NCFuzz: Configuration-Guided Network Service Fuzzing
Xuesong Bai, Hengkai Ye, Shenghan Zheng, Fenglu Zhang, Hong Hu, Zhou Li
Abstract
Network services like FTP and DNS are critical components of modern reliable Internet infrastructure. Software fuzzing, especially network protocol fuzzing, is widely used to uncover flaws in these systems. However, conventional fuzzers operate under a single, fixed configuration throughout the fuzzing campaign, leaving the service’s rich configuration space unexplored. Incorporating configurations as a dynamic input dimension is challenging due to complex semantics, trigger conditions, and the resulting enlarged search space. We tackle the problem of finding bugs under non-default configurations, termed ConfBug, by designing a new fuzzer called NCFuzz. The non-default configurations can be uncommon but administrators may enable them, which cannot be exercised by conventional fuzzers. With the assumption that software documentation that describes configuration options is available, NCFuzz leverages two key observations: 1) software documentation contains rich information about configurations; 2) interactions between configuration and network messages can be tracked through code instrumentation and data-flow analysis. Using these insights, NCFuzz uses configuration knowledge and the relationships between configurations and network messages to guide the fuzzer toward new software states. The quality and completeness of the documentation will affect the effectiveness of NCFuzz. Evaluation on six network service implementations shows NCFuzz achieves higher coverage than baseline fuzzers. Five ConfBugs were discovered during fuzzing.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on25
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Chain-of-Thought Prompting Elicits Reasoning in Large Language ModelsJason Wei, Xuezhi Wang, Dale Schuurmans, Maarten Bosma et al.NeurIPS 2022 · 22,562 citations
- Using an LLM to Help With Code UnderstandingDaye Nam, Andrew Macvean, Vincent J. Hellendoorn, Bogdan Vasilescu et al.ICSE 2024 · 264 citations
- NetLLM: Adapting Large Language Models for NetworkingDuo Wu, Xianda Wang, Yaqi Qiao, Zhi Wang et al.SIGCOMM 2024 · 162 citations
- Systematic Fuzzing and Testing of TLS LibrariesJuraj SomorovskyCCS 2016 · 136 citations
Related papers
- ECFuzz: Effective Configuration Fuzzing for Large-Scale SystemsJunqiang Li, Senyi Li, Keyao Li, Falin Luo et al.ICSE 2024 · 12 citations
- Differential Fuzzing for Data Distribution Service Programs with Dynamic ConfigurationDohyun Ryu, Giyeol Kim, Daeun Lee, Seongjin Kim et al.ASE 2024 · 1 citation
- Configuration-Sensitive Linux Kernel FuzzingYuheng Shen, Jianzhong Liu, Yuhan Chen, Yifei Chu et al.ICSE 2026
- No Peer, no Cry: Network Application Fuzzing via Fault InjectionNils Bars, Moritz Schloegel, Nico Schiller, Lukas Bernhard et al.CCS 2024 · 5 citations
- Logos: Log Guided Fuzzing for Protocol ImplementationsFeifan Wu, Zhengxiong Luo, Yanyang Zhao, Qingpeng Du et al.ISSTA 2024 · 13 citations
