arrow
Return

ICSploit: A Fuzzing Framework for Proprietary Industrial Control System Protocols Driven by Function Codes

delete2026-07-01
delete0
PRE
AI
S
Shen Lu
赖英旭 cover
赖英旭 (Yingxu Lai)
Y
Yutong Dang
H
Huimin Fang
P
Peng Zhao
B
Baoshan Xie
DOI:10.1109/tifs.2026.3709093delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Fuzzing has been effectively validated and widely applied for disovering vulnerability in public industrial control system (ICS) protocols. However, when fuzzing diverse proprietary protocols in an ICS, existing fuzzing methods suffer from a lack of protocol specifications, leading to numerous invalid test cases and shallow state depth coverage. In this paper, ICSploit, a fuzzing framework designed for proprietary ICS protocols, is proposed. ICSploit reconstructs protocol specifications by parsing protocol traffic to guide mutations, ensuring test case validity. Additionally, ICSploit tracks protocol states via bidirectional traffic function codes and sends prefix sequences to reach target states, enabling deep state testing. Experimental results on ten representative network and industrial control protocols demonstrate that ICSploit achieves a test case acceptance rate of more than 80%. Moreover, compared with state-of-the-art fuzzing tools such as Boofuzz, Bleem, and NCMFuzzer, ICSploit significantly improves the ability to trigger anomalies. In terms of state coverage, ICSploit consistently generates more new message types than other methods when tested on the 10 protocols. Additionally, four 0-day vulnerabilities in S7comm that were not identified by prior methods were discovered.
Keywords:
Fuzzing
industrial control system
proprietary protocol
vulnerability discovery

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.3K
Citations:
2.3W

Organization

C
college of cyberspace science and technology
Scholars:
2
Papers: 1
Citations: 0
B
beijing university of technology
Scholars:
6.0K
Papers: 2.0K
Citations: 0
Cited Papers

Cited Papers

Rtkaller: State-aware Task Generation for RTOS Fuzzing
err2021-09-22
err0
PREAI
errYuheng Shen; Hao Sun; Yu Jiang; Heyuan Shi; Yixiao Yang; Wanli Chang
errShare
errSave
Cefuzz: An Directed Fuzzing Framework for PHP RCE Vulnerability
err2022-03-01
err0
errOAAI
errJiazhen Zhao; Yuliang Lu; Kailong Zhu; Zehan Chen; Hui Huang
errShare
errSave
Fuzzing proprietary protocols of programmable controllers to find vulnerabilities that affect physical control
err2022-06-01
err11
PREAI
errLiu, Puzhuo; Zheng, Yaowen; Song, Zhanwei; Fang, Dongliang; Lv, Shichao; Sun, Limin
errShare
errSave
MTA Fuzzer: A low-repetition rate Modbus TCP fuzzing method based on Transformer and Mutation Target Adaptation
err2024-09-01
err0
PREAI
errWang, Wenpeng; Chen, Zhixiang; Zheng, Ziyang; Wang, Hui; Luo, Junxing
errShare
errSave
Fuzzing Technology Based on Information Theory for Industrial Proprietary Protocol
err2023-07-11
err0
errOAAI
errXin Che; Yangyang Geng; Ge Zhang; Mufeng Wang
errShare
errSave
researcher View more