CMFuzz: Parallel Fuzzing of IoT Protocols by Configuration Model Identification and Scheduling
Qi Xu, Fuchen Ma, Yuanliang Chen, Wanli Chen, Feifan Wu, Yanyang Zhao, Heyuan Shi, Yu Jiang
Abstract
IoT protocols are essential for the communication among diverse devices. In real-world scenarios, IoT protocols utilize flexible configurations to meet various use cases. These configurations can significantly impact the protocols' execution paths, with many bugs emerging only under specific configurations. Fuzzing has become a prominent technique for uncovering vulnerabilities in IoT protocol implementations. However, traditional fuzzing approaches are typically conducted using fixed or default configurations, overlooking potential issues that might arise in different settings. This limitation can lead to missing critical bugs that appear only under alternative configurations.
In this paper, we propose CMFUZZ, a parallel fuzzing framework designed to improve fuzzing effectiveness of IoT protocols through configuration identification and scheduling. CMFUZZ first constructs a generalized protocol configuration model by systematically extracting configuration items from protocol implementations. Then, based on this model, CMFUZZ defines the relations among configuration items and introduces a relation-aware allocation mechanism to distribute them across parallel fuzzing instances. For evaluation, We implement CMFUZZ on top of the widely-used protocol fuzzer Peach and conduct experiments on six popular IoT protocols. Compared to the original parallel mode of Peach and state-of-the-art parallel protocol fuzzer SPFuzz, CMFUZZ covers an average of 34.4% and 28.5% more branches within 24 hours. Additionally, CMFUZZ has detected 14 previously-unknown bugs in these real-world IoT protocols.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3eeab821-0951-4302-97c8-dabca1cca952Builds on6
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- Designing New Operating Primitives to Improve Fuzzing PerformanceWen Xu, Sanidhya Kashyap, Changwoo Min, Taesoo KimCCS 2017 · 139 citations
- PAVFuzz: State-Sensitive Fuzz Testing of Protocols in Autonomous VehiclesFeilong Zuo, Zhengxiong Luo, Junze Yu, Zhe Liu et al.DAC 2021 · 30 citations
- Logos: Log Guided Fuzzing for Protocol ImplementationsFeifan Wu, Zhengxiong Luo, Yanyang Zhao, Qingpeng Du et al.ISSTA 2024 · 13 citations
- SPFuzz: Stateful Path based Parallel Fuzzing for Protocols in Autonomous VehiclesJunze Yu, Zhengxiong Luo, Fangshangyuan Xia, Yanyang Zhao et al.DAC 2024 · 11 citations
Related papers
- LLMIF: Augmented Large Language Model for Fuzzing IoT DevicesJincheng Wang, Le Yu, Xiapu LuoS&P 2024 · 61 citations
- MBFuzzer: A Multi-Party Protocol Fuzzer for MQTT BrokersXiangpu Song, Jianliang Wu, Yingpei Zeng, Hao Pan et al.USENIX Security 2025
- WingMuzz: Blackbox Testing of IoT Protocols via Two-dimensional Fuzzing ScheduleXiaogang Zhu, Enze Dai, Xiaotao Feng, Shaohua Wang et al.ASE 2025
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo et al.NDSS 2018 · 311 citations
- Camveil: Unveiling Security Camera Vulnerabilities Through Multi-Protocol Coordinated FuzzingFuchen Ma, Yuqiao Yang, Yuanliang Chen, Yanyang Zhao et al.S&P 2026
