Return
ICSploit: A Fuzzing Framework for Proprietary Industrial Control System Protocols Driven by Function Codes
DOI:10.1109/tifs.2026.3709093.png)
Abstract
En 中文
Fuzzing has been effectively validated and widely applied for disovering vulnerability in public industrial control system (ICS) protocols. However, when fuzzing diverse proprietary protocols in an ICS, existing fuzzing methods suffer from a lack of protocol specifications, leading to numerous invalid test cases and shallow state depth coverage. In this paper, ICSploit, a fuzzing framework designed for proprietary ICS protocols, is proposed. ICSploit reconstructs protocol specifications by parsing protocol traffic to guide mutations, ensuring test case validity. Additionally, ICSploit tracks protocol states via bidirectional traffic function codes and sends prefix sequences to reach target states, enabling deep state testing. Experimental results on ten representative network and industrial control protocols demonstrate that ICSploit achieves a test case acceptance rate of more than 80%. Moreover, compared with state-of-the-art fuzzing tools such as Boofuzz, Bleem, and NCMFuzzer, ICSploit significantly improves the ability to trigger anomalies. In terms of state coverage, ICSploit consistently generates more new message types than other methods when tested on the 10 protocols. Additionally, four 0-day vulnerabilities in S7comm that were not identified by prior methods were discovered.
Keywords:
Fuzzing
industrial control system
proprietary protocol
vulnerability discovery
Journal
IF:
8
Papers:
5.3K
Citations:
2.3W
Organization
Cited Papers
NCMFuzzer: Using non-critical field mutation and test case combination to improve the efficiency of ICS protocol fuzzing
COMPUTERS & SECURITY
IF5.4
MTA Fuzzer: A low-repetition rate Modbus TCP fuzzing method based on Transformer and Mutation Target Adaptation
COMPUTERS & SECURITY
IF5.4

