{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,15]],"date-time":"2026-08-15T08:27:05Z","timestamp":1786782425165,"version":"build-2736575974"},"reference-count":28,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computers &amp; Security"],"published-print":{"date-parts":[[2026,11]]},"DOI":"10.1016\/j.cose.2026.105055","type":"journal-article","created":{"date-parts":[[2026,7,13]],"date-time":"2026-07-13T23:02:49Z","timestamp":1783983769000},"page":"105055","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["RSAFL: Guide protocol fuzzing by runtime state data"],"prefix":"10.1016","volume":"170","author":[{"given":"Shuai","family":"Zhang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6890-6077","authenticated-orcid":false,"given":"Zhi","family":"Yang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2087-2853","authenticated-orcid":false,"given":"Shuyuan","family":"Jin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuanbo","family":"Guo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guangyang","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weiquan","family":"Sang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.cose.2026.105055_b1","series-title":"2024 IEEE Symposium on Security and Privacy","first-page":"1481","article-title":"DY fuzzing: formal dolev-yao models meet cryptographic protocol fuzz testing","author":"Ammann","year":"2024"},{"key":"10.1016\/j.cose.2026.105055_b2","doi-asserted-by":"crossref","unstructured":"Antunes, J., Neves, N., 2011. Automatically complementing protocol specifications from network traces. In: Proceedings of the 13th European Workshop on Dependable Computing. pp. 87\u201392.","DOI":"10.1145\/1978582.1978601"},{"key":"10.1016\/j.cose.2026.105055_b3","series-title":"31st USENIX Security Symposium","first-page":"3255","article-title":"Stateful greybox fuzzing","author":"Ba","year":"2022"},{"key":"10.1016\/j.cose.2026.105055_b4","series-title":"Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security","first-page":"750","article-title":"No peer, no cry: Network application fuzzing via fault injection","author":"Bars","year":"2024"},{"key":"10.1016\/j.cose.2026.105055_b5","series-title":"Proceedings of the 2014 Conference on Internet Measurement Conference","first-page":"475","article-title":"The matter of heartbleed","author":"Durumeric","year":"2014"},{"key":"10.1016\/j.cose.2026.105055_b6","series-title":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security","first-page":"337","article-title":"Snipuzz: Black-box fuzzing of iot firmware via message snippet inference","author":"Feng","year":"2021"},{"key":"10.1016\/j.cose.2026.105055_b7","article-title":"Automated whitebox fuzz testing","author":"Godefroid","year":"2008","journal-title":"DBLP"},{"key":"10.1016\/j.cose.2026.105055_b8","doi-asserted-by":"crossref","unstructured":"Hazimeh, A., Xu, D., Liu, Q., Wang, Y., Payer, M., 2024. Tango: Extracting Higher-Order Feedback through State Inference. In: Proceedings of the 27th International Symposium on Research in Attacks, Intrusions and Defenses. pp. 403\u2013418.","DOI":"10.1145\/3678890.3678908"},{"key":"10.1016\/j.cose.2026.105055_b9","series-title":"Communications and Multimedia Security Issues of the New Century: IFIP TC6\/TC11 Fifth Joint Working Conference on Communications and Multimedia Security (CMS\u201901) May 21\u201322, 2001, Darmstadt, Germany","first-page":"173","article-title":"Software security assessment through specification mutations and fault injection","author":"Kaksonen","year":"2001"},{"key":"10.1016\/j.cose.2026.105055_b10","doi-asserted-by":"crossref","unstructured":"Kaplan, I., Even, R., Klein, A., 2025. You Can Rand but You Can\u2019t Hide: A Holistic Security Analysis of Google Fuchsia\u2019s (and gVisor\u2019s) Network Stack. In: Proceedings of the 31st Annual Network and Distributed System Security Symposium. NDSS.","DOI":"10.14722\/ndss.2025.240122"},{"key":"10.1016\/j.cose.2026.105055_b11","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2025.104684","article-title":"RPFUZZ: Efficient network service fuzzing via pruning redundant mutation","volume":"159","author":"Lin","year":"2025","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cose.2026.105055_b12","series-title":"32nd USENIX Security Symposium","first-page":"4481","article-title":"Bleem: Packet sequence oriented fuzzing for protocol implementations","author":"Luo","year":"2023"},{"key":"10.1016\/j.cose.2026.105055_b13","doi-asserted-by":"crossref","unstructured":"Meng, R., Mirchev, M., B\u00f6hme, M., Roychoudhury, A., 2024. Large Language Model guided Protocol Fuzzing. In: Proceedings of the 31st Annual Network and Distributed System Security Symposium. NDSS.","DOI":"10.14722\/ndss.2024.24556"},{"issue":"5","key":"10.1016\/j.cose.2026.105055_b14","article-title":"A brief study of wannacry threat: Ransomware attack 2017","volume":"8","author":"Mohurle","year":"2017","journal-title":"Int. J. Adv. Res. Comput. Sci."},{"key":"10.1016\/j.cose.2026.105055_b15","series-title":"GLOBECOM 2024 - 2024 IEEE Global Communications Conference","first-page":"1203","article-title":"SCFuzz: Complexity aware state selection algorithm for network protocol fuzzing","author":"Mou","year":"2024"},{"issue":"191","key":"10.1016\/j.cose.2026.105055_b16","article-title":"StateAFL: Greybox fuzzing for stateful network servers","volume":"27","author":"Natella","year":"2022","journal-title":"Empir. Softw. Eng."},{"key":"10.1016\/j.cose.2026.105055_b17","doi-asserted-by":"crossref","unstructured":"Natella, R., Pham, V.T., 2021. ProFuzzBench: A Benchmark for Stateful Protocol Fuzzing. In: Proceedings of the 30th ACM SIGSOFT International Symposium on Software Testing and Analysis.","DOI":"10.1145\/3460319.3469077"},{"key":"10.1016\/j.cose.2026.105055_b18","series-title":"2020 IEEE 13th International Conference on Software Testing, Validation and Verification","article-title":"AFLNET: A greybox fuzzer for network protocols","author":"Pham","year":"2020"},{"key":"10.1016\/j.cose.2026.105055_b19","doi-asserted-by":"crossref","DOI":"10.1145\/3580598","article-title":"NSFuzz : Towards efficient and state-aware network service fuzzing","author":"Qin","year":"2023","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"10.1016\/j.cose.2026.105055_b20","doi-asserted-by":"crossref","first-page":"114","DOI":"10.1007\/978-3-642-40517-4_10","article-title":"Snooze: an autonomic and energy-efficient management system for private clouds","volume":"8046","author":"Simonin","year":"2013","journal-title":"Lecture Notes in Comput. Sci."},{"key":"10.1016\/j.cose.2026.105055_b21","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2025.104581","article-title":"CSFuzzer: A grey-box fuzzer for network protocol using context-aware state feedback","volume":"157","author":"Song","year":"2025","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cose.2026.105055_b22","series-title":"2024 IEEE Symposium on Security and Privacy","first-page":"239","article-title":"Where URLs become weapons: Automated discovery of SSRF vulnerabilities in web applications","author":"Wang","year":"2024"},{"key":"10.1016\/j.cose.2026.105055_b23","series-title":"33rd USENIX Security Symposium","first-page":"4747","article-title":"Understanding ethereum mempool security under asymmetric DoS by symbolized stateful fuzzing","author":"Wang","year":"2024"},{"key":"10.1016\/j.cose.2026.105055_b24","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2024.110404","article-title":"BFTDiagnosis: An automated security testing framework with malicious behavior injection for BFT protocols","volume":"249","author":"Wang","year":"2024","journal-title":"Comput. Netw."},{"key":"10.1016\/j.cose.2026.105055_b25","doi-asserted-by":"crossref","unstructured":"Yu, J., Luo, Z., Xia, F., Zhao, Y., Shi, H., Jiang, Y., 2024. SPFuzz: Stateful path based parallel fuzzing for protocols in autonomous vehicles. In: Proceedings of the 61st ACM\/IEEE Design Automation Conference. pp. 1\u20136.","DOI":"10.1145\/3649329.3658270"},{"issue":"2","key":"10.1016\/j.cose.2026.105055_b26","first-page":"1","article-title":"A survey of protocol fuzzing","volume":"57","author":"Zhang","year":"2024","journal-title":"ACM Comput. Surv."},{"issue":"13","key":"10.1016\/j.cose.2026.105055_b27","doi-asserted-by":"crossref","first-page":"2904","DOI":"10.3390\/electronics12132904","article-title":"A survey on the development of network protocol fuzzing techniques","volume":"12","author":"Zhang","year":"2023","journal-title":"Electronics"},{"key":"10.1016\/j.cose.2026.105055_b28","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2025.104683","article-title":"Survey of network protocol fuzzers: Taxonomy, techniques, and directions","volume":"159","author":"Zheng","year":"2025","journal-title":"Comput. Secur."}],"container-title":["Computers &amp; Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404826002312?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404826002312?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,8,15]],"date-time":"2026-08-15T08:11:09Z","timestamp":1786781469000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0167404826002312"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,11]]},"references-count":28,"alternative-id":["S0167404826002312"],"URL":"https:\/\/doi.org\/10.1016\/j.cose.2026.105055","relation":{},"ISSN":["0167-4048"],"issn-type":[{"value":"0167-4048","type":"print"}],"subject":[],"published":{"date-parts":[[2026,11]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"RSAFL: Guide protocol fuzzing by runtime state data","name":"articletitle","label":"Article Title"},{"value":"Computers & Security","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.cose.2026.105055","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"105055"}}