SNPSFuzzer: A Fast Greybox Fuzzer for Stateful Network Protocols Using Snapshots

SNPSFuzzer: A Fast Greybox Fuzzer for Stateful Network Protocols Using Snapshots
复制标题

DOI:
10.1109/tifs.2022.3192991
复制
发表时间:
2022-02
影响因子:
6.8
通讯作者:
Junqiang Li;Senyi Li;Gang Sun;Ting Chen;Hongfang Yu
Junqiang Li;Senyi Li;Gang Sun;Ting Chen;Hongfang Yu
中科院分区:
计算机科学1区
文献类型:
--
作者:
Junqiang Li;Senyi Li;Gang Sun;Ting Chen;Hongfang Yu

文献摘要

被引文献

相似文献

灰盒模糊测试在无状态程序中得到了广泛的应用,并取得了巨大的成功。然而,大多数最先进的灰盒模糊器在模糊状态网络协议程序中速度慢且状态深度覆盖浅,能够记住和存储交互的细节。现有的网络协议程序灰盒模糊器首先发送一系列明确定义的输入消息前缀序列,然后发送变异消息来测试有状态网络协议的目标状态。这个过程会导致很高的时间成本。在本文中,我们提出了 SNPSFuzzer,这是一种使用快照的状态网络协议的快速灰盒模糊器。 SNPSFuzzer 在网络协议程序处于特定状态时转储上下文信息,并在需要对该状态进行模糊测试时恢复它。此外,我们设计了消息链分析算法来探索更多、更深的网络协议状态。我们的评估表明,与最先进的网络协议灰盒模糊器 AFLNET 相比,SNPSFuzzer 在 24 小时内将网络协议模糊器的消息处理速度提高了 70.7%,路径覆盖率平均提高了 20.9%。此外,SNPSFuzzer 还暴露了 Tinydtls 程序中之前未报告的漏洞。
Greybox fuzzing has been widely used in stateless programs and has achieved great success. However, most state-of-the-art greybox fuzzers have slow speed and shallow state depth coverage in fuzzing stateful network protocol programs, which are able to remember and store the details of interactions. The existing greybox fuzzers for network protocol programs first send a series of well-defined prefix sequences of input messages and then send mutated messages to test the target state of a stateful network protocol. This process leads to a high time cost. In this paper, we propose SNPSFuzzer, a fast greybox fuzzer for stateful network protocols using snapshots. SNPSFuzzer dumps the context information when the network protocol program is in a specific state and restores it when the state needs to be fuzzed. Furthermore, we design a message chain analysis algorithm to explore more and deeper network protocol states. Our evaluation shows that compared with the state-of-the-art network protocol greybox fuzzer AFLNET, SNPSFuzzer improves the message processing speed of network protocol fuzzing by 70.7% and increases the path coverage by 20.9% on average within 24 hours. Moreover, SNPSFuzzer exposes a previously unreported vulnerability in the program Tinydtls.