Automated Construction of High-Quality Initial Seed Corpus for Network Protocol Fuzzing
Weicheng Lin, Laile Xi, Yaowen Zheng, Shenghao Lin, Jiaxing Cheng, Zhen Wang, Shizhao Tian, Yubo Li, Tianheng Qu, Hongsong Zhu
Abstract
Network protocols are foundational to modern communication systems, making vulnerability discovery critical. Stateful protocol fuzzers have been widely adopted due to their high efficiency and low false positives. However, they heavily depend on the quality of the initial seed corpus. Unfortunately, these seeds are typically handcrafted, limited in quantity, and often exercise only shallow protocol behaviors.In this paper, we present AutoSeeder, the first automated framework for constructing high-quality initial seed corpus tailored to stateful protocol fuzzing. Its core idea is to combine lightweight analysis of protocol source code with large language models to get state-handling logic and guide the generation of syntactically valid initial seeds that can reach deeper protocol states. Evaluation on twelve widely-used protocols shows that AutoSeeder can quickly construct a high-quality initial seed corpus, compared with four baselines, resulting in average improvements of 51.95% in state coverage, 152.6% in state transition coverage and 42.51% in code coverage. In addition, AutoSeeder is compatible with three state representation schemes to enhance the performance of the base fuzzers, including AFLNET, StateAFL, and NSFuzz. When integrated with AFLNET, AutoSeeder also discovers seven previously unknown bugs.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 26575a9b-9c7f-428b-80e6-dc28cd105f4fRelated papers
- Large Language Model guided Protocol FuzzingRuijie Meng, Martin Mirchev, Marcel Böhme, Abhik RoychoudhuryNDSS 2024
- MendelFuzz: The Return of the Deterministic StageHan Zheng, Flavio Toffalini, Marcel Böhme, Mathias PayerFSE 2025 · 2 citations
- Stateful Greybox FuzzingJinsheng Ba, Marcel Böhme, Zahra Mirzamomen, Abhik RoychoudhuryUSENIX Security 2022
- Unlocking Low Frequency Syscalls in Kernel Fuzzing with Dependency-Based RAGZhiyu Zhang, Longxing Li, Ruigang Liang, Kai ChenISSTA 2025 · 3 citations
- SmartFuzz: Leveraging Large Language Models and Feature Composition to Generate High-Quality Seeds for Database FuzzingLi Lin, Jintai Hong, Yanlin Zhuang, Rongxin WuOOPSLA 2026
