A Survey of Protocol Fuzzing

被引:0
|
作者
Zhang, Xiaohan [1 ,2 ,3 ]
Zhang, Cen [4 ]
Li, Xinghua [1 ,2 ,3 ]
Du, Zhengjie [5 ]
Mao, Bing [5 ]
Li, Yuekang [4 ]
Zheng, Yao wen [4 ]
Li, Yeting [6 ]
Pan, Li [7 ]
Liu, Yang [4 ]
Deng, Robert [8 ]
机构
[1] Minist Educ, State Key Lab Integrated Serv Networks, Xian, Peoples R China
[2] Minist Educ, Engn Res Ctr Big Data Secur, Xian, Peoples R China
[3] Xidian Univ, Sch Cyber Engn, Xian, Peoples R China
[4] Nanyang Technol Univ, Singapore, Singapore
[5] Nanjing Univ, Nanjing, Peoples R China
[6] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[7] Shanghai Jiao Tong Univ, Shanghai, Peoples R China
[8] Singapore Management Univ, Singapore, Singapore
基金
新加坡国家研究基金会; 中国国家自然科学基金;
关键词
Protocol; fuzz testing; security; NETWORK PROTOCOL; SYMBOLIC EXECUTION; STATE; IMPLEMENTATIONS; SECURITY;
D O I
10.1145/3696788
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Communication protocols form the bedrock of our interconnected world, yet vulnerabilities within their implementations pose significant security threats. Recent developments have seen a surge in fuzzing-based research dedicated to uncovering these vulnerabilities within protocol implementations. However, there still lacks a systematic overview of protocol fuzzing for answering the essential questions such as what the unique challenges are, how existing works solve them, and so on. To bridge this gap, we conducted a comprehensive investigation of related works from both academia and industry. Our study includes a detailed summary of the specific challenges in protocol fuzzing and provides a systematic categorization and overview of existing research efforts. Furthermore, we explore and discuss potential future research directions in protocol fuzzing.
引用
收藏
页数:36
相关论文
共 50 条
  • [41] State Selection Algorithms and Their Impact on The Performance of Stateful Network Protocol Fuzzing
    Liu, Dongge
    Pham, Van-Thuan
    Ernst, Gidon
    Murray, Toby
    Rubinstein, Benjamin I. P.
    2022 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ANALYSIS, EVOLUTION AND REENGINEERING (SANER 2022), 2022, : 720 - 730
  • [42] IPSpex: Enabling Efficient Fuzzing via Specification Extraction on ICS Protocol
    Sun, Yue
    Lv, Shichao
    You, Jianzhou
    Sun, Yuyan
    Chen, Xin
    Zheng, Yaowen
    Sun, Limin
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY, ACNS 2022, 2022, 13269 : 356 - 375
  • [43] SATFuzz: A Stateful Network Protocol Fuzzing Framework from a Novel Perspective
    Pan, Zulie
    Zhang, Liqun
    Hu, Zhihao
    Li, Yang
    Chen, Yuanchao
    APPLIED SCIENCES-BASEL, 2022, 12 (15):
  • [44] Internet Key Exchange Protocol Fuzzing Test On Extended Peach Framework
    Zhang, Jiawei
    Shi, Yijie
    PROCEEDINGS OF THE 2016 INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND ENGINEERING APPLICATIONS, 2016, 63 : 99 - 103
  • [45] The Stacked Seq2seq-attention Model for Protocol Fuzzing
    Gao, Zicong
    Dong, Weiyu
    Chang, Rui
    Ai, Chengwei
    PROCEEDINGS OF 2019 IEEE 7TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT 2019), 2019, : 126 - 130
  • [46] Research on State-Based Bluetooth Multi-Protocol Fuzzing
    Hou, Benyan
    Huang, Chenglong
    Yang, Ting
    Wu, Gaofei
    Wang, He
    Zhang, Yuqing
    2024 IEEE ANNUAL CONGRESS ON ARTIFICIAL INTELLIGENCE OF THING, AIOT 2024, 2024, : 13 - 18
  • [47] Black-box Fuzzing Approaches to Secure Web Applications: Survey
    Alsaedi, Aseel
    Alhuzali, Abeer
    Bamasag, Omaimah
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (05) : 849 - 855
  • [48] Netfuzzlib: Adding First-Class Fuzzing Support to Network Protocol Implementations
    Robben, Jeroen
    Vanhoef, Mathy
    COMPUTER SECURITY-ESORICS 2024, PT II, 2024, 14983 : 65 - 84
  • [49] A Framework of High-Speed Network Protocol Fuzzing Based on Shared Memory
    Fu, Junsong
    Xiong, Shuai
    Wang, Na
    Ren, Ruiping
    Zhou, Ang
    Bhargava, Bharat K.
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 2779 - 2798
  • [50] Intelligent Zigbee Protocol Fuzzing via Constraint-Field Dependency Inference
    Ren, Mengfei
    Zhang, Haotian
    Ren, Xiaolei
    Ming, Jiang
    Lei, Yu
    COMPUTER SECURITY - ESORICS 2023, PT II, 2024, 14345 : 467 - 486