A Survey of Protocol Fuzzing
arXiv:2401.01568 · doi:10.1145/3696788
Abstract
Communication protocols form the bedrock of our interconnected world, yet vulnerabilities within their implementations pose significant security threats. Recent developments have seen a surge in fuzzing-based research dedicated to uncovering these vulnerabilities within protocol implementations. However, there still lacks a systematic overview of protocol fuzzing for answering the essential questions such as what the unique challenges are, how existing works solve them, etc. To bridge this gap, we conducted a comprehensive investigation of related works from both academia and industry. Our study includes a detailed summary of the specific challenges in protocol fuzzing, and provides a systematic categorization and overview of existing research efforts. Furthermore, we explore and discuss potential future research directions in protocol fuzzing. This survey serves as a foundational guideline for researchers and practitioners in the field.
References in corpus (13)
- Sequence to Sequence Learning with Neural Networks
- Hyperledger Fabric: A Distributed Operating System for Permissioned Blockchains
- Survey of Important Issues in UAV Communication Networks
- StateAFL: Greybox Fuzzing for Stateful Network Servers
- Nyx-Net: Network Fuzzing with Incremental Snapshots
- BaseSAFE: Baseband SAnitized Fuzzing through Emulation
- How Effective Are They? Exploring Large Language Model Based Fuzz Driver Generation
- Legion: Best-First Concolic Testing
- L2Fuzz: Discovering Bluetooth L2CAP Vulnerabilities Using Stateful Fuzz Testing
- Leveraging Textual Specifications for Grammar-based Fuzzing of Network Protocols
- TSpec-LLM: An Open-source Dataset for LLM Understanding of 3GPP Specifications
- NLP-based Cross-Layer 5G Vulnerabilities Detection via Fuzzing Generated Run-Time Profiling
- Eywa: Automating Model Based Testing using LLMs