ICS Protocol Fuzzing: Coverage Guided Packet Crack and Generation
Zhengxiong Luo, Feilong Zuo, Yuheng Shen, Xun Jiao, Wanli Chang, Yu Jiang
Abstract
Industrial Control System (ICS) protocols play an essential role in building communications among system components. Recently, many severe vulnerabilities, such as Stuxnet and DragonFly, exposed in ICS protocols have affected a wide distribution of devices. Therefore, it is of vital importance to ensure their correctness. However, the vulnerability detection efficiency of traditional techniques such as fuzzing is challenged by the complexity and diversity of the protocols.
In this paper, we propose to equip the traditional protocol fuzzing with coverage-guided packet crack and generation. We collect the coverage information during the testing procedure, save those valuable packets that trigger new path coverage and crack them into pieces, based on which, we can construct higher-quality new packets for further testing. For evaluation, we build Peach * on top of Peach, which is one of the most widely used protocol fuzzers, and conduct experiments on several ICS protocols such as Modbus and DNP3. Results show that, compared with the original Peach, Peach * achieves the same code coverage and bug detection numbers at the speed of 1.2X-25X. It also gains final increase with 8.35%-36.84% more paths within 24 hours and has exposed 9 previously unknown vulnerabilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers9
- TCP-Fuzz: Detecting Memory and Semantic Bugs in TCP Stacks with FuzzingYonghao Zou, Jia-Ju Bai, Jielong Zhou, Jianfeng Tan et al.USENIX ATC 2021 · 53 citations
- Unicorn: detect runtime errors in time-series databases with hybrid input synthesisZhiyong Wu, Jie Liang, Mingzhe Wang, Chijin Zhou et al.ISSTA 2022 · 16 citations
- Logos: Log Guided Fuzzing for Protocol ImplementationsFeifan Wu, Zhengxiong Luo, Yanyang Zhao, Qingpeng Du et al.ISSTA 2024 · 13 citations
- SPFuzz: Stateful Path based Parallel Fuzzing for Protocols in Autonomous VehiclesJunze Yu, Zhengxiong Luo, Fangshangyuan Xia, Yanyang Zhao et al.DAC 2024 · 11 citations
- DynPRE: Protocol Reverse Engineering via Dynamic InferenceZhengxiong Luo, Kai Liang, Yanyang Zhao, Feifan Wu et al.NDSS 2024
Builds on2
Related papers
- Bleem: Packet Sequence Oriented Fuzzing for Protocol ImplementationsZhengxiong Luo, Junze Yu, Feilong Zuo, Jianzhong Liu et al.USENIX Security 2023
- CollAFL: Path Sensitive FuzzingShuitao Gan, Chao Zhang, Xiaojun Qin, Xuwen Tu et al.S&P 2018 · 426 citations
- PAVFuzz: State-Sensitive Fuzz Testing of Protocols in Autonomous VehiclesFeilong Zuo, Zhengxiong Luo, Junze Yu, Zhe Liu et al.DAC 2021 · 30 citations
- Prompt Fuzzing for Fuzz Driver GenerationYunlong Lyu, Yuxuan Xie, Peng Chen, Hao ChenCCS 2024 · 21 citations
- ICSQuartz: Scan Cycle-Aware and Vendor-Agnostic Fuzzing for Industrial Control SystemsCorban Villa, Constantine Doumanidis, Hithem Lamri, Prashant Hari Narayan Rajput et al.NDSS 2025
