Fizzle: A Framework for Deterministic and Reproducible Network Fuzzing
Nathaniel Bennett, Tyler Tucker, Carson Stillman, William Enck, Patrick Traynor, Kevin R. B. Butler
Abstract
Networked systems regularly receive untrusted inputs. When improperly handled, adversaries thus have the ability to remotely crash or compromise such systems. While many techniques have been proposed to detect these vulnerabilities, their ability to handle asynchronous and nondeterministic behavior significantly limit their coverage of real systems. In this paper we present Fizzle, a high-performance deterministic simulation testing framework for fuzzing network applications. Fizzle interposes system library calls to enforce sequential execution for multi-threading, simulate multi-modal network connections, and control system randomization in a manner that is transparent to the target application. By tracking synchronization and I/O primitives, Fizzle deterministically identifies when an application has finished processing input, thereby dramatically expanding the suite of protocols that it can accurately fuzz relative to other approaches. We show that Fizzle maintains 100% stability across ProFuzzBench targets and highly concurrent applications including Unbound, Redis and Open5GS. This resultantly leads to improved coverage and newly discovered/disclosed CVEs for projects that have already been subject to fuzzing. Surprisingly, Fizzle significantly outperforms existing network fuzzers despite carrying out substantial bookkeeping of external state and enforcing sequential execution of threads, achieving up to 20x more executions per second. Fizzle is designed to be highly configurable to a variety of network inputs and integrates with both AFL++ and LibAFL; we release it as an open-source extensible framework for future network protocol research to be carried out in a deterministic and reproducible manner.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 8c84f08d-07fe-4734-8ca0-5f2a8fbdaf43Related papers
- SnapFuzz: high-throughput fuzzing of network applicationsAnastasios Andronidis, Cristian CadarISSTA 2022 · 56 citations
- SimiFuzz: Seed–Worker Scheduling for Parallel Fuzzing via Contextual BanditsYijia Guo, Zhiguo Ding, Hong Liang, Ming Zhong et al.ISSTA 2026
- CoreCrisis: Threat-Guided and Context-Aware Iterative Learning and Fuzzing of 5G Core NetworksYilu Dong, Tianchang Yang, Abdullah Al Ishtiaq, Syed Md. Mukit Rashid et al.USENIX Security 2025
- Designing New Operating Primitives to Improve Fuzzing PerformanceWen Xu, Sanidhya Kashyap, Changwoo Min, Taesoo KimCCS 2017 · 139 citations
- Chronos: Finding Timeout Bugs in Practical Distributed Systems by Deep-Priority Fuzzing with Transient DelayYuanliang Chen, Fuchen Ma, Yuanhang Zhou, Ming Gu et al.S&P 2024 · 12 citations
