Loading…
Vault 2016 has ended
Thursday, April 21 • 10:30am - 11:20am
Filesystem Fuzzing with American Fuzzy Lop (AFL) - Vegard Nossum & Quentin Casasnovas, Oracle

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

American Fuzzy Lop (AFL) is an open source fuzzing framework that relies on code instrumentation of a target program to find inputs that will cause the program to take new (and hopefully interesting) code paths. We have applied AFL to a range of Linux filesystem drivers and have quickly found a multitude of new bugs not found with regular ("dumb") fuzzers. Additionally, the testcases found by AFL can be used as a regression test suite that will help increase the confidence that any future change to the filesystem driver does not accidentally introduce bugs.

Through our presentation we share our techniques and tools directly with filesystem developers and make filesystem fuzzing with AFL more accessible to a wider audience. In this way, bugs can be found (and fixed) faster by the people who already know the filesystem code intimately.

Speakers
QC

Quentin Casasnovas

Senior SW engineer, Oracle
Quentin graduated from EPITA, a french engineering school, in 2010.He's started working as an embedded engineer for MathEmbedded, a Britishstart-up, then as a freelancer for Intel.  He's now working for Oracle inthe Ksplice tight knit team where he prepares Ksplice updates and try... Read More →
VN

Vegard Nossum

Senior Developer, Oracle
Vegard graduated from the University of Oslo in 2012 with a thesis on the topic of SAT solving and has been working for Oracle on Ksplice kernel updates and infrastructure ever since. His experience with the Linux kernel includes writing kmemcheck, a tool for detecting use of uninitialized... Read More →


Thursday April 21, 2016 10:30am - 11:20am PDT
State Ballroom B