Automata-Based Automated Detection of State Machine Bugs in Protocol Implementations
Paul Fiterau-Brostean, Bengt Jonsson, Konstantinos Sagonas, Fredrik Tåquist
Abstract
—Implementations of stateful security protocols must carefully manage the type and order of exchanged messages and cryptographic material, by maintaining a state machine which keeps track of protocol progress. Corresponding implementation flaws, called state machine bugs , can constitute serious security vulnerabilities. We present an automated black-box technique for detecting state machine bugs in implementations of stateful network protocols. It takes as input a catalogue of state machine bugs for the protocol, each specified as a finite automaton which accepts sequences of messages that exhibit the bug, and a (possibly inaccurate) model of the implementation under test, typically obtained by model learning. Our technique constructs the set of sequences that (according to the model) can be performed by the implementation and that (according to the automaton) expose the bug. These sequences are then transformed to test cases on the actual implementation to find a witness for the bug or filter out false alarms. We have applied our technique on three widely-used implementations of SSH servers and nine different DTLS server and client implementations, including their most recent versions. Our technique easily reproduced all bugs identified by security researchers before, and produced witnesses for them. More importantly, it revealed several previously unknown bugs in the same implementations, two new vulnerabilities, and a variety of new bugs and non-conformance issues in newer versions of the same SSH and DTLS implementations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9af07517-09e5-44df-aba0-70fa03302842Cited by top-tier papers8
- Logic Gone Astray: A Security Analysis Framework for the Control Plane Protocols of 5G BasebandsKai Tu, Abdullah Al Ishtiaq, Syed Md. Mukit Rashid, Yilu Dong et al.USENIX Security 2024 · 26 citations
- State Machine Mutation-based Testing Framework for Wireless Communication ProtocolsSyed Md. Mukit Rashid, Tianwei Wu, Kai Tu, Abdullah Al Ishtiaq et al.CCS 2024 · 4 citations
- A Formal Analysis of SCTP: Attack Synthesis and Patch VerificationJacob Ginesin, Max von Hippel, Evan Defloor, Cristina Nita-Rotaru et al.USENIX Security 2024 · 4 citations
- AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi NetworksXin'an Zhou, Juefei Pu, Zhutian Liu, Zhiyun Qian et al.NDSS 2026 · 1 citation
- Identifying Logical Vulnerabilities in QUIC ImplementationsKaihua Wang, Jianjun Chen, Pinji Chen, Jianwei Zhuge et al.NDSS 2026 · 1 citation
Builds on10
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 225 citations
- Systematic Fuzzing and Testing of TLS LibrariesJuraj SomorovskyCCS 2016 · 136 citations
- SFADiff: Automated Evasion Attacks and Fingerprinting Using Black-box Differential Automata LearningGeorge Argyros, Ioannis Stais, Suman Jana, Angelos D. Keromytis et al.CCS 2016 · 65 citations
- Automated Attack Discovery in TCP Congestion Control Using a Model-guided ApproachSamuel Jero, Md. Endadul Hoque, David R. Choffnes, Alan Mislove et al.NDSS 2018 · 46 citations
- Noncompliance as Deviant Behavior: An Automated Black-box Noncompliance Checker for 4G LTE Cellular DevicesSyed Rafiul Hussain, Imtiaz Karim, Abdullah Al Ishtiaq, Omar Chowdhury et al.CCS 2021 · 41 citations
Related papers
- The Closer You Look, The More You Learn: A Grey-box Approach to Protocol State Machine LearningChris McMahon Stone, Sam L. Thomas, Mathy Vanhoef, James Henderson et al.CCS 2022 · 11 citations
- Stateful Greybox FuzzingJinsheng Ba, Marcel Böhme, Zahra Mirzamomen, Abhik RoychoudhuryUSENIX Security 2022
- Finding SSH Strict Key Exchange Violations by State LearningFabian Bäumer, Marcel Maehren, Marcus Brinkmann, Jörg SchwenkCCS 2025 · 1 citation
- Towards Internet-Based State Learning of TLS State MachinesMarcel Maehren, Nurullah Erinola, Robert Merget, Jörg Schwenk et al.USENIX Security 2025
- HVLearn: Automated Black-Box Analysis of Hostname Verification in SSL/TLS ImplementationsSuphannee Sivakorn, George Argyros, Kexin Pei, Angelos D. Keromytis et al.S&P 2017 · 88 citations
