DomFuzz: Dominator-Based Directed Gray-Box Fuzzing for ICPSs

Guangquan Xu, Guohua Xin, Yao Zhang, Xibin Zhao, Shouling Ji, Hao Peng, Tao Luo, Limengzi Yuan · IEEE Network · 2025

The integration of computing, network, and physical devices across cloud and fog platforms has significantly increased the coordination complexity of industrial cyber-physical systems (ICPSs). This complexity stems from managing numerous heterogeneous components, making it increasingly challenging to identify security vulnerabilities. To address these issues, it is crucial to rapidly test high-risk components and support timely recovery of industrial processes. In this article, we propose DomFuzz, a dominator-based directed grey-box fuzzing method that enables precise vulnerability distance calculations for critical infrastructure components. Specifically, to fairly distribute computing resources to testing inputs, we use a dominator-based power schedule for the first time. Additionally, we adjust the transition time between testing phases dynamically to improve vulnerability identification efficiency in ICPSs. Furthermore, we implement a lightweight patching method capable of addressing incomplete call graphs in the presence of proof-of-concept code, effectively resolving the complexity challenges inherent in ICPSs. Our evaluation shows that DomFuzz outperforms AFL, AFLGo, and WindRanger. DomFuzz finds 77.06 percent of the vulnerabilities in LAVA-M, while AFLGo and AFL find only 0.41 percent on average. Remarkably, DomFuzz significantly reduces the time-to-exposure (TTE) of vulnerabilities in ICPSs, identifying vulnerabilities on average 2.09x faster than AFLGo and 1.57 x faster than WindRanger.

Read the paper · More papers on PaperTik