An ASN.1 UPER Encoding Based Fuzzing Method for Radio Resource Control Protocol

Rui Wang, Donglan Liu, Xin Liu, Lei Ma, Hao Zhang, Yong Wang, Zhenghao Li, Fangzhe Zhang, Lili Sun · 2023

Fuzz testing is one of the most direct and effective automated vulnerability mining methods. The latest approach in vulnerability mining related to protocols specified based on ASN.1 such as the Radio Resource Control (RRC) protocol is to compile a large number of manually constructed malformed ASN.1 schema and then generate messages based on these schemas thus fuzz testing the protocol. However, this approach is relatively simple and the seed construction way is not effective enough, which can affect the efficiency and effectiveness of the fuzz testing. Therefore, some works proposed to implement fuzz testing by extracting an abstract syntax tree (AST), which mutates messages on the intermediate format to trigger deeper logic. Inspired by this, this paper proposes a fuzz testing method for RRC protocols based on ASN.1 UPER encoding details, extracting the ASN.1 syntax tree at the intermediate level and placing the mutation after compiling the ASN.1 schema. This reduces the mutation message construction time and space on the one hand, and enables the mutation to cover more fields on the other.

Read the paper · More papers on PaperTik