Search NASASearch

SEARCH · Search NASA

Results for “fuzzing”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Speeding-up fuzzing through directional seeds

Abstract Fuzzing is an automated process for discovering inputs in a program that may trigger unexpected behavior. Today, fuzzing has become a standard practice for the discovery of bugs and security vulnerabilities. However, the main issue with such practices is that the exploration of the input space of programs can often be prohibitively expensive. Therefore, several alternative fuzzing strategies have been introduced during the last few years. Some fuzzing techniques rely on human expertise to provide a plausible set of initial input examples, namely, seeds. However, the process of handcrafting seeds for fuzzing purposes often becomes strenuous for humans as it requires a deeper understanding of the Program-Under-Test (PUT). Also, the use of known inputs to programs often does not trigger vulnerable program behavior or may not reach potentially vulnerable code locations. To address those issues, we propose a seed generation framework that enables Human-In-The-Loop (HITL) directed fuzzing where the human assumes a more active role in the creation of seeds that can penetrate and assess desired locations of the PUT. Our proposed framework uses Symbolic Execution (SE) to generate seeds that exercise paths to target program locations. Moreover, our framework enables the visualization of the explored execution paths in the binary of the PUT for the generated seeds. We evaluated our approach on a set of 12 carefully designed C programs with diverse characteristics that mimic real-world programs. The experimental results show the effectiveness of the proposed approach in improving the performance of standard fuzzing tools such as the American Fuzzy Lop ("Image missing" <#comment/> ). Specifically, our solution can generate seeds that substantially enhance the performance of the fuzzer, achieving speedups ranging from $$1.46\times $$ 1.46 × to $$68.53\times $$ 68.53 × for branch conditions, $$1.39\times $$ 1.39 × to $$254.62\times $$ 254.62 × for branch depths, $$14,879.59\times $$ 14 , 879.59 × to $$30,295.88\times $$ 30 , 295.88 × for branch widths over traditional seeds. Additionally, the speedup increases with the number of target function ranging from $$12,260\times $$ 12 , 260 × to $$22,856.07\times $$ 22 , 856.07 × over traditional seeds while only requiring less than 15 seconds on average for the seed generation step.

97 MATHEMATICS AND COMPUTING

StructuredFuzzer: Fuzzing Structured Text-Based Control Logic Applications

Rigorous testing methods are essential for ensuring the security and reliability of industrial controller software. Fuzzing, a technique that automatically discovers software bugs, has also proven effective in finding software vulnerabilities. Unsurprisingly, fuzzing has been applied to a wide range of platforms, including programmable logic controllers (PLCs). However, current approaches, such as coverage-guided evolutionary fuzzing implemented in the popular fuzzer American Fuzzy Lop Plus Plus (AFL++), are often inadequate for finding logical errors and bugs in PLC control logic applications. They primarily target generic programming languages like C/C++, Java, and Python, and do not consider the unique characteristics and behaviors of PLCs, which are often programmed using specialized programming languages like Structured Text (ST). Furthermore, these fuzzers are ill suited to deal with complex input structures encapsulated in ST, as they are not specifically designed to generate appropriate input sequences. This renders the application of traditional fuzzing techniques less efficient on these platforms. To address this issue, this paper presents a fuzzing framework designed explicitly for PLC software to discover logic bugs in applications written in ST specified by the IEC 61131-3 standard. The proposed framework incorporates a custom-tailored PLC runtime and a fuzzer designed for the purpose. We demonstrate its effectiveness by fuzzing a collection of ST programs that were crafted for evaluation purposes. We compare the performance against a popular fuzzer, namely, AFL++. The proposed fuzzing framework demonstrated its capabilities in our experiments, successfully detecting logic bugs in the tested PLC control logic applications written in ST. On average, it was at least 83 times faster than AFL++, and in certain cases, for example, it was more than 23,000 times faster.

47 OTHER INSTRUMENTATION

IoT Firmware Emulation and Its Security Application in Fuzzing: A Critical Revisit

As IoT devices with microcontroller (MCU)-based firmware become more common in our lives, memory corruption vulnerabilities in their firmware are increasingly targeted by adversaries. Fuzzing is a powerful method for detecting these vulnerabilities, but it poses unique challenges when applied to IoT devices. Direct fuzzing on these devices is inefficient, and recent efforts have shifted towards creating emulation environments for dynamic firmware testing. However, unlike traditional software, firmware interactions with peripherals that are significantly more diverse presents new challenges for achieving scalable full-system emulation and effective fuzzing. This paper reviews 27 state-of-the-art works in MCU-based firmware emulation and its applications in fuzzing. Instead of classifying existing techniques based on their capabilities and features, we first identify the fundamental challenges faced by firmware emulation and fuzzing. We then revisit recent studies, organizing them according to the specific challenges they address, and discussing how each specific challenge is addressed. We compare the emulation fidelity and bug detection capabilities of various techniques to clearly demonstrate their strengths and weaknesses, aiding users in selecting or combining tools to meet their needs. Finally, we highlight the remaining technical gaps and point out important future research directions in firmware emulation and fuzzing.

Zhou, Wei (ORCID:0000000178340839)

Hardware Fuzzing with An Emulator

Bugs in digital logic have led to some significant security vulnerabilities. Hardware bugs are particularly troublesome since they cannot be easily patched. Additionally, if the bug is in the root of trust, all trust built upon it can be vulnerable. Traditional testing either require a deep knowledge of the system, creative attack vectors and lots of human interaction. This is not scalable as there are very few engineers that can wear the hat of a designer, a verification engineer, and a cybersecurity expert. Hardware fuzzing is a relatively new research area in dynamic hardware testing. It has proven to be an effective method for discovering bugs, unexpected behaviors, and security vulnerabilities in software. While hardware fuzzing is new to the hardware domain, it has a strong track record in software testing. Fuzzing is a testing technique that randomly mutates the input data to uncover bugs or vulnerabilities in the design. It is especially good at finding corner cases that test engineers can not envision. Another advantage over other dynamic testing techniques is that, if done well, deep knowledge of the design is not required. Additionally, fuzzing scales well. If the system is set up correctly, it can run unsupervised for weeks if necessary. In this work, we propose using hardware fuzzing to improve the input vector generation for an information flow tracking tool. To get reasonable throughput of test vectors, an emulator is targeted as the execution platform. Efficient emulator execution has some specific requirements.

42 ENGINEERING

Retention and surface morphology evaluation of fine-grain dispersion-strengthened tungsten for plasma-facing component applications

This study exposed novel fine-grain dispersion-strengthened tungsten (W) to high fluence, low energy deuterium (D) and helium (He) plasmas to evaluate how material microstructure and composition affect hydrogen retention and surface morphology. Tested materials included fine-grain dispersion-strengthened tungsten (DSW) with 3 wt% zirconium carbide (ZrC) dispersoids, fine-grain dense W without any dispersoids (FGW), and coarse-grained polycrystalline ‘ITER-grade’ W. Samples were exposed to D 2 + and He + plasmas at fusion-relevant fluences (∼10 25 m -2 ) and ion energies (75 eV) over a range of temperatures (200 °C, 300 °C, 450 °C for D, 850 °C for He). Helium ion microscopy was performed on the exposed samples to evaluate surface morphology changes and material integrity. After D plasma exposure, the ZrC dispersoids showed near-surface degradation at exposure temperatures above 300 °C, but no detrimental morphology changes were observed for the adjacent W grains. After He plasma-exposure, nano-structured fuzz formation was observed in the tungsten matrix of all samples. The ZrC dispersoids maintained their integrity despite the surrounding fuzz growth, with clear delineation between the W fuzz and dispersoid regions. Thermal desorption spectroscopy showed that ZrC DSW consistently retained more D than the FGW by about a factor of 2 across all temperatures. At 200 °C and 300 °C, the ITER-W displayed lower D retention than both the DSW and FGW, however at 450 °C ITER-W showed the highest retention, about 50% more than DSW. He retention was comparable across all samples, with the highest retention observed in the fine-grain W, only 26% higher than in ITER-W. These insights on retention behavior will inform further optimization of these novel fine-grained tungsten materials with and without dispersoid additives.

Dispersion-strengthened tungsten

Helium plasma operations on ASDEX Upgrade and JET in support of the non-nuclear phases of ITER

For its initial operational phase, ITER has until recently considered using non-nuclear hydrogen (H) or helium (He) plasmas to keep nuclear activation at low levels. To this end, the Tokamak Exploitation Task Force of the EUROfusion Consortium carried out dedicated experimental campaigns in He on the ASDEX Upgrade (AUG) and JET tokamaks in 2022, with particular emphasis put on the ELMy H-mode operation and plasma-wall interaction processes as well as comparison to H or deuterium (D) plasmas. Both in pure He and mixed He + H plasmas, H-mode operation could be reached but more effort was needed to obtain a stable plasma scenario than in H or D. Even if the power threshold for the LH transition was lower in He, entering the type-I ELMy regime appeared to require equally much or even more heating power than in H. Suppression of ELMs by resonant magnetic perturbations was studied on AUG but was only possible in plasmas with a He content below 19%; the reason for this unexpected behaviour remains still unclear and various theoretical approaches are being pursued to properly understand the physics behind ELM suppression. The erosion rates of tungsten (W) plasma-facing components were an order of magnitude larger than what has been reported in hydrogenic plasmas, which can be attributed to the prominent role of He 2+ ions in the plasma. For the first time, the formation of nanoscale structures (W fuzz) was unambiguously demonstrated in H-mode He plasmas on AUG. However, no direct evidence of fuzz creation on JET was obtained despite the main conditions for its occurrence being met. The reason could be a delicate balance between W erosion by ELMs, competition between the growth and annealing of the fuzz, and coverage of the surface with co-deposits.

70 PLASMA PHYSICS AND FUSION TECHNOLOGY

Interfaces enhanced plasma irradiation resistance in CrMoTaWV/W multilayer films through blocking He diffusion

The performance of plasma-facing materials (PFMs) is one of the key factors that significantly impact the stability of operation in fusion reactors. Herein, a new CrMoTaWV/W (high entropy alloy (HEA)/W) multilayer structure is designed as PFM to investigate its resistance to He plasma irradiation. It was observed that the introduction of the interfaces effectively absorbed plenty of He atoms, preventing them from diffusing into the material and delaying the formation of fuzz incubation zone, therefore, enhancing the resistance to plasma irradiation. The thickness transformed to fuzz in the HEA/W multilayer films was observed to be about two-thirds of those in the CrMoTaWV (HEA) film. Additionally, the fuzz growth rates in HEA/W multilayer films are lower than the average growth rate of bulk W and HEA films combined. These findings highlight a promising new avenue for the exploration of high-performance PFMs.

70 PLASMA PHYSICS AND FUSION TECHNOLOGY

Accelerating plasma and radiation surface science using transient grating spectroscopy

A facility for the investigation of in situ radiation-materials and plasma-materials interaction is demonstrated with tungsten, using transient grating spectroscopy as a probe of thermal diffusivity and surface acoustic wave speed. Helium plasma exposure at 645 °C to 1.18 × 10 18 cm −2 helium, until the growth of tungsten fuzz, showed an increase in surface acoustic wave speed at the near-surface from 2542 ± 1 m s −1 up to 2565 ± 1 m s −1 , followed by a greater drop to 2499 ± 7 m s −1 . No observable change in thermal diffusivity was present for plasma exposure alone. A separate 10.26 MeV self-ion-irradiation of tungsten to a dose of 7.92 dpa showed a reduction in both thermal diffusivity from 61.4 ± 1.4 mm 2 s −1 to 36.0 ± 0.7 mm 2 s −1 , following trends seen in existing studies, and surface acoustic wave speed from 2647.8 ± 0.6 m s −1 to 2640.0 ± 0.4 m s −1 . Facilities like these are poised to rapidly close critical knowledge gaps regarding the coupled effects of plasma and radiation damage for materials in fusion systems.

Accelerated plasmas

Secondary electron emission for reticulated carbon foam surfaces using direct measurements and spectroscopic analysis

This study investigates secondary electron emission (SEE) characteristics of reticulated foams using direct measurements and analytical modeling. Total SEE was quantified, revealing suppression of up to 44% in carbon foam structures compared to planar graphite surfaces. An optimal geometric configuration was identified and supported by analytical models. SEE angular dependence experiments showed diverse behaviors: fiber-like behavior and directional dependence for pore and ligaments on the mm scale, with fuzz-like characteristics when the foam features are between 10–100 µm. Electron energy analyzer measurements showed that carbon foams preferentially suppress inelastic backscattered electrons (BSEs) more so than true secondary electrons (SEs). The analysis indicated a larger fraction of low-energy SE generation in foams compared to flat surfaces due to increased emission from curved fiber ligaments and tertiary SEs from high-energy BSEs. These findings have implications for design and optimization of materials with tailored electron emission properties for applications like plasma-facing components, spacecraft materials, and accelerator surfaces.

Auger

Enhancing Automotive Intrusion Detection Through Multi-Modal Fusion: A CAN FD-LiDAR Approach

As vehicles become smarter and more autonomous, they increasingly depend on advanced sensors and communication technologies to operate securely. However, such growing dependence on technology—whether it’s CAN (Controller Area Network) for internal communication or LiDAR (Light Detection and Ranging) for sensing the world around them—also expands the attack surface for the types of cyber attacks. Traditional intrusion detection systems (IDS) typically monitor these systems in isolation, limiting their ability to detect sophisticated, crosssystem attacks. To address this, we propose a multi-modal fusion approach that combines real-world CAN FD signals (from the HCRL dataset) with LiDAR features (from the nuScenes dataset) to enhance attack detection. Our method employs a twostage ensemble approach. Calibrated XGBoost and LightGBM models initially process CAN FD (Fuzzing Data) and LiDAR data independently, detecting timing anomalies and space abnormalities. They are subsequently logarithmically combined with a logistic regression meta-model along with 17 engineered features capturing cross-modal behavior, prediction conflicts, and nonlinear interactions. This approach achieves an AUC of 0.87 and an F1-score of 0.82, surpassing single-modality baselines and early fusion methods, at merely 2 ms inference latency. Compared with deep learning competitors, it is 3 times more efficient, providing a lightweight, interpretable, and real time solution to automotive cybersecurity.

97 MATHEMATICS AND COMPUTING