Return
SGPFuzzer: A State-Driven Smart Graybox Protocol Fuzzer for Network Protocol Implementations
DOI:10.1109/ACCESS.2020.3025037.png)
Abstract
En 中文
As one of the most widely used technologies in software testing, fuzzing technology has been applied to network protocol vulnerability detection, and various network protocol fuzzers have been proposed. In this study, we first analyze and summarize some typical network protocol fuzzers to highlight the challenges when addressing stateful network protocol fuzzing. Then, a state-driven smart graybox protocol fuzzer (SGPFuzzer) is proposed to deal with these challenges. Finally, we evaluate SGPFuzzer on two widely used protocol implementations (LightFTP and tinyDTLS).The results show that SGPFuzzer outperforms Boofuzz and AFL in path coverage, unique crashes and the first time crash to crash, and it triggers a known bug which can't be trigged by the other two tools, fully proving its effectiveness and practicability.
Keywords:
Protocols
Fuzzing
Computer bugs
Servers
Security
Tools
Stateful network protocol
graybox fuzzer
AFL
smart mutation
Boofuzz
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

