A Framework of High-Speed Network Protocol Fuzzing Based on Shared Memory

模糊测试 计算机科学 有状态防火墙 协议(科学) 无状态协议 计算机网络 分布式计算 操作系统 软件 网络数据包 医学 替代医学 病理
作者
Junsong Fu,Shuai Xiong,Na Wang,R. Ren,Ang Zhou,Bharat Bhargava
出处
期刊:IEEE Transactions on Dependable and Secure Computing [Institute of Electrical and Electronics Engineers]
卷期号:: 1-18
标识
DOI:10.1109/tdsc.2023.3318571
摘要

In recent years, security test of network protocols based on fuzzing has been attracting more and more attentions. This is very challenging compared with the stateless software fuzzing and most early network protocol fuzzers are of low speed and poor test effect. Since the first greybox and stateful fuzzer named AFLNET was proposed, several new schemes have been designed to improve its performance from different aspects. During the research, a great challenge is how to greatly improve the fuzzing efficiency. Based on the basic analysis in SNPSFuzzer, this paper provides a more thorough analysis about the time consumption in a fuzzing iteration for 13 network protocols and then we design a High-speed Network Protocol Fuzzer named HNPFuzzer. In HNPFuzzer, the test cases and response messages between the client and server are transmitted through the shared memory, guided by a precise synchronizer, rather than the socket interfaces. This greatly shorten the period of an iteration. Moreover, we design a persistent mode attempting to fuzz the service instances in the memory more than one time based on analyzing the side effect information. This mode further improves the speed of fuzzing. Experiment results illustrate that our scheme can improve the fuzzing throughput by about 39.66 times in average and triggers a large number of crashes including 2 new vulnerabilities which cannot discovered by existing fuzzers. Note that, the existing network protocol fuzzing schemes proposed in different directions do not compete with each other and on the contrary, they can collaborate with each other to improve the overall fuzzing effect and efficiency. Consequently, more existing tools can be integrated into our framework to get better network protocol fuzzing effect.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
muyu发布了新的文献求助30
1秒前
2秒前
wenwen完成签到,获得积分20
5秒前
吧唧吧唧发布了新的文献求助10
5秒前
april完成签到,获得积分10
6秒前
内向秋寒发布了新的文献求助10
7秒前
超级冰淇淋完成签到 ,获得积分10
12秒前
17秒前
罗燕发布了新的文献求助20
20秒前
Jasper应助Jin采纳,获得10
23秒前
大模型应助曾至城采纳,获得10
24秒前
田様应助刘小博采纳,获得10
25秒前
花城完成签到,获得积分10
28秒前
scq完成签到 ,获得积分10
35秒前
传奇3应助无私思雁采纳,获得10
39秒前
搞怪的语风完成签到 ,获得积分10
39秒前
wch666发布了新的文献求助10
40秒前
xingyi完成签到,获得积分10
41秒前
41秒前
43秒前
44秒前
开心的云发布了新的文献求助10
45秒前
49秒前
54秒前
1751587229发布了新的文献求助10
55秒前
57秒前
Hello应助MAD666采纳,获得10
58秒前
Jyy77发布了新的文献求助10
58秒前
59秒前
天天快乐应助科研通管家采纳,获得10
1分钟前
SciGPT应助科研通管家采纳,获得10
1分钟前
CodeCraft应助科研通管家采纳,获得10
1分钟前
一一应助科研通管家采纳,获得30
1分钟前
852应助科研通管家采纳,获得10
1分钟前
大个应助科研通管家采纳,获得10
1分钟前
1分钟前
1分钟前
pluto应助科研通管家采纳,获得10
1分钟前
1分钟前
bkagyin应助科研通管家采纳,获得10
1分钟前
高分求助中
LNG地下式貯槽指針(JGA Guideline-107)(LNG underground storage tank guidelines) 1000
Generalized Linear Mixed Models 第二版 1000
rhetoric, logic and argumentation: a guide to student writers 1000
Asymptotically optimum binary codes with correction for losses of one or two adjacent bits 800
Preparation and Characterization of Five Amino-Modified Hyper-Crosslinked Polymers and Performance Evaluation for Aged Transformer Oil Reclamation 700
Operative Techniques in Pediatric Orthopaedic Surgery 510
Full waveform acoustic data processing 500
热门求助领域 (近24小时)
化学 医学 材料科学 生物 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 基因 遗传学 物理化学 催化作用 免疫学 细胞生物学 电极
热门帖子
关注 科研通微信公众号,转发送积分 2926065
求助须知:如何正确求助?哪些是违规求助? 2573684
关于积分的说明 6950600
捐赠科研通 2226412
什么是DOI,文献DOI怎么找? 1183217
版权声明 589129
科研通“疑难数据库(出版商)”最低求助积分说明 579089