USENIX Security2020Top-tier venue
Analysis of DTLS Implementations Using Protocol State Fuzzing
Paul Fiterau-Brostean, Bengt Jonsson, Robert Merget, Joeri de Ruiter, Konstantinos Sagonas, Juraj Somorovsky
Abstract
Recent years have witnessed an increasing number of protocols relying on UDP. Compared to TCP, UDP offers performance advantages such as simplicity and lower latency. This has motivated its adoption in Voice over IP, tunneling technologies, IoT, and novel Web protocols. To protect sensitive data exchange in these scenarios, the DTLS protocol has been developed as a cryptographic variation of TLS. DTLS's main challenge is to support the stateless and unreliable transport of UDP. This has forced protocol designers to make choices that affect the complexity of DTLS, and to incorporate features that need not be addressed in the numerous TLS analyses. We present the first comprehensive analysis of DTLS implementations using protocol state fuzzing. To that end, we extend TLS-Attacker, an open source framework for analyzing TLS implementations, with support for DTLS tailored to the stateless and unreliable nature of the underlying UDP layer. We build a framework for applying protocol state fuzzing on DTLS servers, and use it to learn state machine models for thirteen DTLS implementations. Analysis of the learned state models reveals four serious security vulnerabilities, including a full client authentication bypass in the latest JSSE version, as well as several functional bugs and non-conformance issues. It also uncovers considerable differences between the models, confirming the complexity of DTLS state machines. Name Version Utility Algorithms Client Cert Auth URL GnuTLS 3.5.19 gnutls-serv DH,ECDH,RSA,PSK NONE,REQ,OPT https://www.gnutls.org 3.6.7 DH,ECDH,RSA,PSK NONE ,REQ ,OPT JSSE 9.0.4 -DH,ECDH,RSA NONE,REQ ,OPT https://www.oracle.com/java/ 12.0.2 DH ,ECDH ,RSA NONE ,REQ ,OPT MbedTLS 2.16.1 ssl-server2 DH,ECDH,RSA,PSK NONE ,REQ ,OPT https://tls.mbed.org NSS 3.46 tstclnt DH,ECDH,RSA NONE ,REQ,OPT https://nss-crypto.org OpenSSL 1.1.1b openssl s _ server DH,ECDH,RSA,PSK NONE ,REQ ,OPT https://www.openssl.org PionDTLS e4481fc -ECDH ,PSK NONE ,REQ ,OPT https://github.com/pion/dtls Scandium old c7895c6 -ECDH ,PSK NONE ,REQ ,OPT https://www.eclipse.org/californium/ Scandium new 6979a09 ECDH ,PSK NONE ,REQ ,OPT TinyDTLS C 53a0d97 dtls-server ECDH ,PSK NONE ,REQ https://github.com/contiki-ng/tinydtls
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 434a6ffb-b807-4d70-82c3-471e95b9852bCited by top-tier papers23
- DriveFuzz: Discovering Autonomous Driving Bugs through Driving Quality-Guided FuzzingSeulbae Kim, Major Liu, Junghwan John Rhee, Yuseok Jeon et al.CCS 2022 · 65 citations
- Noncompliance as Deviant Behavior: An Automated Black-box Noncompliance Checker for 4G LTE Cellular DevicesSyed Rafiul Hussain, Imtiaz Karim, Abdullah Al Ishtiaq, Omar Chowdhury et al.CCS 2021 · 41 citations
- Prognosis: closed-box analysis of network protocol implementationsTiago Ferreira, Harrison Brewton, Loris D'Antoni, Alexandra SilvaSIGCOMM 2021 · 34 citations
- Linear-time Temporal Logic guided Greybox FuzzingRuijie Meng, Zhen Dong, Jialin Li, Ivan Beschastnikh et al.ICSE 2022 · 29 citations
- Logic Gone Astray: A Security Analysis Framework for the Control Plane Protocols of 5G BasebandsKai Tu, Abdullah Al Ishtiaq, Syed Md. Mukit Rashid, Yilu Dong et al.USENIX Security 2024 · 26 citations
Builds on2
Related papers
- Exploring the Unknown DTLS Universe: Analysis of the DTLS Server Ecosystem on the InternetNurullah Erinola, Marcel Maehren, Robert Merget, Juraj Somorovsky et al.USENIX Security 2023
- DY Fuzzing: Formal Dolev-Yao Models Meet Cryptographic Protocol Fuzz TestingMax Ammann, Lucca Hirschi, Steve KremerS&P 2024 · 25 citations
- Analyzing the WebRTC Ecosystem and Breaking Authentication in DTLS-SRTPMartin Bach, Vukašin Karadžić, Lukas Knittel, Robert Merget et al.USENIX Security 2026
- DUMPLING: Fine-grained Differential JavaScript Engine FuzzingLiam Wachter, Julian Gremminger, Christian Wressnegger, Mathias Payer et al.NDSS 2025
- Automata-Based Automated Detection of State Machine Bugs in Protocol ImplementationsPaul Fiterau-Brostean, Bengt Jonsson, Konstantinos Sagonas, Fredrik TåquistNDSS 2023
