Search NASA⌕ Search

SEARCH · Search NASA

Results for “Fuzzing”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

The dependence of tungsten fuzz layer thickness and porosity on tungsten deposition rate and helium ion fluence

Abstract Fuzz formation on a heated tungsten surface in the presence of a helium-containing plasma and tungsten deposition source was investigated. Tungsten samples were exposed at 1123 K to pure helium plasma with ion incident energy of 76 eV, W/He ion flux ratio of ∼ 0.4 × 10 − 4 , and varied helium ion fluence from 0.18 to 3.4 × 10 26 m −2 . Fuzz thickness was measured by cross-sectional scanning electron microscopy to increase from 0.22 to 15 µ m with increasing helium ion fluence. No indication of saturation in fuzz thickness at high fluence was observed, in contrast to fuzz produced on a tungsten surface without tungsten deposition. Additional tungsten samples were exposed at 1123 K to pure helium plasma with ion incident energy of 76 eV, helium ion fluence of ∼ 3.4 × 10 26 m −2 , and varied W/He ion flux ratio from 0.26 to 3.0 × 10 − 4 . Fuzz thickness increased from 7.5 to 120 µ m with increasing W/He ion ratio. A final sample exposed at 1123 K to a mixed helium-deuterium plasma with ion incident energy of 76 eV, helium ion fluence of 0.18 × 10 26 m −2 , and W/He ion flux ratio of 2.2 × 10 − 4 developed nearly identical fuzz structures to that developed in a pure He plasma. As a function of deposited tungsten fluence, all results were found to trace out a single layer-growth curve given by a power law relation, indicating that fuzz thickness is independent of the W/He ion flux ratio in the range investigated and independent of any deuterium present in the plasma. As a result, for tungsten plasma facing walls in magnetic fusion devices at 1000–2000 K with 10 −4 W/He ion flux ratio, fuzz with thicknesses greater than hundreds of microns may form in as little as 10 4 s (in the absence of ELM-induced erosion or annealing), and may more significantly affect its thermophysical properties than fuzz generated without a tungsten deposition source.

Physics↗

Speeding-up fuzzing through directional seeds

Abstract Fuzzing is an automated process for discovering inputs in a program that may trigger unexpected behavior. Today, fuzzing has become a standard practice for the discovery of bugs and security vulnerabilities. However, the main issue with such practices is that the exploration of the input space of programs can often be prohibitively expensive. Therefore, several alternative fuzzing strategies have been introduced during the last few years. Some fuzzing techniques rely on human expertise to provide a plausible set of initial input examples, namely, seeds. However, the process of handcrafting seeds for fuzzing purposes often becomes strenuous for humans as it requires a deeper understanding of the Program-Under-Test (PUT). Also, the use of known inputs to programs often does not trigger vulnerable program behavior or may not reach potentially vulnerable code locations. To address those issues, we propose a seed generation framework that enables Human-In-The-Loop (HITL) directed fuzzing where the human assumes a more active role in the creation of seeds that can penetrate and assess desired locations of the PUT. Our proposed framework uses Symbolic Execution (SE) to generate seeds that exercise paths to target program locations. Moreover, our framework enables the visualization of the explored execution paths in the binary of the PUT for the generated seeds. We evaluated our approach on a set of 12 carefully designed C programs with diverse characteristics that mimic real-world programs. The experimental results show the effectiveness of the proposed approach in improving the performance of standard fuzzing tools such as the American Fuzzy Lop ("Image missing" <#comment/> ). Specifically, our solution can generate seeds that substantially enhance the performance of the fuzzer, achieving speedups ranging from $$1.46\times $$ 1.46 × to $$68.53\times $$ 68.53 × for branch conditions, $$1.39\times $$ 1.39 × to $$254.62\times $$ 254.62 × for branch depths, $$14,879.59\times $$ 14 , 879.59 × to $$30,295.88\times $$ 30 , 295.88 × for branch widths over traditional seeds. Additionally, the speedup increases with the number of target function ranging from $$12,260\times $$ 12 , 260 × to $$22,856.07\times $$ 22 , 856.07 × over traditional seeds while only requiring less than 15 seconds on average for the seed generation step.

97 MATHEMATICS AND COMPUTING↗

StructuredFuzzer: Fuzzing Structured Text-Based Control Logic Applications

Rigorous testing methods are essential for ensuring the security and reliability of industrial controller software. Fuzzing, a technique that automatically discovers software bugs, has also proven effective in finding software vulnerabilities. Unsurprisingly, fuzzing has been applied to a wide range of platforms, including programmable logic controllers (PLCs). However, current approaches, such as coverage-guided evolutionary fuzzing implemented in the popular fuzzer American Fuzzy Lop Plus Plus (AFL++), are often inadequate for finding logical errors and bugs in PLC control logic applications. They primarily target generic programming languages like C/C++, Java, and Python, and do not consider the unique characteristics and behaviors of PLCs, which are often programmed using specialized programming languages like Structured Text (ST). Furthermore, these fuzzers are ill suited to deal with complex input structures encapsulated in ST, as they are not specifically designed to generate appropriate input sequences. This renders the application of traditional fuzzing techniques less efficient on these platforms. To address this issue, this paper presents a fuzzing framework designed explicitly for PLC software to discover logic bugs in applications written in ST specified by the IEC 61131-3 standard. The proposed framework incorporates a custom-tailored PLC runtime and a fuzzer designed for the purpose. We demonstrate its effectiveness by fuzzing a collection of ST programs that were crafted for evaluation purposes. We compare the performance against a popular fuzzer, namely, AFL++. The proposed fuzzing framework demonstrated its capabilities in our experiments, successfully detecting logic bugs in the tested PLC control logic applications written in ST. On average, it was at least 83 times faster than AFL++, and in certain cases, for example, it was more than 23,000 times faster.

47 OTHER INSTRUMENTATION↗

IoT Firmware Emulation and Its Security Application in Fuzzing: A Critical Revisit

As IoT devices with microcontroller (MCU)-based firmware become more common in our lives, memory corruption vulnerabilities in their firmware are increasingly targeted by adversaries. Fuzzing is a powerful method for detecting these vulnerabilities, but it poses unique challenges when applied to IoT devices. Direct fuzzing on these devices is inefficient, and recent efforts have shifted towards creating emulation environments for dynamic firmware testing. However, unlike traditional software, firmware interactions with peripherals that are significantly more diverse presents new challenges for achieving scalable full-system emulation and effective fuzzing. This paper reviews 27 state-of-the-art works in MCU-based firmware emulation and its applications in fuzzing. Instead of classifying existing techniques based on their capabilities and features, we first identify the fundamental challenges faced by firmware emulation and fuzzing. We then revisit recent studies, organizing them according to the specific challenges they address, and discussing how each specific challenge is addressed. We compare the emulation fidelity and bug detection capabilities of various techniques to clearly demonstrate their strengths and weaknesses, aiding users in selecting or combining tools to meet their needs. Finally, we highlight the remaining technical gaps and point out important future research directions in firmware emulation and fuzzing.

Zhou, Wei (ORCID:0000000178340839)↗

Hardware Fuzzing with An Emulator

Bugs in digital logic have led to some significant security vulnerabilities. Hardware bugs are particularly troublesome since they cannot be easily patched. Additionally, if the bug is in the root of trust, all trust built upon it can be vulnerable. Traditional testing either require a deep knowledge of the system, creative attack vectors and lots of human interaction. This is not scalable as there are very few engineers that can wear the hat of a designer, a verification engineer, and a cybersecurity expert. Hardware fuzzing is a relatively new research area in dynamic hardware testing. It has proven to be an effective method for discovering bugs, unexpected behaviors, and security vulnerabilities in software. While hardware fuzzing is new to the hardware domain, it has a strong track record in software testing. Fuzzing is a testing technique that randomly mutates the input data to uncover bugs or vulnerabilities in the design. It is especially good at finding corner cases that test engineers can not envision. Another advantage over other dynamic testing techniques is that, if done well, deep knowledge of the design is not required. Additionally, fuzzing scales well. If the system is set up correctly, it can run unsupervised for weeks if necessary. In this work, we propose using hardware fuzzing to improve the input vector generation for an information flow tracking tool. To get reasonable throughput of test vectors, an emulator is targeted as the execution platform. Efficient emulator execution has some specific requirements.

42 ENGINEERING↗

CROWBAR: Natively Fuzzing Trusted Applications Using ARM CoreSight

Abstract Trusted execution environments (TEE) are deployed on many platforms to provide both confidentiality and integrity, and their extensive use offers a secure environment for privacy-sensitive operations. Despite TEE prevalence in the smartphone and tablet market, vulnerability research into TEE security is relatively rare. This is, in part, due to the strong isolation guarantees provided by its implementation. In this paper, we propose a hardware assisted fuzzing framework, CROWBAR, that bypasses TEE isolation to natively evaluate trusted applications (TAs) on mobile devices by leveraging ARM CoreSight components. CROWBAR performs feedback-driven fuzzing on commercial, closed source TAs while running in a TEE protected environment. We implement CROWBAR on 2 prototype commercial-off-the-shelf (COTS) smartphones and one development board, finding 3 unique crashes in 5 closed source TAs that are previously unreported in the TrustZone fuzzing literature.

Shan, Haoqi↗

Spectroscopy of the fuzz associated with four quasars

The spectral features detected in the fuzz of four probable quasars spanning the z range of 0.036-0.37 are reported; the objects studied are 0351 + 026 (z = 0.036), 1059 + 730 (z = 0.089), 0845 + 378 (z = 0.307), and 3C 48 (z = 0.368). The results indicate that apparently some (and probably all) low-redshift quasars are embedded in fuzz whose size, morphology, absolute magnitude, and spectroscopic character are those of a galaxy. Thus, it appears virtually certain that quasars are the active nuclei of galaxies.

Balick, B.↗

An Integrated Testbed for Trojans in Printed Circuit Boards with Fuzzing Capabilities

This paper showcases an all-in-one testing environment that combines Trojan detection and fuzzing capabilities for printed circuit boards using the OpenPLC “NYU Trojan Edition” and a dedicated Trojan detection framework. The demo system is self-contained and equipped with two OpenPLC-based boards (one with a Trojan and one without), and automated tools for inserting the Trojan and collecting side-channel data. We developed a graphical user interface for interactive Trojan selection, data visualization, and anomaly detection analysis.

Trojan detection, anomaly detection, PCB, timing l↗

Retention and surface morphology evaluation of fine-grain dispersion-strengthened tungsten for plasma-facing component applications

This study exposed novel fine-grain dispersion-strengthened tungsten (W) to high fluence, low energy deuterium (D) and helium (He) plasmas to evaluate how material microstructure and composition affect hydrogen retention and surface morphology. Tested materials included fine-grain dispersion-strengthened tungsten (DSW) with 3 wt% zirconium carbide (ZrC) dispersoids, fine-grain dense W without any dispersoids (FGW), and coarse-grained polycrystalline ‘ITER-grade’ W. Samples were exposed to D 2 + and He + plasmas at fusion-relevant fluences (∼10 25 m -2 ) and ion energies (75 eV) over a range of temperatures (200 °C, 300 °C, 450 °C for D, 850 °C for He). Helium ion microscopy was performed on the exposed samples to evaluate surface morphology changes and material integrity. After D plasma exposure, the ZrC dispersoids showed near-surface degradation at exposure temperatures above 300 °C, but no detrimental morphology changes were observed for the adjacent W grains. After He plasma-exposure, nano-structured fuzz formation was observed in the tungsten matrix of all samples. The ZrC dispersoids maintained their integrity despite the surrounding fuzz growth, with clear delineation between the W fuzz and dispersoid regions. Thermal desorption spectroscopy showed that ZrC DSW consistently retained more D than the FGW by about a factor of 2 across all temperatures. At 200 °C and 300 °C, the ITER-W displayed lower D retention than both the DSW and FGW, however at 450 °C ITER-W showed the highest retention, about 50% more than DSW. He retention was comparable across all samples, with the highest retention observed in the fine-grain W, only 26% higher than in ITER-W. These insights on retention behavior will inform further optimization of these novel fine-grained tungsten materials with and without dispersoid additives.

Dispersion-strengthened tungsten↗

Helium plasma operations on ASDEX Upgrade and JET in support of the non-nuclear phases of ITER

For its initial operational phase, ITER has until recently considered using non-nuclear hydrogen (H) or helium (He) plasmas to keep nuclear activation at low levels. To this end, the Tokamak Exploitation Task Force of the EUROfusion Consortium carried out dedicated experimental campaigns in He on the ASDEX Upgrade (AUG) and JET tokamaks in 2022, with particular emphasis put on the ELMy H-mode operation and plasma-wall interaction processes as well as comparison to H or deuterium (D) plasmas. Both in pure He and mixed He + H plasmas, H-mode operation could be reached but more effort was needed to obtain a stable plasma scenario than in H or D. Even if the power threshold for the LH transition was lower in He, entering the type-I ELMy regime appeared to require equally much or even more heating power than in H. Suppression of ELMs by resonant magnetic perturbations was studied on AUG but was only possible in plasmas with a He content below 19%; the reason for this unexpected behaviour remains still unclear and various theoretical approaches are being pursued to properly understand the physics behind ELM suppression. The erosion rates of tungsten (W) plasma-facing components were an order of magnitude larger than what has been reported in hydrogenic plasmas, which can be attributed to the prominent role of He 2+ ions in the plasma. For the first time, the formation of nanoscale structures (W fuzz) was unambiguously demonstrated in H-mode He plasmas on AUG. However, no direct evidence of fuzz creation on JET was obtained despite the main conditions for its occurrence being met. The reason could be a delicate balance between W erosion by ELMs, competition between the growth and annealing of the fuzz, and coverage of the surface with co-deposits.

70 PLASMA PHYSICS AND FUSION TECHNOLOGY↗

Interfaces enhanced plasma irradiation resistance in CrMoTaWV/W multilayer films through blocking He diffusion

The performance of plasma-facing materials (PFMs) is one of the key factors that significantly impact the stability of operation in fusion reactors. Herein, a new CrMoTaWV/W (high entropy alloy (HEA)/W) multilayer structure is designed as PFM to investigate its resistance to He plasma irradiation. It was observed that the introduction of the interfaces effectively absorbed plenty of He atoms, preventing them from diffusing into the material and delaying the formation of fuzz incubation zone, therefore, enhancing the resistance to plasma irradiation. The thickness transformed to fuzz in the HEA/W multilayer films was observed to be about two-thirds of those in the CrMoTaWV (HEA) film. Additionally, the fuzz growth rates in HEA/W multilayer films are lower than the average growth rate of bulk W and HEA films combined. These findings highlight a promising new avenue for the exploration of high-performance PFMs.

70 PLASMA PHYSICS AND FUSION TECHNOLOGY↗

Further morphological studies of QSOs

Results are presented of optical mapping of 29 QSOs, together with results of VLA observations of 16 of the optically observed objects. Principal results are that QSOs to z = 0.45 have extended nebulosity, the average ratio of nuclear to fuzz luminosity, corrected for resolution, is about 0.5, some 8 times higher than Seyfert I values, the average fuzz luminosity is -21.5, fainter than giant ellipticals, and fuzz morphology does not resemble E or S galaxies, but is very similar to Seyfert I's to similar luminosity limits. In some cases, indications of spiral structure are seen, and a large fraction of asymmetrical morphology is noted. In the QSO 0241 + 622, steep spectrum radio emission is found displaced from the central source exactly along the minor optical axis.

Hutchings, J. B.↗

Enhanced resistance to helium irradiations through unusual interaction between high-entropy-alloy and helium

Finding high performance plasma-facing materials (PFMs) is one of the most important and challenging tasks for realizing the commercial application of fusion reactors. Herein, we found the CrMoTaWV high entropy alloy (HEA) is highly resistant to low-energy and high-flux He plasma exposure. The nanochannel HEA film has 20 times higher initial fluence for the formation of fuzz and a remarkable 8.9 times slower fuzz growth rate than those of W. Combining the in-situ TEM observation and the Molecular dynamics (MD) simulation of the He bubble growth process, a new mechanism for the enhanced radiation resistance in HEA with the unusual interaction between HEA and He is found, where, differing from traditional metal, bubble growth in HEA leads to non-directional emission of interstitial atoms while HEA greatly suppress the growth of He bubbles. Additionally, the special nanochannel structure further rise the radiation resistance through releasing He out of the HEA film and reducing the He concentration. This new nanochannel refractory HEA material presents a promising choice as the PFMs with excellent performance and a much longer serving lifetime for future commercial fusion reactors.

36 MATERIALS SCIENCE↗