{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T04:43:47Z","timestamp":1784090627875,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":50,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,11,12]],"date-time":"2021-11-12T00:00:00Z","timestamp":1636675200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Australian Research Council","award":["DP210102670"],"award-info":[{"award-number":["DP210102670"]}]},{"name":"Australian Research Council","award":["LP180100170"],"award-info":[{"award-number":["LP180100170"]}]},{"name":"Australian Research Council","award":["DP200100886"],"award-info":[{"award-number":["DP200100886"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,11,12]]},"DOI":"10.1145\/3460120.3484543","type":"proceedings-article","created":{"date-parts":[[2021,11,13]],"date-time":"2021-11-13T12:05:34Z","timestamp":1636805134000},"page":"337-350","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":145,"title":["Snipuzz: Black-box Fuzzing of IoT Firmware via Message Snippet Inference"],"prefix":"10.1145","author":[{"given":"Xiaotao","family":"Feng","sequence":"first","affiliation":[{"name":"Swinburne University of Technology, Melbourne, VIC, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ruoxi","family":"Sun","sequence":"additional","affiliation":[{"name":"The University of Adelaide, Adelaide, SA, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaogang","family":"Zhu","sequence":"additional","affiliation":[{"name":"Swinburne University of Technology, Melbourne, VIC, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Minhui","family":"Xue","sequence":"additional","affiliation":[{"name":"The University of Adelaide, Adelaide, SA, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sheng","family":"Wen","sequence":"additional","affiliation":[{"name":"Swinburne University of Technology, Melbourne, VIC, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dongxi","family":"Liu","sequence":"additional","affiliation":[{"name":"CSIRO Data61, Sydney, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Surya","family":"Nepal","sequence":"additional","affiliation":[{"name":"CSIRO Data61, Sydney, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yang","family":"Xiang","sequence":"additional","affiliation":[{"name":"Swinburne University of Technology, Melbourne, VIC, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,11,13]]},"reference":[{"key":"e_1_3_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23412"},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"crossref","unstructured":"I. Ashraf X. Ma B. Jiang and W. K. Chan. 2020. GasFuzzer: Fuzzing ethereum smart contract binaries to expose gas-oriented exception security vulnerabilities. IEEE Access (2020).","DOI":"10.1109\/ACCESS.2020.2995183"},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134020"},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978428"},{"key":"e_1_3_2_2_5_1","unstructured":"Kali Bot. 2019. bed. https:\/\/gitlab.com\/kalilinux\/packages\/bed."},{"key":"e_1_3_2_2_6_1","volume-title":"2018 USENIX Annual Technical Conference (USENIX ATC 18)","author":"Celik Z. Berkay","year":"2018","unstructured":"Z. Berkay Celik, Patrick McDaniel, and Gang Tan. 2018. Soteria: Automated IoT safety and security analysis. In 2018 USENIX Annual Technical Conference (USENIX ATC 18)."},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23415"},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23159"},{"key":"e_1_3_2_2_9_1","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX '20)","author":"Clements Abraham","year":"2020","unstructured":"Abraham Clements, Eric Gustafson, Tobias Scharnowski, Paul Grosen, David Fritz, Christopher Kruegel, Giovanni Vigna, Saurabh Bagchi, and Mathias Payer. 2020. HALucinator: Firmware re-hosting through abstraction layer emulation. In Proceedings of the 29th USENIX Security Symposium (USENIX '20)."},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2818000.2818035"},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134069"},{"key":"e_1_3_2_2_12_1","volume-title":"23rd USENIX Security Symposium (USENIX Security 14)","author":"Costin Andrei","year":"2014","unstructured":"Andrei Costin, Jonas Zaddach, Aur\u00e9lien Francillon, and Davide Balzarotti. 2014. A Large-Scale Analysis of the Security of Embedded Firmwares. In 23rd USENIX Security Symposium (USENIX Security 14)."},{"key":"e_1_3_2_2_13_1","volume-title":"Graph-based comparison of executable objects (english version). Journal of Computer Virology and Hacking Techniques","author":"Dullien Thomas","year":"2005","unstructured":"Thomas Dullien and Rolf Rolles. 2005. Graph-based comparison of executable objects (english version). Journal of Computer Virology and Hacking Techniques (2005)."},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"crossref","unstructured":"Sebastian Eschweiler Khaled Yakdan and Elmar Gerhards-Padilla. 2016. discovRE: Efficient cross-architecture identification of bugs in binary code. In Network and Distributed Systems Security (NDSS).","DOI":"10.14722\/ndss.2016.23185"},{"key":"e_1_3_2_2_15_1","unstructured":"Pwnie Express. 2020. What makes IoT so vulnerable to attack? Technical Report. Outpost24."},{"key":"e_1_3_2_2_16_1","volume-title":"29th $$USENIX$$ Security Symposium ($$USENIX$$ Security 20).","author":"Feng Bo","unstructured":"Bo Feng, Alejandro Mera, and Long Lu. 2020. P2IM: Scalable and hardware-independent firmware testing via automatic peripheral interface modeling. In 29th $$USENIX$$ Security Symposium ($$USENIX$$ Security 20)."},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978370"},{"key":"e_1_3_2_2_18_1","unstructured":"Fitblip. 2019. Sulley. https:\/\/github.com\/OpenRCE\/sulley."},{"key":"e_1_3_2_2_19_1","volume-title":"22nd International Symposium on Research in Attacks, Intrusions and Defenses ($$RAID$$","author":"Gustafson Eric","year":"2019","unstructured":"Eric Gustafson, Marius Muench, Chad Spensky, Nilo Redini, Aravind Machiry, Yanick Fratantonio, Davide Balzarotti, Aur\u00e9lien Francillon, Yung Ryn Choe, Christophe Kruegel, et al. 2019. Toward the analysis of embedded firmware through automated re-hosting. In 22nd International Symposium on Research in Attacks, Intrusions and Defenses ($$RAID$$ 2019)."},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427294"},{"key":"e_1_3_2_2_21_1","volume-title":"NEMESYS: Network message syntax reverse engineering by analysis of the intrinsic structure of individual messages. In 12th $$USENIX$$ Workshop on Offensive Technologies ($$WOOT$$ 18).","author":"Kleber Stephan","year":"2018","unstructured":"Stephan Kleber, Henning Kopp, and Frank Kargl. 2018. NEMESYS: Network message syntax reverse engineering by analysis of the intrinsic structure of individual messages. In 12th $$USENIX$$ Workshop on Offensive Technologies ($$WOOT$$ 18)."},{"key":"e_1_3_2_2_22_1","volume-title":"there will be 4 devices for every human on earth. Futurism","author":"Lant Karla","year":"2017","unstructured":"Karla Lant. 2017. By 2020, there will be 4 devices for every human on earth. Futurism (2017)."},{"key":"e_1_3_2_2_23_1","unstructured":"lcamtuf. 2017. AFL. https:\/\/lcamtuf.coredump.cx\/afl\/."},{"key":"e_1_3_2_2_24_1","unstructured":"Trend Micro. 2020 a. Mirai botnet exploit weaponized to attack IoT devices via CVE-2020--5902. Technical Report. Security Intelligence Blog."},{"key":"e_1_3_2_2_25_1","unstructured":"Trend Micro. 2020 b. Smart yet flawed: IoT device vulnerabilities explained. Technical Report. Security News."},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23166"},{"key":"e_1_3_2_2_27_1","unstructured":"Lindsey O'Donnell. 2020. More than half of IoT devices vulnerable to severe attacks. Technical Report. ThreatPost."},{"key":"e_1_3_2_2_28_1","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"\u00d6sterlund Sebastian","year":"2020","unstructured":"Sebastian \u00d6sterlund, Kaveh Razavi, Herbert Bos, and Cristiano Giuffrida. 2020. ParmeSan: Sanitizer-guided greybox fuzzing. In 29th USENIX Security Symposium (USENIX Security 20)."},{"key":"e_1_3_2_2_29_1","volume-title":"PEACH: The PEACH fuzzer platform. https:\/\/www.peach.tech\/products\/peach-fuzzer\/ Accessed: 2021-01.","year":"2021","unstructured":"Peachtech. 2021. PEACH: The PEACH fuzzer platform. https:\/\/www.peach.tech\/products\/peach-fuzzer\/ Accessed: 2021-01."},{"key":"e_1_3_2_2_30_1","unstructured":"Joshua Pereyda. 2017. boofuzz: Network protocol fuzzing for humans. https:\/\/boofuzz.readthedocs.io\/en\/stable\/."},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.49"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICST46399.2020.00062"},{"key":"e_1_3_2_2_33_1","volume-title":"Alexandru Razvan Caciulescu, and Abhik Roychoudhury.","author":"Pham Van-Thuan","year":"2019","unstructured":"Van-Thuan Pham, Marcel B\u00f6hme, Andrew Edward Santosa, Alexandru Razvan Caciulescu, and Abhik Roychoudhury. 2019. Smart greybox fuzzing. IEEE Transactions on Software Engineering (2019)."},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00036"},{"key":"e_1_3_2_2_35_1","volume-title":"26th USENIX Security Symposium (USENIX Security 17)","author":"Schumilo Sergej","year":"2017","unstructured":"Sergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel, and Thorsten Holz. 2017. kAFL: Hardware-assisted feedback fuzzing for OS Kernels. In 26th USENIX Security Symposium (USENIX Security 17)."},{"key":"e_1_3_2_2_36_1","volume-title":"SPFuzz: a hierarchical scheduling framework for stateful network protocol fuzzing","author":"Song Congxi","year":"2019","unstructured":"Congxi Song, Bo Yu, Xu Zhou, and Qiang Yang. 2019. SPFuzz: a hierarchical scheduling framework for stateful network protocol fuzzing. IEEE Access (2019)."},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338507.3358616"},{"key":"e_1_3_2_2_38_1","unstructured":"Liam Tung. 2017. IoT devices will outnumber the world's population this year for the first time. Technical Report. ZDNet."},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.23"},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24422"},{"key":"e_1_3_2_2_41_1","unstructured":"Wikipedia. 2021 a. Edit distance. https:\/\/en.wikipedia.org\/wiki\/Edit_distance."},{"key":"e_1_3_2_2_42_1","unstructured":"Wikipedia. 2021 b. Hierarchical clustering. https:\/\/en.wikipedia.org\/wiki\/Hierarchical_clustering."},{"key":"e_1_3_2_2_43_1","unstructured":"wireghoul. 2019. Doona. https:\/\/github.com\/wireghoul\/doona."},{"key":"e_1_3_2_2_44_1","unstructured":"wireshark. 2020. About wireshark. https:\/\/www.wireshark.org\/about.html."},{"key":"e_1_3_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134018"},{"key":"e_1_3_2_2_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363247"},{"key":"e_1_3_2_2_47_1","doi-asserted-by":"crossref","unstructured":"Y. Yu Z. Chen S. Gan and X. Wang. 2020. SGPFuzzer: A state-driven smart graybox protocol fuzzer for network protocol implementations. IEEE Access (2020).","DOI":"10.1109\/ACCESS.2020.3025037"},{"key":"e_1_3_2_2_48_1","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Yue Tai","year":"2020","unstructured":"Tai Yue, Pengfei Wang, Yong Tang, Enze Wang, Bo Yu, Kai Lu, and Xu Zhou. 2020. EcoFuzz: Adaptive energy-saving greybox fuzzing as a variant of the adversarial multi-armed bandit. In 29th USENIX Security Symposium (USENIX Security 20)."},{"key":"e_1_3_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23229"},{"key":"e_1_3_2_2_50_1","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Zheng Yaowen","year":"2019","unstructured":"Yaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song, Hongsong Zhu, and Limin Sun. 2019. FIRM-AFL: High-throughput greybox fuzzing of IoT firmware via augmented process emulation. In 28th USENIX Security Symposium (USENIX Security 19)."}],"event":{"name":"CCS '21: 2021 ACM SIGSAC Conference on Computer and Communications Security","location":"Virtual Event Republic of Korea","acronym":"CCS '21","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460120.3484543","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3460120.3484543","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T20:51:42Z","timestamp":1763499102000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460120.3484543"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,12]]},"references-count":50,"alternative-id":["10.1145\/3460120.3484543","10.1145\/3460120"],"URL":"https:\/\/doi.org\/10.1145\/3460120.3484543","relation":{},"subject":[],"published":{"date-parts":[[2021,11,12]]},"assertion":[{"value":"2021-11-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}