FitM: Binary-Only Coverage-Guided Fuzzing for Stateful Network Protocols

Dominik Maier, Otto Bittner, Julian Beier, Marc Munier · 2022

Common network protocol fuzzers use complex grammars for fuzzing clients and servers with a (semi-)correct input for the server.In contrast, feedback-guided fuzzers learn their way through the target and discover valid input on their own.However, their random mutations frequently destroy all stateful progress when they clobber necessary early communication packets.Deeper into the communication, it gets increasingly unlikely for a coverage-guided fuzzer like AFL ++ to explore later stages in client-server communications.Even combinations of both approaches require considerable manual effort for seed and grammar generation, even though sound input sources for servers already exist: their respective clients.In this paper, we present FitM, the Fuzzer in the Middle, a coverage-guided fuzzer for complex client-server interactions.To overcome issues of the State-of-the-Art, FitM emulates the network layer between client and host, fuzzing both server and client at the same time.Once FitM reaches a new step in a protocol, it uses CRIU's userspace snapshots to checkpoint client and server to continue fuzzing this step in the protocol directly.The combination of domain knowledge gathered from the proper peer, with coverage-guided snapshot fuzzing, allows FitM to explore the target extensively.At the same time, FitM reruns earlier snapshots in a probabilistic manner, effectively fuzzing the state space.We show that FitM can reach greater depth than previous tools by comparing found basic blocks, the number of client-server interactions, and execution speed.Based on AFL ++ 's qemuafl, FitM is an effective and low-effort binary-only fuzzer for network protocols, that uncovered overflows in the GNU Inetutils FTP client with minimum effort.Index Terms-snapshot, stateful, protocol, fuzzing fuzzing ineffective.The typical approach to fuzz complex network services is to write a grammar by hand and pass input over slow sockets.We show that we can get around writing grammars and manual harnesses, as we already have the domain knowledge as part of the client-server communication.With FitM, the Fuzzer in the Middle, we present a qemuaflbased [1] coverage-guided fuzzer that fuzzes client and server at the same time.FitM-qemu uses network layer emulation, able to handle synchronous and asynchronous network interactions.The networking syscall hooks pass input through shared maps instead of sockets, increasing the speed many-fold.For each potential new state, meaning a new recv→send→recv transition, we create persistent snapshots using CRIU [2].Persistent snapshots allow us to stop and continue fuzzing of target states at any time and even replay snapshots with strace, or other debugging features enabled.Additionally, we implement waypoints and smart state creation -based on new socket outputs and unique AFL maps -and fuzz each state transition independently.FitM is the first tool to use persistent snapshots of userspace processes.In comparison to hypervisor-based solutions [3]-[5] userspace fuzzing works without the need for additional introspection into the host system, is simpler, and can potentially reach faster speeds, without the need for expensive hypervisor interactions [6].More important than the snapshotting itself, however, is our answer to: when to snapshot, how to schedule, and how to automatically explore stateful protocols.In this paper, we explain how we tackle these challenges.Our contributions are as follows:• We design, develop and open-source FitM, a novel coverage-guided Fuzzer in the Middle for binary-only targets.• We propose a scheme of state snapshots and stateful fuzzing.• We extend qemuafl through a fuzzer-aware network emulation layer, taking away the need for kernel interactions.It emulates both synchronous and asynchronous sockets.• We evaluate FitM against AFLNet, a State-of-the-Art coverage-guided fuzzer for network protocols, and show promising results.• We find a previously unknown buffer-overflow in GNU Inetutils' FTP client by fuzzing the FTP Server and running it on other networking servers and clients.

Read the paper · More papers on PaperTik