LLM-Boofuzz: Generation-Based Black-Box Fuzzing for Network Protocols via LLMs

Tian Wang, Yuwei Li, Zulie Pan, Qian Chen, Zixiong Li, Yifan Zhang, Yi Shen, Miao Hu, Qiangpu Chen · Electronics · 2025

Identifying network protocol vulnerabilities is critical for cyberspace security. Generation-based black-box protocol fuzzing is widely used but faces challenges: over-reliance on manual protocol analysis and script writing, single-threaded fuzzing, and lack of dynamic fuzzing strategy optimization. To address these, we propose LLM-Boofuzz, a generation-based black-box protocol fuzzing framework via Large Language Models (LLMs). It leverages LLMs to parse real traffic to extract protocol information, guides LLMs to generate executable scripts with a repair mechanism, and enables multi-script iterative fuzzing via an LLM-based agent. Experiments show that LLM-Boofuzz outperforms state-of-the-art tools: it triggers all 15 test vulnerabilities (vs. 8/7/7 for Boofuzz/Snipuzz/AFLNet) and achieves an average 53.4% code line coverage on two protocol programs (vs. 30.65%/31.95%/41.65%), providing an efficient solution for network protocol fuzzing.

Read the paper · More papers on PaperTik