Metal-fuzz

A Hardware-in-the-Loop Fuzzing Framework for Hypervisors in Mixed-Criticality Space Applications

Master Thesis (2026)
Author(s)

D. Peter (TU Delft - Electrical Engineering, Mathematics and Computer Science)

Contributor(s)

G. Smaragdakis – Mentor (TU Delft - Electrical Engineering, Mathematics and Computer Science)

A. Voulimeneas – Mentor (TU Delft - Electrical Engineering, Mathematics and Computer Science)

S.S. Chakraborty – Graduation committee member (TU Delft - Electrical Engineering, Mathematics and Computer Science)

A. Atlasis – Mentor (European Space Agency (ESA))

Faculty
Electrical Engineering, Mathematics and Computer Science
More Info
expand_more
Publication Year
2026
Language
English
Graduation Date
29-06-2026
Awarding Institution
Delft University of Technology
Programme
Computer Science
Sponsors
European Space Agency (ESA)
Faculty
Electrical Engineering, Mathematics and Computer Science
Page Views
61
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

Securing modern satellites is increasingly challenging as commercial off-the-shelf components and mixed-criticality workloads make spacecraft software stacks more complex and interconnected. Hypervisors are now used to isolate critical subsystems, yet their privileged position makes them attractive targets and their security has received limited automated scrutiny in space contexts.

This work introduces \textsc{Metal-fuzz}, a coverage-guided, hardware-in-the-loop, bare-metal fuzzing framework that targets paravirtualized hypervisor interfaces under realistic execution conditions. Metal-fuzz bridges common kernel fuzzing backends with embedded targets by forwarding executor operations to a remote system under test, enabling hypercall fuzzing while preserving hardware-specific behavior. We define a threat model centered on guest-to-hypervisor escape and identify key challenges in fuzzing embedded hypervisors, including stateful interfaces, hardware dependence, and coverage collection.

A prototype on a Zynq-7000 (Cortex-A9) platform demonstrates feasibility by fuzzing the XtratuM hypervisor and integrating JTAG-based control and trace-driven coverage. The framework provides a practical foundation for systematic security evaluation of space hypervisors and guides future extensions toward broader device coverage and automated analysis.

Files

License info not available
warning

File under embargo until 10-12-2026