Dynamic Differential Testing for Black-Box IPsec Implementations
Jiaxing Guo, Dongliang Zhao, Liying Zhang, Chunxiang Gu · 2024
Owing to the rapid development of information technology, numerous cryptographic protocols are used for secure communication and data protection. To ensure the security of cryptographic protocols in deployment and implementation, abundant protocol analysis and vulnerability detection methods have been proposed and applied. Among these approaches, differential testing is widely employed for security analysis and robustness evaluation of protocol software and hardware systems, playing a significant role in discovering and exploiting vulnerabilities. In this paper, we propose a novel differential fuzzing method, dedicated to searching for semantic issues in real-world black box protocol implementations. This method does not require program source code for the protocol but takes captured packets as input. It selects seeds from the seed library each time and executes mutations. Then, it simultaneously performs stateful interaction and testing with multiple protocol objects, and adds test cases that can trigger behavioral differences to the seed library, iteratively executing dynamic testing. We apply this method to analyze three IPsec implementations. The results show that compared to existing black-box differential testing tools, our method can improve the efficiency of discovering protocol behavior differences and flaws.