arrow
Return

LIBAFLSTAR: Fast and State-Aware Protocol Fuzzing

delete2026-01-01
delete0
PRE
AI
C
Cristian Daniele *
T
Timme Bethe
M
M. Maugeri
A
Andrea Continella
E
Erik Poll
DOI:10.1007/978-3-032-07894-0_6delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Fuzzing is arguably one of the most effective software vulnerability discovery techniques. However, despite recent advances, fuzzing stateful software suffers from severe inefficiencies and scalability limitations. This hinders automated testing for software that relies on state models, such as protocol implementations. Unlike stateless approaches, efficient stateful fuzzers need to i) explore the state model of the target system, ii) focus on the most interesting states, iii) track which messages are interesting for each state, and iv) handle expensive restarts and synchronizations of the system. In this paper, we present LIBAFLSTAR, a fast and state-aware protocol fuzzer that addresses the aforementioned challenges leveraging i) partial message sequences, ii) a novel state scheduler, iii) state-aware queues and bitmaps, and iv) persistent mode. We fine-tune our approach by running an extensive ablation study with more than 20 configurations over six protocol implementations. Then, we evaluate LIBAFLSTAR on the same protocol implementations (FTP, RTSP and HTTP) for 24 hours. We compare LIBAFLSTAR'S performance with two state-of-the-art fuzzers: AFLNET and CHATAFL. Our experiments show that LIBAFLSTAR is more than 30x faster than competitors and achieves, on average, 1.4x more coverage.
Keywords:
Software Security
Software Testing
Fuzzing
Stateful Systems
Network Protocols

Journal

C
COMPUTER SECURITY-ESORICS 2025, PT III
IF:
0
Papers:
26
Citations:
0

Organization

U
university of twente
Scholars:
1.5W
Papers: 1.4W
Citations: 9
R
Radboud University Nijmegen
Scholars:
4.4W
Papers: 3.4W
Citations: 5.4W
U
university of catania
Scholars:
3.0K
Papers: 1.1K
Citations: 0
researcher View more organizations