RPFUZZ: Efficient network service fuzzing via pruning redundant mutation

Wenfeng Lin, Fangliang Xu, Zhiyuan Jiang, Gang Yang, Zhiwei Li, Chaojing Tang · Computers & Security · 2025

Coverage-guided fuzzing (CGF) has proven its outstanding performance on vulnerability detection. However, existing approaches exhibit limitations when handling network service. Restricted by network I/O duration and chronology, long packet sequences crafted by fuzzers incur a substantial execution cost. Test cases with such non-coverage-improving mutations (i.e. redundant mutation) can significantly reduce fuzzing throughput and compromise vulnerability discovery. To address this issue, we propose RPFUZZ, a novel network fuzzing framework designed to systematically reduce redundant mutations: (1) We propose redundant mutation pruning for network service fuzzing. By early terminating redundant mutations’ execution, RPFUZZ can achieve higher throughput. (2) To detect redundant mutation, we propose redundant mutation oracle. This oracle dynamically judges whether a test case is redundant according to current code coverage and value of service-related variables (SRVs). (3)To identify SRVs, we propose an integrated approach combining dynamic call stack analysis with static value-flow graph (VFG) analysis. To evaluate the performance of RPFUZZ, we implement a prototype on top of NYX-NET. We conduct thorough experiments on ProFuzzBench, a benchmark that consists of 12 real-world network services. The results indicate that RPFUZZ achieves over 185% improvement in throughput and 1.02% rise in code coverage compared with NYX-NET. Besides, RPFUZZ has successfully uncovered 1753 unique crashes across 6 network services, including an unreported vulnerability (assigned to CVE-2024-57392) in ProFTPD, which has been well tested. • We propose redundant mutation pruning technique for network service fuzzing. By pruning mutated suffix packet sequence which is non-coverage-improving, network service fuzzer can achieve higher throughout. This is achieved by redundant mutation oracle, which leverage code coverage and identified service-related variables’ (SRVs) value to decide whether continuing current execution is advisable. • To precisely identify SRVs in network services, we propose an identification method combining with call stack analysis and value-flow graph analysis. This method is based on SRV’s programming features, which can be applied in various network service. • Based on technique above, We implement RPFUZZ. RPFUZZ achieved more than 185.92% (average 56.39%) throughput enhancement over NYX-NET, while improving maximum 4.27% code coverage (average +1.02%). It successfully identified 1753 unique crashes across 6 targets without ASAN and a buffer overflow vulnerability in ProFTPD (assigned CVE-2024-57392).

Read the paper · More papers on PaperTik