USENIX Security2023Top-tier venue
Intender: Fuzzing Intent-Based Networking with Intent-State Transition Guidance
Jiwon Kim, Benjamin E. Ujcich, Dave Tian
Abstract
Intent-based networking (IBN) abstracts network configuration complexity from network operators by focusing on what operators want the network to do rather than how such configuration should be implemented. While such abstraction eases network management challenges, little attention to date has focused on IBN's new security concerns that adversely impact an entire network's correct operation. To motivate the prevalence of such security concerns, we systematize IBN's security challenges by studying existing bug reports from a representative IBN implementation within the ONOS network operating system. We find that 61% of IBN-related bugs are semantic bugs that are challenging, if not impossible, to detect efficiently by state-of-the-art vulnerability discovery tools. To tackle existing limitations, we present INTENDER, the first semantically-aware fuzzing framework for IBN. IN-TENDER leverages network topology information and intentoperation dependencies (IOD) to efficiently generate testing inputs. INTENDER introduces a new feedback mechanism, intent-state transition guidance (ISTG), which traces the history of transitions in intent states. We evaluate INTENDER using ONOS and find 12 bugs, 11 of which were CVE-assigned security-critical vulnerabilities affecting network-wide control plane integrity and availability. Compared to state-of-theart fuzzing tools AFL, Jazzer, Zest, and PAZZ, INTENDER generates up to 78.7× more valid fuzzing input, achieves up to 2.2× better coverage, and detects up to 82.6× more unique errors. INTENDER with IOD reduces 73.02% of redundant operations and spends 10.74% more time on valid operations. INTENDER with ISTG leads to 1.8× more intent-state transitions compared to code-coverage guidance.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c49d7b31-721d-47a8-8858-d5c68c4d4fe5Cited by top-tier papers4
- Manipulating OpenFlow Link Discovery Packet Forwarding for Topology PoisoningMingming Chen, Thomas La Porta, Teryl Taylor, Frederico Araujo et al.CCS 2024 · 8 citations
- Exploiting Temporal Vulnerabilities for Unauthorized Access in Intent-based NetworkingBen Weintraub, Jiwon Kim, Ran Tao, Cristina Nita-Rotaru et al.CCS 2024 · 3 citations
- NCFuzz: Configuration-Guided Network Service FuzzingXuesong Bai, Hengkai Ye, Shenghan Zheng, Fenglu Zhang et al.ISSTA 2026
- When Address Learning Goes Wrong: Inducing Forwarding Loops and DoS Amplification in SDNDezhang Kong, Yilun Zhang, Zekun Xie, Ningpeng Zheng et al.USENIX Security 2026
Builds on16
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 836 citations
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang et al.USENIX Security 2018 · 537 citations
- SAVIOR: Towards Bug-Driven Hybrid TestingYaohui Chen, Peng Li, Jun Xu, Shengjian Guo et al.S&P 2020 · 186 citations
Related papers
- SemFuzz: A Semantics-Aware Fuzzing Framework for Network Protocol ImplementationsYanbang Sun, Quan Luo, Yuelin Wang, Qian Chen et al.WWW 2026
- AudiSDN: Automated Detection of Network Policy Inconsistencies in Software-Defined NetworksSeungsoo Lee, Seungwon Woo, Jinwoo Kim, Vinod Yegneswaran et al.INFOCOM 2020 · 13 citations
- DELTA: A Security Assessment Framework for Software-Defined NetworksSeungsoo Lee, Changhoon Yoon, Chanhee Lee, Seungwon Shin et al.NDSS 2017 · 128 citations
- TCP-Fuzz: Detecting Memory and Semantic Bugs in TCP Stacks with FuzzingYonghao Zou, Jia-Ju Bai, Jielong Zhou, Jianfeng Tan et al.USENIX ATC 2021 · 53 citations
- Fizzle: A Framework for Deterministic and Reproducible Network FuzzingNathaniel Bennett, Tyler Tucker, Carson Stillman, William Enck et al.S&P 2026 · 1 citation
