Leveraging textual specifications for grammar-based fuzzing of network protocols

28Citations
Citations of this article
53Readers
Mendeley users who have this article in their library.

Abstract

Grammar-based fuzzing is a technique used to find software vulnerabilities by injecting well-formed inputs generated following rules that encode application semantics. Most grammar-based fuzzers for network protocols rely on human experts to manually specify these rules. In this work we study automated learning of protocol rules from textual specifications (i.e. RFCs). We evaluate the automatically extracted protocol rules by applying them to a state-of-the-art fuzzer for transport protocols and show that it leads to a smaller number of test cases while finding the same attacks as the system that uses manually specified rules.

Cite

CITATION STYLE

APA

Jero, S., Pacheco, M. L., Goldwasser, D., & Nita-Rotaru, C. (2019). Leveraging textual specifications for grammar-based fuzzing of network protocols. In 33rd AAAI Conference on Artificial Intelligence, AAAI 2019, 31st Innovative Applications of Artificial Intelligence Conference, IAAI 2019 and the 9th AAAI Symposium on Educational Advances in Artificial Intelligence, EAAI 2019 (pp. 9478–9483). AAAI Press. https://doi.org/10.1609/aaai.v33i01.33019478

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free