MTA Fuzzer: A low-repetition rate Modbus TCP fuzzing method based on Transformer and Mutation Target Adaptation
Wenpeng Wang, Zhixiang Chen, Ziyang Zheng, Hui Wang, Junxing Luo · Computers & Security · 2024
The widespread application of industrial control systems has driven the development of industrial control protocols. However, traditional industrial control protocols suffer from issues such as a lack of security mechanisms, resulting in the existence of many dangerous vulnerabilities in industrial control systems . Fuzzing, as a commonly used technique for vulnerability discovery, has its own set of issues, including low testing efficiency, lack of adaptive capability, and high repetition rate of generated test cases . To solve the existing problems, we propose a low-repetition rate Modbus TCP fuzzing method based on Transformer and Mutation Target Adaptation. Firstly, the syntactic features of the industrial control protocol Modbus TCP are learned by using a simplified Transformer model. The model effectively reduces the training and generation time without decreasing the acceptance rate of test cases; Secondly, in the test case generation phase, in order to improve the mutation efficiency of test cases, the byte mutation probability adaptive strategy is introduced to replace the greedy strategy of Transformer. This strategy can dynamically adjust the mutation probability of each byte in the newly generated test cases , so as to improve the abnormal rate and reduce the repetition rate of test cases; Finally, the mutation results are selected by the mutation byte adaptive selection strategy, which not only improves the mutation adaptivity, but also maintains the diversity of mutations. The experimental results indicate that, compared to traditional methods, our approach has improved acceptance rates and abnormal rates by at least 10%. In comparison to AI-based fuzzing methods, our approach maintains a similar acceptance rate while increasing the abnormal rate by 3% to 25%.