AFLNETGO:A Directed Fuzzer for Stateful Network Protocol Implementation

Xiaofeng Tang, Yongjun Wang, Fangliang Xu · 2023

Directed Gray Box Fuzzers (DGF) are widely used for patch testing, bug reproduction, and special bug detection. Despite these successes, not all software can benefit from DGF, such as stateful network protocol implementations. In a stateful network protocol implementation, the target is unlocked only in certain states. Running in a state where the target cannot be unlocked wastes a lot of resources. In this article, we propose AFLNETGO, a directed greybox fuzzing scheme for stateful network protocol implementations. AFLNETGO automatically and dynamically identifies the state of the network protocol implementations and the target state at run time. AFLNETGO assigns energy to a state in a state transition graph based on the probability of that state transitioning to a target state, allowing fuzzer processing to focus more on the states of possible execution targets. For comparison, we have implemented the directed method of AFLGo on AFLNET and called it AFLGo plus. We fuzzed random targets in two popular stateful network protocol implementations: LIVE555 and Dcmqrscp. The evaluation results show that AFLNETGO has better directed performance than AFLGo plus for targets.

Read the paper · More papers on PaperTik