<p>Network protocol fuzzing is a critical method for detecting vulnerabilities in network protocol programs. However, traditional selection algorithms used in network protocol fuzzing often fail to accurately select effective states and seeds. To address this limitation, this paper proposes a fuzzing framework called Contextual AFL<span>net</span> (CAFL<span>net</span>), which employs a selection algorithm that utilizes enhanced contextual information. This framework introduces key metrics, such as <i>state in-degree</i>, <i>state out-degree</i>, and <i>trace-adjacent call count</i>, to enhance contextual information. The selection algorithm is divided into two parts: (1) a state selection algorithm based on the linear upper confidence bound, which optimizes the balance between exploration and exploitation by utilizing enhanced contextual information, and (2) a tri-factor seed selection algorithm, designed to utilize contextual information such as seed labels, execution information, and session information to thoroughly and effectively evaluate seed value in the selection process. We evaluated our framework and AFL<span>net</span> using eleven benchmark programs from ProFuzzBench and the real-world. The results demonstrate that our framework outperformed AFL<span>net</span> by an average of 6.86% in terms of branch coverage, with a notable increase of 18.79% on PureFTPD. In addition, our framework slightly outperformed AFL<span>net</span> in state discovery and exhibited superior performance in vulnerability detection, triggering known vulnerabilities earlier and more frequently and successfully exposing a previously unknown vulnerability.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

CAFLnet: a network protocol fuzzing framework based on selection algorithm with enhanced contextual information

  • Zhiming Li,
  • Shuquan Zhou,
  • Xiaokan Luo,
  • Heping Wei,
  • Guangkang Zhang

摘要

Network protocol fuzzing is a critical method for detecting vulnerabilities in network protocol programs. However, traditional selection algorithms used in network protocol fuzzing often fail to accurately select effective states and seeds. To address this limitation, this paper proposes a fuzzing framework called Contextual AFLnet (CAFLnet), which employs a selection algorithm that utilizes enhanced contextual information. This framework introduces key metrics, such as state in-degree, state out-degree, and trace-adjacent call count, to enhance contextual information. The selection algorithm is divided into two parts: (1) a state selection algorithm based on the linear upper confidence bound, which optimizes the balance between exploration and exploitation by utilizing enhanced contextual information, and (2) a tri-factor seed selection algorithm, designed to utilize contextual information such as seed labels, execution information, and session information to thoroughly and effectively evaluate seed value in the selection process. We evaluated our framework and AFLnet using eleven benchmark programs from ProFuzzBench and the real-world. The results demonstrate that our framework outperformed AFLnet by an average of 6.86% in terms of branch coverage, with a notable increase of 18.79% on PureFTPD. In addition, our framework slightly outperformed AFLnet in state discovery and exhibited superior performance in vulnerability detection, triggering known vulnerabilities earlier and more frequently and successfully exposing a previously unknown vulnerability.