LLMUZZ: LLM-based seed optimization for black-box device fuzzing

Guangming Gao, Shuitao Gan, Xiaofeng Wang, Shengkai Zhu · 2024

As an increasing number of Internet of Things (IoT) devices are being deployed, the threat from vulnerabilities inside these devices is growing. Fuzzing is a primary method used for discovering vulnerabilities in IoT devices. The quality of the initial seeds and the seed mutation strategy are two crucial components of fuzzing that largely determine the effectiveness of the fuzzing process. However, owing to the diversity of IoT devices and the highly structured nature of inputs, designing universal seed generation and mutation strategies is extremely challenging. In this paper, we propose LLMUZZ, which is a large language model (LLM)-based black-box fuzzing approach for IoT devices. Specifically, we employ prompt engineering techniques in few-shot learning, using HTML form data from frontend files and an example HTTP request as inputs to LLMs to generate initial seeds. Then, we input the requests to be mutated into LLMs to identify the fields requiring mutation, thereby assisting in the seed mutation process. This approach ensures that the mutated seeds remain valid. Additionally, static analysis methods are utilized to discover hidden keywords within the firmware, thereby further expanding the initial seeds. In the experiments, we implement a prototype of LLMUZZ and evaluate it on 8 different IoT devices. A total of 16 previously unknown vulnerabilities are found, for which we have received 4 CVEs; the remaining vulnerabilities still under review, demonstrating that LLMUZZ has a strong capacity for vulnerability discovery.

Read the paper · More papers on PaperTik