{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,1]],"date-time":"2025-10-01T15:44:26Z","timestamp":1759333466175,"version":"build-2065373602"},"publisher-location":"Cham","reference-count":45,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031944543"},{"type":"electronic","value":"9783031944550"}],"license":[{"start":{"date-parts":[[2025,9,5]],"date-time":"2025-09-05T00:00:00Z","timestamp":1757030400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,9,5]],"date-time":"2025-09-05T00:00:00Z","timestamp":1757030400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-031-94455-0_6","type":"book-chapter","created":{"date-parts":[[2025,9,4]],"date-time":"2025-09-04T09:24:23Z","timestamp":1756977863000},"page":"113-135","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["FISFuzzer: A Grey-Box Protocol Fuzzer Based on\u00a0Field Inference and\u00a0Scheduling"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-9732-2922","authenticated-orcid":false,"given":"Hao","family":"Pan","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-9714-1752","authenticated-orcid":false,"given":"Xiangpu","family":"Song","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-3892-8096","authenticated-orcid":false,"given":"Honglin","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-7648-279X","authenticated-orcid":false,"given":"Kai","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3367-0951","authenticated-orcid":false,"given":"Shanqing","family":"Guo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8824-1356","authenticated-orcid":false,"given":"Xing","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,9,5]]},"reference":[{"key":"6_CR1","unstructured":"American fuzzy lop. https:\/\/lcamtuf.coredump.cx\/afl\/. Accessed 3 Nov 2022"},{"key":"6_CR2","doi-asserted-by":"crossref","unstructured":"Pham, V.-T., B\u00f6hme, M., Roychoudhury, A.: AFLNet: a greybox fuzzer for network protocols. In: 2020 IEEE 13th International Conference on Software Testing, Validation and Verification (ICST), pp. 460\u2013465. IEEE (2020)","DOI":"10.1109\/ICST46399.2020.00062"},{"key":"6_CR3","unstructured":"Andronidis, A., Cadar, C.: Snapfuzz: an efficient fuzzing framework for network applications. arXiv preprint arXiv:2201.04048 (2022)"},{"key":"6_CR4","doi-asserted-by":"crossref","unstructured":"Fioraldi, A., D\u2019Elia, D.C., Coppa, E.: Weizz: automatic grey-box fuzzing for structured binary formats. In: Proceedings of the 29th ACM SIGSOFT International Symposium on Software Testing and Analysis, pp. 1\u201313 (2020)","DOI":"10.1145\/3395363.3397372"},{"key":"6_CR5","unstructured":"Fiterau-Brostean, P., Jonsson, B., Merget, R., De\u00a0Ruiter, J., Sagonas, K., Somorovsky, J.: Analysis of DTLS implementations using protocol state fuzzing. In :29th USENIX Security Symposium (USENIX Security 20), pp. 2523\u20132540 (2020)"},{"key":"6_CR6","unstructured":"De\u00a0Ruiter, J., Poll, E.: Protocol state fuzzing of TLS implementations. In: 24th USENIX Security Symposium (USENIX Security 15), pp. 193\u2013206 (2015)"},{"key":"6_CR7","doi-asserted-by":"crossref","unstructured":"Han, X., Wen, Q., Zhang, Z.: A mutation-based fuzz testing approach for network protocol vulnerability detection. In: Proceedings of 2012 2nd International Conference on Computer Science and Network Technology, pp. 1018\u20131022. IEEE (2012)","DOI":"10.1109\/ICCSNT.2012.6526099"},{"key":"6_CR8","doi-asserted-by":"crossref","unstructured":"Li, H., Wang, S., Zhang, B., Shuai, B., Tang, C.: Network protocol security testing based on fuzz. In: 2015 4th International Conference on Computer Science and Network Technology (ICCSNT), vol. 1, pp. 955\u2013958. IEEE (2015)","DOI":"10.1109\/ICCSNT.2015.7490895"},{"key":"6_CR9","doi-asserted-by":"crossref","unstructured":"Cui, B., Feng, S., Xiao, Q., Li, M.: Detection of LTE protocol based on format fuzz. In: 2015 10th International Conference on Broadband and Wireless Computing, Communication and Applications (BWCCA), pp. 187\u2013192. IEEE (2015)","DOI":"10.1109\/BWCCA.2015.42"},{"key":"6_CR10","unstructured":"Luo, Z., et al.: BLEEM: packet sequence oriented fuzzing for protocol implementations. In: 32nd USENIX Security Symposium (USENIX Security 23), pp. 4481\u20134498 (2023)"},{"key":"6_CR11","doi-asserted-by":"crossref","unstructured":"L\u00e1di, G., Butty\u00e1n, L., Holczer, T.: Message format and field semantics inference for binary protocols using recorded network traffic. In: 2018 26th International Conference on Software, Telecommunications and Computer Networks (SoftCOM), pp. 1\u20136. IEEE (2018)","DOI":"10.23919\/SOFTCOM.2018.8555813"},{"key":"6_CR12","doi-asserted-by":"crossref","unstructured":"Zhang, Z., Wen, Q.-Y., Tang, W.: An efficient mutation-based fuzz testing approach for detecting flaws of network protocol. In: 2012 International Conference on Computer Science and Service System, pp. 814\u2013817. IEEE (2012)","DOI":"10.1109\/CSSS.2012.208"},{"key":"6_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"892","DOI":"10.1007\/978-3-319-72359-4_56","volume-title":"Information Security Practice and Experience","author":"J Cai","year":"2017","unstructured":"Cai, J., Luo, J.-Z., Ruan, J., Liu, Y.: Toward fuzz test based on protocol reverse engineering. In: Liu, J.K., Samarati, P. (eds.) ISPEC 2017. LNCS, vol. 10701, pp. 892\u2013897. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-72359-4_56"},{"key":"6_CR14","unstructured":"Ji, S., et al.: AIFORE: smart fuzzing based on automatic input format reverse engineering. In: 32nd USENIX Security Symposium (USENIX Security 23), pp. 4967\u20134984 (2023)"},{"key":"6_CR15","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.cose.2013.02.001","volume":"36","author":"SY Kim","year":"2013","unstructured":"Kim, S.Y., Cha, S., Bae, D.-H.: Automatic and lightweight grammar generation for fuzz testing. Comput. Secur. 36, 1\u201311 (2013)","journal-title":"Comput. Secur."},{"issue":"3","key":"6_CR16","doi-asserted-by":"publisher","first-page":"645","DOI":"10.4304\/jsw.8.3.645-651","volume":"8","author":"F Pan","year":"2013","unstructured":"Pan, F., Hou, Y., Hong, Z., Lifa, W., Lai, H.: Efficient model-based fuzz testing using higher-order attribute grammars. J. Softw. 8(3), 645\u2013651 (2013)","journal-title":"J. Softw."},{"issue":"9","key":"6_CR17","first-page":"1980","volume":"47","author":"V-T Pham","year":"2019","unstructured":"Pham, V.-T., B\u00f6hme, M., Santosa, A.E., R\u0103zvan C\u0103ciulescu, A., Roychoudhury, A.: Smart greybox fuzzing. IEEE Trans. Softw. Eng. 47(9), 1980\u20131997 (2019)","journal-title":"IEEE Trans. Softw. Eng."},{"key":"6_CR18","doi-asserted-by":"publisher","first-page":"1497","DOI":"10.1007\/s00521-020-05039-7","volume":"33","author":"MZ Nasrabadi","year":"2021","unstructured":"Nasrabadi, M.Z., Parsa, S., Kalaee, A.: Format-aware learn &fuzz: deep test data generation for efficient fuzzing. Neural Comput. Appl. 33, 1497\u20131513 (2021)","journal-title":"Neural Comput. Appl."},{"key":"6_CR19","doi-asserted-by":"crossref","unstructured":"Shi, Q., Shao, J., Ye, Y., Zheng, M., Zhang, X.: Lifting network protocol implementation to precise format specification with security applications. arXiv preprint arXiv:2305.11781 (2023)","DOI":"10.1145\/3576915.3616614"},{"key":"6_CR20","unstructured":"Moore, P., Herriot, R.G., Wenn, J.C., Butler, S.: Internet printing protocol\/1.1: encoding and transport. RFC 2910 (2000)"},{"key":"6_CR21","unstructured":"Isaacson, S.A., Hastings, T.N., Powell, P., Herriot, DeBry, R.G.: Internet printing protocol\/1.1: model and semantics. RFC 2911 (2000)"},{"key":"6_CR22","unstructured":"ftp. https:\/\/github.com\/chengshiwen\/ftp. Accessed 25 Dec 2023"},{"key":"6_CR23","unstructured":"ftp. https:\/\/github.com\/Siim\/ftp\/issues\/6. Accessed on 25 Dec 2023"},{"key":"6_CR24","unstructured":"DHCPServer. https:\/\/github.com\/crossbowerbt\/dhcpserver. Accessed 25 Dec 2023"},{"key":"6_CR25","unstructured":"Kleber, S., Kopp, H., Kargl, F.: NEMESYS: network message syntax reverse engineering by analysis of the intrinsic structure of individual messages. In: 12th USENIX Workshop on Offensive Technologies (WOOT 18) (2018)"},{"key":"6_CR26","doi-asserted-by":"crossref","unstructured":"Ye, Y., Zhang, Z., Wang, F., Zhang, X., Xu, D.: Probabilistic network protocol reverse engineering from message traces. In: NDSS, Netplier (2021)","DOI":"10.14722\/ndss.2021.24531"},{"key":"6_CR27","doi-asserted-by":"crossref","unstructured":"Chandler, J., Wick, A., Fisher, K.: BinaryInferno: a semantic-driven approach to field inference for binary message formats. In: NDSS (2023)","DOI":"10.14722\/ndss.2023.23131"},{"key":"6_CR28","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1016\/j.comcom.2016.02.015","volume":"84","author":"I Bermudez","year":"2016","unstructured":"Bermudez, I., Tongaonkar, A., Iliofotou, M., Mellia, M., Munaf\u00f2, M.M.: Towards automatic protocol field inference. Comput. Commun. 84, 40\u201351 (2016)","journal-title":"Comput. Commun."},{"key":"6_CR29","unstructured":"Yun, I., Lee, S., Xu, M., Jang, Y., Kim, T.: QSYM: a practical concolic execution engine tailored for hybrid fuzzing. In: 27th USENIX Security Symposium (USENIX Security 18), pp. 745\u2013761 (2018)"},{"key":"6_CR30","doi-asserted-by":"crossref","unstructured":"Chen, P., Chen, H.: Angora: efficient fuzzing by principled search. In: 2018 IEEE Symposium on Security and Privacy (SP), pp. 711\u2013725. IEEE (2018)","DOI":"10.1109\/SP.2018.00046"},{"key":"6_CR31","doi-asserted-by":"crossref","unstructured":"Jie, L., et al.: PATA: fuzzing with path aware taint analysis. In: 2022 IEEE Symposium on Security and Privacy (SP), pp. 1\u201317. IEEE (2022)","DOI":"10.1109\/SP46214.2022.9833594"},{"key":"6_CR32","doi-asserted-by":"crossref","unstructured":"B\u00f6hme, M., Man\u00e8s, V.J.M., Cha, S.K.: Boosting fuzzer efficiency: an information theoretic perspective. In: Proceedings of the 28th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, pp. 678\u2013689 (2020)","DOI":"10.1145\/3368089.3409748"},{"key":"6_CR33","unstructured":"Zhang, Y., Pang, C., Portokalidis, G., Triandopoulos, N., Xu, J.: Debloating address sanitizer. In: 31st USENIX Security Symposium (USENIX Security 22), pp. 4345\u20134363 (2022)"},{"key":"6_CR34","doi-asserted-by":"crossref","unstructured":"You, W., et al.: Profuzzer: on-the-fly input type probing for better zero-day vulnerability discovery. In: 2019 IEEE Symposium on Security and Privacy (SP), pp. 769\u2013786. IEEE (2019)","DOI":"10.1109\/SP.2019.00057"},{"key":"6_CR35","unstructured":"Preeny. https:\/\/github.com\/zardus\/preeny. Accessed 20 Dec 2023"},{"key":"6_CR36","doi-asserted-by":"crossref","unstructured":"Natella, R., Pham, V.-T.: Profuzzbench: a benchmark for stateful protocol fuzzing. In: Proceedings of the 30th ACM SIGSOFT International Symposium on Software Testing and Analysis, pp. 662\u2013665 (2021)","DOI":"10.1145\/3460319.3469077"},{"key":"6_CR37","unstructured":"Li, Y., et\u00a0al.: UNIFUZZ: a holistic and pragmatic metrics-driven platform for evaluating fuzzers. In: 30th USENIX Security Symposium (USENIX Security 21), pp. 2777\u20132794 (2021)"},{"key":"6_CR38","series-title":"Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","doi-asserted-by":"publisher","first-page":"330","DOI":"10.1007\/978-3-319-28865-9_18","volume-title":"Security and Privacy in Communication Networks","author":"H Gascon","year":"2015","unstructured":"Gascon, H., Wressnegger, C., Yamaguchi, F., Arp, D., Rieck, K.: Pulsar: stateful black-box fuzzing of proprietary network protocols. In: Thuraisingham, B., Wang, X.F., Yegneswaran, V. (eds.) SecureComm 2015. LNICSSITE, vol. 164, pp. 330\u2013347. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-28865-9_18"},{"key":"6_CR39","doi-asserted-by":"crossref","unstructured":"Feng, X., et al. Snipuzz: black-box fuzzing of IoT firmware via message snippet inference. In: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, pp. 337\u2013350 (2021)","DOI":"10.1145\/3460120.3484543"},{"key":"6_CR40","doi-asserted-by":"crossref","unstructured":"Peach fuzzer. https:\/\/github.com\/MozillaSecurity\/peach. Accessed 20 Dec 2023","DOI":"10.1215\/15476715-10829087"},{"key":"6_CR41","doi-asserted-by":"crossref","unstructured":"Schumilo, S., Aschermann, C., Jemmett, A., Abbasi, A., Holz, T.: Nyx-net: network fuzzing with incremental snapshots. In: Proceedings of the Seventeenth European Conference on Computer Systems, pp. 166\u2013180 (2022)","DOI":"10.1145\/3492321.3519591"},{"key":"6_CR42","doi-asserted-by":"crossref","unstructured":"Introducing Whitebox Fuzzing: Sage: whitebox fuzzing for security testing. SAGE 10(1) (2012)","DOI":"10.1145\/2090147.2094081"},{"key":"6_CR43","doi-asserted-by":"crossref","unstructured":"Godefroid, P., Kiezun, A., Levin, M.Y.: Grammar-based Whitebox fuzzing. In: Proceedings of the 29th ACM SIGPLAN Conference on Programming Language Design and Implementation, pp. 206\u2013215 (2008)","DOI":"10.1145\/1375581.1375607"},{"key":"6_CR44","doi-asserted-by":"crossref","unstructured":"Ganesh, V., Leek, T., Rinard, M.: Taint-based directed Whitebox fuzzing. In: 2009 IEEE 31st International Conference on Software Engineering, pp. 474\u2013484. IEEE (2009)","DOI":"10.1109\/ICSE.2009.5070546"},{"key":"6_CR45","doi-asserted-by":"crossref","unstructured":"Cho, M., Kim, S., Kwon, T.: Intriguer: field-level constraint solving for hybrid fuzzing. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, pp. 515\u2013530 (2019)","DOI":"10.1145\/3319535.3354249"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Security and Privacy in Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-94455-0_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,30]],"date-time":"2025-09-30T22:16:25Z","timestamp":1759270585000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-94455-0_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,5]]},"ISBN":["9783031944543","9783031944550"],"references-count":45,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-94455-0_6","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2025,9,5]]},"assertion":[{"value":"5 September 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SecureComm","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Security and Privacy in Communication Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Dubai","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"United Arab Emirates","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28 October 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 October 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"securecomm2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/securecomm.eai-conferences.org\/2024\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}