Real-Time Operating Systems (RTOS) are widely used in embedded systems to support functionalities such as Bluetooth and Wi-Fi. As RTOS kernels grow in functionality, their attack surface also expands, increasing the need for effective security testing. However, existing dynamic testing techniques such as fuzzing have difficulty effectively testing deeply located kernel functions because these functions require complex execution contexts.
This tutorial presents RTCon, a context-adaptive function-level fuzzer for RTOS kernels. The tutorial uses Zephyr, an open-source RTOS for embedded and IoT devices that has been adopted as the embedded controller platform for ChromeOS devices, as the target system. Participants will learn the principles of function-level fuzzing, execution context construction for kernel functions, and practical techniques for testing RTOS kernels.
Biographies
-
Eunkyu Lee received the B.S. and M.S. degrees in electrical engineering from KAIST, Daejeon, South Korea, in 2017 and 2019, respectively. He is currently pursuing the Ph.D. degree in electrical engineering at KAIST. From 2019 to 2023, he served as a Security Researcher at the Ministry of National Defense of the Republic of Korea. His recent research interests include large language model (LLM) agents, real-time operating systems (RTOS), and reverse engineering for ARM and x86_64 architectures. His earlier work focused on mobile network security, particularly vulnerability discovery in LTE downlink protocols and modem implementations, as well as dynamic protocol testing using software-defined radios.
-
Insu Yun is an associate professor at KAIST, currently leading Hacking Lab. He is interested in system security in general, especially, binary analysis, automatic vulnerability detection, and automatic exploit generation. His work has been published to the major computer conferences such as IEEE Security & Privacy, USENIX Security, and USENIX OSDI. Particularly, his research won the best paper award from USENIX Security and OSDI in 2018, and he also won DARPA AIxCC with Team Atlanta.
In addition to research, he has been participating in several hacking competitions as a hacking expert. In particular, he won Pwn2Own 2020 by compromising Apple Safari and won DEFCON CTF in 2015 and 2018, which is the world hacking competition. Prior to joining KAIST, he received his Ph.D. degree in Computer Science from Georgia Tech in 2020.
Mon 18 MayDisplayed time zone: Seoul change
11:00 - 12:30 | |||
11:00 90mTutorial | Function-Level Fuzzing for RTOS Kernels with RTCon Tutorials | ||