GreenAFL is a modified version of AFLPlusPlus that integrates energy measurement into program execution. It allows users to measure energy consumption of target programs, either directly or during fuzzing with AFL.
Overview of GreenAFL’s energy-guided fuzzing loop The green boxes with bold text highlight where our energy-aware heuristics are applied, B, energy-aware score computation) and D, airtime scheduling).}
- Project Structure
- Dependencies
- Build Instructions
- Using the Preload Library
- Testing
- AFLPlusPlus Integration
- Cleaning the Build
- Notes on Modifications
.
├── AFLPlusPlus # Local AFLPlusPlus clone/build
├── data
├── Makefile
├── README.md
├── scripts
└── src
├── oss-fuzz
├── preload
│ └── energy_preload.cpp # Preload library to measure energy
└── tests
└── hello.cpp # Example test programAFLPlusPlus/: Directory for the AFL++ fuzzer. This project includes a customized AFLPlusPlus build.src/preload/: Contains energy_preload.cpp, the preload library measuring energy usage.src/tests/: Example test programs that can be compiled and run with the preload library.build/: Build artifacts will be generated here, including the compiled preload library and test binaries.
In order to fuzz with AFL++ you must set the power governor to performance:
cd /sys/devices/system/cpu
echo performance | sudo tee cpu*/cpufreq/scaling_governorGCC/G++newer than 11.0MakeCPPJoules(linked in the preload library)perf(for performance monitoring)CMake(for building jsoncpp)
To install CPPJoules follow instructions here, or use the following commands on Ubuntu:
curl https://raw.githubusercontent.com/rishalab/CPPJoules/main/installer.sh | bash
source ~/.bashrcTo install perf on Ubuntu:
sudo apt-get install linux-tools-common linux-tools-generic linux-tools-`uname -r`And in order to use perf without root you must set the following kernel parameter:
echo "kernel.perf_event_paranoid=-1" | sudo tee -a /etc/sysctl.conf
sudo sysctl -pYou need CMake (>=3.24) which can be installed via Kitware's APT repository:
sudo apt-get update
sudo apt-get install -y apt-transport-https ca-certificates gnupg wget
wget -O - https://apt.kitware.com/keys/kitware-archive-latest.asc | sudo apt-key add -
sudo apt-add-repository "deb https://apt.kitware.com/ubuntu/ $(lsb_release -cs) main"
sudo apt-get update
sudo apt-get install -y cmake
cmake --versionGreenAFL uses a Makefile to build both the preload library and test binaries. Please make sure CPPJoules is installed before build.
makeThis will:
- Build the energy measurement preload library (
build/energy.so). - Clone and build a AFLPlusPlus instance in
AFLplusplus/ - Build a local AFLPlusPlus instance in
AFLPlusPlus/.
make preloadmake preload_aflAdds -DAFL_ENERGY_MAPPING to the build, enabling energy tracking in AFL fuzzing runs.
make preload_printAdds -DAFL_FORCE_PRINT to the build, enabling output of energy measurements, even when within AFL (required for cmin)
make preload_print_aflEnables both AFL energy tracking and forced printing.
The preload library can be used in two modes:
LD_PRELOAD=/path/to/build/energy.so ./build/tests/helloThis runs the program with energy measurement.
AFL_PRELOAD=/path/to/build/energy.so afl-prog ...This injects the energy measurement library into programs being fuzzed.
Test file hello.cpp in src/tests/ will be build with make hello
Example:
./build/tests/hello.cppand.ctest sources are supported.- Build artifacts are placed in build/tests/.
GreenAFL comes with a local copy of AFLPlusPlus, which is built automatically:
make aflThis builds AFL in the AFLPlusPlus/llvm_mode and AFLPlusPlus/qemu_mode directories depending on the chosen build options.
Remove all compiled artifacts:
make clean- Deletes the
build/directory entirely. - Does not affect AFLPlusPlus or source files.
GreenAFL modifies AFLPlusPlus to integrate with the energy measurement preload library. Key features:
- Seed Minimisation with energy tracking.
- Edits to
AFLPlusPlus/afl-cmin.pyto support energy measurement during minimisation. - Requires
-DAFL_FORCE_PRINTto ensure energy data is output during minimisation.
- Edits to
- Fuzzing with energy tracking.
- Edits to
AFLPlusPlus/include/afl-fuzz.hto add maps for child process to write to, and to store energy data in each fuzzing iteration. - Edits to
AFLPlusPlus/src/afl-fuzz-init.cto initialise the new maps, and set the env variable for the preload library. - Edits to
AFLPlusPlus/src/afl-fuzz-run.cto read energy data from the maps after each execution, and store it in the fuzzing queue entry. - Edits to
AFLPlusPlus/src/afl-fuzz-queue.cto modify the heuristics of a fuzzing entry to include energy data. - Requires
-DAFL_ENERGY_MAPPINGto enable energy tracking during fuzzing.
- Edits to