USENIX Security2023Top-tier venue
Extracting Protocol Format as State Machine via Controlled Static Loop Analysis
Qingkai Shi, Xiangzhe Xu, Xiangyu Zhang
Abstract
Reverse engineering of protocol message formats is critical for many security applications. Mainstream techniques use dynamic analysis and inherit its low-coverage problem -- the inferred message formats only reflect the features of their inputs. To achieve high coverage, we choose to use static analysis to infer message formats from the implementation of protocol parsers. In this work, we focus on a class of extremely challenging protocols whose formats are described via constraint-enhanced regular expressions and parsed using finite-state machines. Such state machines are often implemented as complicated parsing loops, which are inherently difficult to analyze via conventional static analysis. Our new technique extracts a state machine by regarding each loop iteration as a state and the dependency between loop iterations as state transitions. To achieve high, i.e., path-sensitive, precision but avoid path explosion, the analysis is controlled to merge as many paths as possible based on carefully-designed rules. The evaluation results show that we can infer a state machine and, thus, the message formats, in five minutes with over 90% precision and recall, far better than state of the art. We also applied the state machines to enhance protocol fuzzers, which are improved by 20% to 230% in terms of coverage and detect ten more zero-days compared to baselines.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bee8bc0a-3111-4005-af07-5545d1e23c4dCited by top-tier papers6
- State Machine Mutation-based Testing Framework for Wireless Communication ProtocolsSyed Md. Mukit Rashid, Tianwei Wu, Kai Tu, Abdullah Al Ishtiaq et al.CCS 2024 · 4 citations
- Discovering Blind-Trust Vulnerabilities in PLC Binaries via State Machine RecoveryFangzhou Dong, Arvind S. Raj, Efrén López-Morales, Siyu Liu et al.NDSS 2026 · 1 citation
- DynPRE: Protocol Reverse Engineering via Dynamic InferenceZhengxiong Luo, Kai Liang, Yanyang Zhao, Feifan Wu et al.NDSS 2024
- Recovering Process Variables from Industrial Network Traffic via Search-Based OptimizationChuan Sheng, Shan Jiang, Jianming Zhao, Yu YaoCCS 2026
- Protocol Reverse Engineering via Deep Transfer LearningYanyang Zhao, Zhengxiong Luo, Wenlong Zhang, Feifan Wu et al.FSE 2026
Builds on12
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic et al.CCS 2018 · 428 citations
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo et al.NDSS 2018 · 311 citations
- Verified Models and Reference Implementations for the TLS 1.3 Standard CandidateKarthikeyan Bhargavan, Bruno Blanchet, Nadim KobeissiS&P 2017 · 233 citations
- Systematic Fuzzing and Testing of TLS LibrariesJuraj SomorovskyCCS 2016 · 136 citations
- Component-Based Formal Analysis of 5G-AKA: Channel Assumptions and Session ConfusionCas Cremers, Martin Dehnel-WildNDSS 2019 · 131 citations
Related papers
- Lifting Network Protocol Implementation to Precise Format Specification with Security ApplicationsQingkai Shi, Junyang Shao, Yapeng Ye, Mingwei Zheng et al.CCS 2023 · 15 citations
- BinPRE: Enhancing Field Inference in Binary Analysis Based Protocol Reverse EngineeringJiayi Jiang, Xiyuan Zhang, Chengcheng Wan, Haoyi Chen et al.CCS 2024 · 8 citations
- Generating Precise Format Specification for Network Protocols Through Adversarial LLM InteractionsHengdi Ye, Bing Shui, Jielun Wu, Yufan Zhou et al.USENIX Security 2026
- Breaking the Traffic Barrier: Unveiling Multi-Format of Protocols via Autonomous Program ExplorationDingzhao Xue, Yibo Qu, Bowen Jiang, Xin Chen et al.ASE 2025
- Stateful Greybox FuzzingJinsheng Ba, Marcel Böhme, Zahra Mirzamomen, Abhik RoychoudhuryUSENIX Security 2022
