{"id":{"repo_id":"vt","oai_identifier":"oai:vtechworks.lib.vt.edu:10919/138146"},"canonical_url":"https://search.dev.ndltd.org/etd/vt/oai:vtechworks.lib.vt.edu:10919/138146","repository":{"repo_id":"vt","name":"Virginia Tech","base_url":"https://vtechworks.lib.vt.edu/oai/request"},"display":{"title":"EKFuzz: Fuzzing the BPF subsystem","abstract":"The extended Berkeley Packet Filter (eBPF) framework has revolutionized the way developers interact with the Linux kernel by enabling safe, dynamic programmability. However, this flexibility comes at a cost. The new kernel functions (kfuncs) exposed to eBPF programs are rapidly proliferating, often without adequate testing. While prior work has addressed verifier and helper function fuzzing, the kfuncs remain a largely unexplored attack surface. This thesis presents EKFuzz, a Syzkaller-based fuzzing extension that systematically targets kfuncs used by eBPF programs. EKFuzz incorporates type-aware generation of verifier-compliant programs, automatically generates dependent syscalls (e.g., for maps), and employs a mutation-driven feedback loop. Our evaluation demonstrates that EKFuzz achieves deeper runtime coverage than Syzkaller and uncovers latent bugs within the kfunc execution paths.","abstract_html":"The extended Berkeley Packet Filter (eBPF) framework has revolutionized the way developers interact with the Linux kernel by enabling safe, dynamic programmability. However, this flexibility comes at a cost. The new kernel functions (kfuncs) exposed to eBPF programs are rapidly proliferating, often without adequate testing. While prior work has addressed verifier and helper function fuzzing, the kfuncs remain a largely unexplored attack surface. This thesis presents EKFuzz, a Syzkaller-based fuzzing extension that systematically targets kfuncs used by eBPF programs. EKFuzz incorporates type-aware generation of verifier-compliant programs, automatically generates dependent syscalls (e.g., for maps), and employs a mutation-driven feedback loop. Our evaluation demonstrates that EKFuzz achieves deeper runtime coverage than Syzkaller and uncovers latent bugs within the kfunc execution paths.","abstract_has_math":false,"creators":["Puranam, Ananta Srikar"],"institution":"Virginia Tech","degree_name":"Master of Science","degree_level":"masters","degree_discipline":"Computer Engineering","degree_department":"Electrical and Computer Engineering","school":null,"contributors":[],"advisors":[],"committee_chairs":["Ravindran, Binoy"],"committee_members":["Wang, Haining","Giles, Kendall Everett"],"year":2025,"date_issued":"2025-08-15","date_published":"2025-08-15","updated_at":"2026-07-22T22:18:55Z","subjects":["Linux","Fuzzing","eBPF","syzkaller","EKFuzz"],"languages":["en"],"rights":["CC0 1.0 Universal"],"rights_urls":["http://creativecommons.org/publicdomain/zero/1.0/"],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/10919/138146","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.committeechair","label":"Committee Chair","values":["Ravindran, Binoy"]},{"key":"dc:contributor.committeemember","label":"Committee Member","values":["Wang, Haining","Giles, Kendall Everett"]},{"key":"dc:contributor.department","label":"Department","values":["Electrical and Computer Engineering"]},{"key":"dc:creator","label":"Author","values":["Puranam, Ananta Srikar"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2025-10-13T13:36:15Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2025-10-13T13:36:15Z"]},{"key":"dc:date.issued","label":"Date","values":["2025-08-15"]},{"key":"dc:publisher","label":"Institution","values":["Virginia Tech"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"dc:type.dcmitype","label":"Dc Type Dcmitype","values":["Text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Engineering"]},{"key":"thesis:degree_level","label":"Degree Level","values":["masters"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Science"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["Virginia Polytechnic Institute and State University"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Linux","Fuzzing","eBPF","syzkaller","EKFuzz"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["CC0 1.0 Universal"]},{"key":"dc:rights.uri","label":"Rights URI","values":["http://creativecommons.org/publicdomain/zero/1.0/"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/10919/138146"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["The extended Berkeley Packet Filter (eBPF) framework has revolutionized the way developers interact with the Linux kernel by enabling safe, dynamic programmability. However, this flexibility comes at a cost. The new kernel functions (kfuncs) exposed to eBPF programs are rapidly proliferating, often without adequate testing. While prior work has addressed verifier and helper function fuzzing, the kfuncs remain a largely unexplored attack surface. This thesis presents EKFuzz, a Syzkaller-based fuzzing extension that systematically targets kfuncs used by eBPF programs. EKFuzz incorporates type-aware generation of verifier-compliant programs, automatically generates dependent syscalls (e.g., for maps), and employs a mutation-driven feedback loop. Our evaluation demonstrates that EKFuzz achieves deeper runtime coverage than Syzkaller and uncovers latent bugs within the kfunc execution paths."]},{"key":"dc:description.abstractgeneral","label":"General Abstract","values":["Modern operating systems must balance safety and performance. Linux introduced eBPF to safely run custom programs inside the kernel-making tools for networking, monitoring, and security more efficient. To help eBPF programs interact with the kernel, developers expose internal kernel functions (called kfuncs). However, these functions are growing rapidly in number and are often not thoroughly tested. This thesis presents a testing tool, EKFuzz, which can automatically try many different inputs and combinations to catch potential problems in these functions. EKFuzz builds on an existing testing tool called Syzkaller and improves it to better handle this new type of kernel interaction. The result is a safer, more robust Linux system."]},{"key":"dc:description.degree","label":"Dc Description Degree","values":["Master of Science"]},{"key":"dc:format.medium","label":"Dc Format Medium","values":["ETD"]},{"key":"dc:format.mimetype","label":"Dc Format Mimetype","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["EKFuzz: Fuzzing the BPF subsystem"]}]}],"canonical_facts":{"dc:contributor.committeechair":["Ravindran, Binoy"],"dc:contributor.committeemember":["Wang, Haining","Giles, Kendall Everett"],"dc:contributor.department":["Electrical and Computer Engineering"],"dc:creator":["Puranam, Ananta Srikar"],"dc:date.accessioned":["2025-10-13T13:36:15Z"],"dc:date.available":["2025-10-13T13:36:15Z"],"dc:date.issued":["2025-08-15"],"dc:description.abstract":["The extended Berkeley Packet Filter (eBPF) framework has revolutionized the way developers interact with the Linux kernel by enabling safe, dynamic programmability. However, this flexibility comes at a cost. The new kernel functions (kfuncs) exposed to eBPF programs are rapidly proliferating, often without adequate testing. While prior work has addressed verifier and helper function fuzzing, the kfuncs remain a largely unexplored attack surface. This thesis presents EKFuzz, a Syzkaller-based fuzzing extension that systematically targets kfuncs used by eBPF programs. EKFuzz incorporates type-aware generation of verifier-compliant programs, automatically generates dependent syscalls (e.g., for maps), and employs a mutation-driven feedback loop. Our evaluation demonstrates that EKFuzz achieves deeper runtime coverage than Syzkaller and uncovers latent bugs within the kfunc execution paths."],"dc:description.abstractgeneral":["Modern operating systems must balance safety and performance. Linux introduced eBPF to safely run custom programs inside the kernel-making tools for networking, monitoring, and security more efficient. To help eBPF programs interact with the kernel, developers expose internal kernel functions (called kfuncs). However, these functions are growing rapidly in number and are often not thoroughly tested. This thesis presents a testing tool, EKFuzz, which can automatically try many different inputs and combinations to catch potential problems in these functions. EKFuzz builds on an existing testing tool called Syzkaller and improves it to better handle this new type of kernel interaction. The result is a safer, more robust Linux system."],"dc:description.degree":["Master of Science"],"dc:format.medium":["ETD"],"dc:format.mimetype":["application/pdf"],"dc:identifier.uri":["https://hdl.handle.net/10919/138146"],"dc:language.iso":["en"],"dc:publisher":["Virginia Tech"],"dc:rights":["CC0 1.0 Universal"],"dc:rights.uri":["http://creativecommons.org/publicdomain/zero/1.0/"],"dc:subject":["Linux","Fuzzing","eBPF","syzkaller","EKFuzz"],"dc:title":["EKFuzz: Fuzzing the BPF subsystem"],"dc:type":["Thesis"],"dc:type.dcmitype":["Text"],"thesis:degree_discipline":["Computer Engineering"],"thesis:degree_level":["masters"],"thesis:degree_name":["Master of Science"],"thesis:institution_name":["Virginia Polytechnic Institute and State University"]},"updated_at":"2026-07-22T22:18:55Z"}