BEGIN:VCALENDAR
VERSION:2.0
PRODID:Linklings LLC
BEGIN:VTIMEZONE
TZID:America/Chicago
X-LIC-LOCATION:America/Chicago
BEGIN:DAYLIGHT
TZOFFSETFROM:-0600
TZOFFSETTO:-0500
TZNAME:CDT
DTSTART:19700308T020000
RRULE:FREQ=YEARLY;BYMONTH=3;BYDAY=2SU
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0500
TZOFFSETTO:-0600
TZNAME:CST
DTSTART:19701101T020000
RRULE:FREQ=YEARLY;BYMONTH=11;BYDAY=1SU
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTAMP:20230124T171522Z
LOCATION:C141-143-149
DTSTART;TZID=America/Chicago:20221118T094100
DTEND;TZID=America/Chicago:20221118T101100
UID:submissions.supercomputing.org_SC22_sess447_ws_shpc101@linklings.com
SUMMARY:Improving HPC Security with Targeted Syscall Fuzzing
DESCRIPTION:Workshop\n\nImproving HPC Security with Targeted Syscall Fuzzi
 ng\n\nWeaver\n\nAll modern computer systems, including supercomputers, are
  vulnerable to a wide variety of security exploits. Performance analysis t
 ools are an often overlooked source of vulnerabilities. Performance measur
 ement interfaces can have security issues that lead to information leakage
 , denial of service attacks, and possibly even full system compromise. Des
 ktop systems can mitigate risk by disabling performance interfaces, but th
 at is not always possible on HPC systems where performance (and thus measu
 rement) is paramount. We investigate various ways of finding security issu
 es in the performance measurement stack. We introduce the perf_fuzzer, a t
 ool that methodically finds bugs in the Linux perf_event_open() system cal
 l. We also discuss the perf data fuzzer which looks for userspace bugs in 
 the perf analysis tool. We describe the development of the fuzzing tools, 
 examine the bugs found, and discuss ways to prevent such bugs from occurri
 ng in the future.\n\nSession Format: Recorded\n\nTag: Security\n\nRegistra
 tion Category: Workshop Reg Pass
END:VEVENT
END:VCALENDAR
