025

Virtual devices are a large attack surface of hypervisors. Vulnerabilities in virtual devices may enable attackers to jailbreak hypervisors or even endanger co-located virtual machines. While fuzzing has discovered vulnerabilities in virtual devices across both open-source and closed-source hypervisors, the efficiency of these virtual device fuzzers remains limited because they are unaware of the complex behaviors of virtual devices in general. We present Truman, a novel universal fuzzing engine that automatically infers dependencies from open-source OS drivers to construct device behavior models (DBMs) for virtual device fuzzing, regardless of whether target virtual devices are open-source or binaries. The DBM includes inter- and intra-message dependencies and fine-grained state dependency of virtual device messages. Based on the DBM, Truman generates and mutates quality seeds that satisfy the dependencies encoded in the DBM. We evaluate the prototype of Truman on the latest version of hypervisors. In terms of coverage, Truman outperformed start-of-the-art fuzzers for 19/29 QEMU devices and obtained a relative coverage boost of 34% compared to Morphuzz for virtio devices. Additionally, Truman discovered 54 new bugs in QEMU, VirtualBox, VMware Workstation Pro, and Parallels, with 6 CVEs assigned.

  • Details
  • Metrics
Type
conference paper
DOI
10.14722/ndss.2025.240301
Author(s)
Ma, Zhao
Liu, Qiang
Li, Zheming
Yin, Tingting
Tan, Wende
Zhang, Chao
Payer, Mathias  

École Polytechnique Fédérale de Lausanne

Date Issued

2025

Publisher

Internet Society

Publisher place

Reston, VA

Published in
Proceedings 2025 Network and Distributed System Security Symposium
URL

Video

https://youtu.be/i6V2DaEGv9k

Slides

https://www.ndss-symposium.org/wp-content/uploads/5A-f0301-Zheyu.pdf
Editorial or Peer reviewed

REVIEWED

Written at

EPFL

EPFL units
HEXHIVE  
Event nameEvent acronymEvent placeEvent date
Network and Distributed System Security Symposium 2025

NDSS 2025

San Diego, CA, USA

2025-02-24 - 2025-02-28

Available on Infoscience
January 9, 2026
Use this identifier to reference this record
https://infoscience.epfl.ch/handle/20.500.14299/257746
Logo EPFL, École polytechnique fédérale de Lausanne
  • Contact
  • infoscience@epfl.ch

  • Follow us on Facebook
  • Follow us on Instagram
  • Follow us on LinkedIn
  • Follow us on X
  • Follow us on Youtube
AccessibilityLegal noticePrivacy policyCookie settingsEnd User AgreementGet helpFeedback

Infoscience is a service managed and provided by the Library and IT Services of EPFL. © EPFL, tous droits réservés