arrow
Return

SGPFuzzer: A State-Driven Smart Graybox Protocol Fuzzer for Network Protocol Implementations

delete2020-01-01
delete17
delete
OA
AI
Y
Yingchao Yu *
Z
Zuoning Chen
S
Shuitao Gan
X
Xiaofeng Wang
DOI:10.1109/ACCESS.2020.3025037delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
As one of the most widely used technologies in software testing, fuzzing technology has been applied to network protocol vulnerability detection, and various network protocol fuzzers have been proposed. In this study, we first analyze and summarize some typical network protocol fuzzers to highlight the challenges when addressing stateful network protocol fuzzing. Then, a state-driven smart graybox protocol fuzzer (SGPFuzzer) is proposed to deal with these challenges. Finally, we evaluate SGPFuzzer on two widely used protocol implementations (LightFTP and tinyDTLS).The results show that SGPFuzzer outperforms Boofuzz and AFL in path coverage, unique crashes and the first time crash to crash, and it triggers a known bug which can't be trigged by the other two tools, fully proving its effectiveness and practicability.
Keywords:
Protocols
Fuzzing
Computer bugs
Servers
Security
Tools
Stateful network protocol
graybox fuzzer
AFL
smart mutation
Boofuzz
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.8W
Citations:
29.4W

Organization

J
Jiangnan University
Scholars:
3.9W
Papers: 2.7W
Citations: 4.7W