An LLM-Guided Fuzzing of Proprietary Industrial Communication Protocols with Context Knowledge
Tianci Pan, Huan Qian, Yaowen Zheng, Haining Wang, Peng Zhang, Jiaxing Cheng, Ge Chu, Ke Li, Ming Zhou
Abstract
Existing fuzzing tools struggle to analyze proprietary Industrial Communication Protocols (ICPs) due to the lack of detailed protocol specifications. Consequently, they often rely on manual analysis or coarse-grained black-box approaches, which offer limited insight into protocol field semantics. This ultimately restricts both the coverage and depth of the testing process. To address these limitations, we propose a novel fuzzing framework called ICProFuzz, which leverages Large Language Models (LLMs) to understand proprietary ICPs. ICProFuzz utilizes LLMs to deeply analyze captured communication messages and available partial protocol descriptions. This enables the automated extraction of field semantics, length constraints, and inter-field dependencies. Utilizing the inferred field types and syntactic formats, we design a suite of advanced mutation strategies, including boundary value injection, format-preserving assignment, and protocol-aware keyword insertion. Finally, the generated test cases are fed into the fuzzing engine, where both the semantic parsing and mutation strategies are dynamically adjusted based on test coverage and anomaly feedback. We conducted extensive evaluations using three widely used proprietary ICPs: S7comm, UMAS, and CIP. The experimental results show that ICProFuzz outperforms traditional baseline fuzzers in vulnerability identification, path coverage, and branch coverage. Moreover, ICProFuzz identified 14 vulnerabilities across six real devices, including two zero-day vulnerabilities.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get a3f6cf00-60b8-4334-80de-0ee3081b3203Related papers
- SemFuzz: A Semantics-Aware Fuzzing Framework for Network Protocol ImplementationsYanbang Sun, Quan Luo, Yuelin Wang, Qian Chen et al.WWW 2026
- Generating Precise Format Specification for Network Protocols Through Adversarial LLM InteractionsHengdi Ye, Bing Shui, Jielun Wu, Yufan Zhou et al.USENIX Security 2026
- LLMIF: Augmented Large Language Model for Fuzzing IoT DevicesJincheng Wang, Le Yu, Xiapu LuoS&P 2024 · 61 citations
- Large Language Model guided Protocol FuzzingRuijie Meng, Martin Mirchev, Marcel Böhme, Abhik RoychoudhuryNDSS 2024
- BSFuzzer: Context-Aware Semantic Fuzzing for BLE Logic Flaw DetectionTing Yang, Yue Qin, Lan Zhang, Zhiyuan Fu et al.NDSS 2026 · 1 citation
