SulleyEX: A fuzzer for stateful network protocol

Rui Ma*, Tianbao Zhu, Changzhen Hu, Chun Shan, Xiaolin Zhao

*此作品的通讯作者

科研成果: 书/报告/会议事项章节会议稿件同行评审

4 引用 (Scopus)

摘要

Fuzzing has become one of the most important technologies in the field of network security, and fuzzer also has become an important tool for discovering network vulnerabilities. But for the stateful network protocol fuzzing, most of fuzzers could not effectively cover the state trajectory, and not achieve a good automation. Aiming at the above issues, this paper designs a fuzzer named SulleyEX based on the open source project Sulley. Firstly, the SulleyEX uses finite-state machine to describe the state trajectory of stateful network protocol and further generates sessions automatically. That dramatically enhances the automation of Sulley session management module. In order to improve the optional ability of the fuzzer, the SulleyEX could automatically extract the protocol format based on Sulley’s data presentation module as well as provide an interface to custom fuzz testing data generation algorithm. Comparing with the traditional Sulley, the experimental results highlight that the SulleyEX could successfully discover the same vulnerability, while the SulleyEX achieves higher automation.

源语言英语
主期刊名Network and System Security - 11th International Conference, NSS 2017, Proceedings
编辑Zheng Yan, Refik Molva, Wojciech Mazurczyk, Raimo Kantola
出版商Springer Verlag
359-372
页数14
ISBN(印刷版)9783319647005
DOI
出版状态已出版 - 2017
活动11th International Conference on Network and System Security, NSS 2017 - Helsinki, 芬兰
期限: 21 8月 201723 8月 2017

出版系列

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
10394 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议11th International Conference on Network and System Security, NSS 2017
国家/地区芬兰
Helsinki
时期21/08/1723/08/17

指纹

探究 'SulleyEX: A fuzzer for stateful network protocol' 的科研主题。它们共同构成独一无二的指纹。

引用此