Batch Me If You Can: Coverage-Guided RPKI Fuzzing at Scale
Haya Schulmann, Niklas Vogel
摘要
The Resource Public Key Infrastructure (RPKI) has become essential to secure inter-domain routing. Despite its critical role, RPKI software remains largely untested beyond shallow parsing. Existing fuzzers, like AFL++ or libFuzzer, do not work well for RPKI as they assume a single, self-contained input per execution, while RPKI repositories contain hundreds of interdependent cryptographically linked objects. Existing fuzzers fail to handle this complexity and lack the ability for precise coverage attribution in multi-object repositories, breaking feedback-based exploration and thereby missing most severe vulnerabilities in RPKI validation.
In this paper, we overcome these limitations through novel fuzzing techniques, including continuous sampling and using functions as side-channels for per-object coverage attribution in large input repositories. We further show how parsing inputs to a labeled tree allows structural and semantic mutations while preserving cryptographic validity in mutated repositories. We implement our new techniques into a powerful fuzzing tool called CAT, combining non-sequential fuzzing with our template-agnostic ASN.1 mutation engine to achieve 66× throughput improvement over sequential fuzzing and exploring 24 -47% more unique code paths compared to libFuzzer and previous work.
Evaluating CAT on RPKI validators uncovered 21 previously unknown vulnerabilities with 8 CVEs already assigned (CVSS 7.5 -9.8). These include a buffer overflow, Denial-of-Service (DoS), and exploitable repository-poisoning logic flaws.
We open-source CAT to enable reproducibility, further research, and adaptation of our methods to other complex cryptography-based protocols such as DNSSEC and TLS.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper12
- Directed Greybox FuzzingMarcel Böhme, Van-Thuan Pham, Manh-Dung Nguyen, Abhik RoychoudhuryCCS 2017 · 被引用 836 次
- Systematic Fuzzing and Testing of TLS LibrariesJuraj SomorovskyCCS 2016 · 被引用 136 次
- A Longitudinal, End-to-End View of the DNSSEC EcosystemTaejoong Chung, Roland van Rijswijk-Deij, Balakrishnan Chandrasekaran, David R. Choffnes 等USENIX Security 2017 · 被引用 125 次
- Nyx: Greybox Hypervisor Fuzzing using Fast Snapshots and Affine TypesSergej Schumilo, Cornelius Aschermann, Ali Abbasi, Simon Wörner 等USENIX Security 2021 · 被引用 102 次
- Detecting critical bugs in SMT solvers using blackbox mutational fuzzingMuhammad Numair Mansur, Maria Christakis, Valentin Wüstholz, Fuyuan ZhangFSE 2020 · 被引用 51 次
相关 Paper
- The CURE to Vulnerabilities in RPKI ValidationDonika Mirdita, Haya Schulmann, Niklas Vogel, Michael WaidnerNDSS 2024
- The Fault in Our Drafts: Vulnerabilities in RPKI Specification and SoftwareOliver Jacobsen, Tobias Kirsch, Haya Schulmann, Niklas Vogel 等S&P 2026
- ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response FuzzingQifan Zhang, Xuesong Bai, Xiang Li, Haixin Duan 等USENIX Security 2024 · 被引用 13 次
- Pruning the Tree: Rethinking RPKI Architecture from the Ground upHaya Schulmann, Niklas VogelNDSS 2026 · 被引用 1 次
- SoK: An Introspective Analysis of RPKI SecurityDonika Mirdita, Haya Schulmann, Michael WaidnerUSENIX Security 2025
