{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T15:08:18Z","timestamp":1784646498553,"version":"3.55.0"},"reference-count":202,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2024,10,10]],"date-time":"2024-10-10T00:00:00Z","timestamp":1728518400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62125205 and U23A20303"],"award-info":[{"award-number":["62125205 and U23A20303"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100018925","name":"\u2018111 Center\u2019","doi-asserted-by":"crossref","award":["B16037"],"award-info":[{"award-number":["B16037"]}],"id":[{"id":"10.13039\/501100018925","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100015401","name":"Key Research and Development Program of Shaanxi","doi-asserted-by":"crossref","award":["2023KXJ190"],"award-info":[{"award-number":["2023KXJ190"]}],"id":[{"id":"10.13039\/501100015401","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"crossref","award":["YJSJ24010"],"award-info":[{"award-number":["YJSJ24010"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Nanyang Technological University (NTU)-DESAY SV Research Program","award":["2018-0980"],"award-info":[{"award-number":["2018-0980"]}]},{"name":"National Research Foundation Singapore under its AI Singapore Programme","award":["AISG2-RP-2020-019"],"award-info":[{"award-number":["AISG2-RP-2020-019"]}]},{"name":"National Research Foundation, Singapore, and the Cyber Security Agency under its National Cybersecurity R&D Programme","award":["NCRP25-P04-TAICeN"],"award-info":[{"award-number":["NCRP25-P04-TAICeN"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2025,2,28]]},"abstract":"<jats:p>Communication protocols form the bedrock of our interconnected world, yet vulnerabilities within their implementations pose significant security threats. Recent developments have seen a surge in fuzzing-based research dedicated to uncovering these vulnerabilities within protocol implementations. However, there still lacks a systematic overview of protocol fuzzing for answering the essential questions such as what the unique challenges are, how existing works solve them, and so on. To bridge this gap, we conducted a comprehensive investigation of related works from both academia and industry. Our study includes a detailed summary of the specific challenges in protocol fuzzing and provides a systematic categorization and overview of existing research efforts. Furthermore, we explore and discuss potential future research directions in protocol fuzzing.<\/jats:p>","DOI":"10.1145\/3696788","type":"journal-article","created":{"date-parts":[[2024,9,21]],"date-time":"2024-09-21T09:49:27Z","timestamp":1726912167000},"page":"1-36","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":28,"title":["A Survey of Protocol Fuzzing"],"prefix":"10.1145","volume":"57","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3260-4530","authenticated-orcid":false,"given":"Xiaohan","family":"Zhang","sequence":"first","affiliation":[{"name":"the State Key Laboratory of Integrated Services Networks, and Engineering Research Center of Big Data Security, Ministry of Education, and the School of Cyber Engineering, Xidian University, Xian, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5603-1322","authenticated-orcid":false,"given":"Cen","family":"Zhang","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5583-4155","authenticated-orcid":false,"given":"Xinghua","family":"Li","sequence":"additional","affiliation":[{"name":"the State Key Laboratory of Integrated Services Networks, and Engineering Research Center of Big Data Security, Ministry of Education, and the School of Cyber Engineering, Xidian University, Xian, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-7032-2681","authenticated-orcid":false,"given":"Zhengjie","family":"Du","sequence":"additional","affiliation":[{"name":"Nanjing University, Nanjing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7066-2144","authenticated-orcid":false,"given":"Bing","family":"Mao","sequence":"additional","affiliation":[{"name":"Nanjing University, Nanjing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4382-0757","authenticated-orcid":false,"given":"Yuekang","family":"Li","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8953-0782","authenticated-orcid":false,"given":"Yaowen","family":"Zheng","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0991-4231","authenticated-orcid":false,"given":"Yeting","family":"Li","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering CAS, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0424-9845","authenticated-orcid":false,"given":"Li","family":"Pan","sequence":"additional","affiliation":[{"name":"Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7300-9215","authenticated-orcid":false,"given":"Yang","family":"Liu","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3491-8146","authenticated-orcid":false,"given":"Robert","family":"Deng","sequence":"additional","affiliation":[{"name":"Singapore Management University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,10,10]]},"reference":[{"key":"e_1_3_3_2_2","first-page":"1","article-title":"IEEE standard for local and metropolitan area networks\u2013port-based network access control","year":"2020","unstructured":"2020. IEEE standard for local and metropolitan area networks\u2013port-based network access control. IEEE Std 802.1X-2020 (Revision of IEEE Std 802.1X-2010 Incorporating IEEE Std 802.1Xbx-2014 and IEEE Std 802.1Xck-2018) (2020), 1\u2013289.","journal-title":"IEEE Std 802.1X-2020 (Revision of IEEE Std 802.1X-2010 Incorporating IEEE Std 802.1Xbx-2014 and IEEE Std 802.1Xck-2018)"},{"key":"e_1_3_3_3_2","first-page":"1","article-title":"IEEE standard for information technology\u2013telecommunications and information exchange between systems - local and metropolitan area networks\u2013specific requirements - part 11: Wireless LAN Medium Access Control (MAC) and Physical Layer (PHY) specifications","year":"2021","unstructured":"2021. IEEE standard for information technology\u2013telecommunications and information exchange between systems - local and metropolitan area networks\u2013specific requirements - part 11: Wireless LAN Medium Access Control (MAC) and Physical Layer (PHY) specifications. IEEE Std 802.11-2020 (Revision of IEEE Std 802.11-2016) (2021), 1\u20134379.","journal-title":"IEEE Std 802.11-2020 (Revision of IEEE Std 802.11-2016)"},{"key":"e_1_3_3_4_2","first-page":"2759","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Aafer Yousra","year":"2021","unstructured":"Yousra Aafer, Wei You, Yi Sun, Yu Shi, Xiangyu Zhang, and Heng Yin. 2021. Android SmartTVs vulnerability discovery via log-guided fuzzing. In 30th USENIX Security Symposium (USENIX Security 21). 2759\u20132776."},{"key":"e_1_3_3_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICST49551.2021.00017"},{"key":"e_1_3_3_6_2","unstructured":"ZigBee Alliance. 2015. ZigBee Specification."},{"key":"e_1_3_3_7_2","unstructured":"Kaled M. Alshmrany and Lucas C. Cordeiro. 2020. Finding security vulnerabilities in network protocol implementations. (2020). arXiv:2001.09592"},{"key":"e_1_3_3_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00096"},{"key":"e_1_3_3_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/ASE56229.2023.00095"},{"key":"e_1_3_3_10_2","unstructured":"Anastasios Andronidis and Cristian Cadar. 2022. SnapFuzz: An efficient fuzzing framework for network applications. (2022). arXiv:2201.04048"},{"key":"e_1_3_3_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/3190508.3190538"},{"key":"e_1_3_3_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICST53961.2022.00019"},{"key":"e_1_3_3_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00117"},{"key":"e_1_3_3_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00083"},{"key":"e_1_3_3_15_2","unstructured":"AUTOSAR. 2016. SOME\/IP Protocol Specification."},{"key":"e_1_3_3_16_2","first-page":"3255","volume-title":"31st USENIX Security Symposium (USENIX Security)","author":"Ba Jinsheng","year":"2022","unstructured":"Jinsheng Ba, Marcel B\u00f6hme, Zahra Mirzamomen, and Abhik Roychoudhury. 2022. Stateful greybox fuzzing. In 31st USENIX Security Symposium (USENIX Security). 3255\u20133272."},{"key":"e_1_3_3_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/215530.215544"},{"key":"e_1_3_3_18_2","first-page":"1847","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Bars Nils","year":"2023","unstructured":"Nils Bars, Moritz Schloegel, Tobias Scharnowski, Nico Schiller, and Thorsten Holz. 2023. Fuzztruction: Using fault injection-based fuzzing to leverage implicit domain knowledge. In 32nd USENIX Security Symposium (USENIX Security 23). 1847\u20131864."},{"key":"e_1_3_3_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.39"},{"key":"e_1_3_3_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW59978.2023.00043"},{"key":"e_1_3_3_21_2","first-page":"62","volume-title":"28th European Symposium on Research in Computer Security (ESORICS)","author":"Bushart Jonas","year":"2023","unstructured":"Jonas Bushart and Christian Rossow. 2023. ResolFuzz: Differential fuzzing of DNS resolvers. In 28th European Symposium on Research in Computer Security (ESORICS). 62\u201380."},{"key":"e_1_3_3_22_2","unstructured":"Andrei Bytes Prashant Hari Narayan Rajput Michail Maniatakos and Jianying Zhou. 2022. FieldFuzz: Enabling vulnerability discovery in Industrial Control Systems supply chain using stateful system-level fuzzing. arXiv:2204.13499"},{"key":"e_1_3_3_23_2","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315286"},{"key":"e_1_3_3_24_2","unstructured":"Hongjian Cao. 2021. Owfuzz: WiFi Nightmare.https:\/\/www.blackhat.com\/eu-21\/briefings\/schedule\/#owfuzz-wifi-nightmare-24338"},{"key":"e_1_3_3_25_2","doi-asserted-by":"publisher","DOI":"10.1146\/annurev.psych.48.1.61"},{"key":"e_1_3_3_26_2","first-page":"173","volume-title":"3rd Symposium on Operating Systems Design and Implementation (OSDI)","author":"Castro Miguel","year":"1999","unstructured":"Miguel Castro and Barbara Liskov. 1999. Practical Byzantine fault tolerance. In 3rd Symposium on Operating Systems Design and Implementation (OSDI), Vol. 99. 173\u2013186."},{"key":"e_1_3_3_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2009.20"},{"key":"e_1_3_3_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.40"},{"key":"e_1_3_3_29_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23159"},{"key":"e_1_3_3_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/MWC.2005.1404570"},{"key":"e_1_3_3_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/3338502.3359762"},{"key":"e_1_3_3_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179386"},{"key":"e_1_3_3_33_2","unstructured":"Cisco. 2022. Cisco Secure Client Data Sheet.https:\/\/www.cisco.com\/c\/en\/us\/products\/collateral\/security\/anyconnect-secure-mobility-client\/secure-mobility-client-ds.html"},{"key":"e_1_3_3_34_2","doi-asserted-by":"publisher","DOI":"10.1016\/0140-3664(87)90311-2"},{"key":"e_1_3_3_35_2","doi-asserted-by":"publisher","DOI":"10.5555\/2531597"},{"key":"e_1_3_3_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.14"},{"key":"e_1_3_3_37_2","unstructured":"Mitsubishi Electric Corporation. 2020. GX Works2 - Programmable Controllers MELSEC.https:\/\/www.mitsubishielectric.com\/fa\/products\/cnt\/plceng\/smerit\/gx_works2\/index.html"},{"key":"e_1_3_3_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2010.22"},{"key":"e_1_3_3_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW.2018.00009"},{"key":"e_1_3_3_40_2","first-page":"193","volume-title":"24th USENIX Security Symposium (USENIX Security)","author":"Ruiter Joeri de","year":"2015","unstructured":"Joeri de Ruiter and Erik Poll. 2015. Protocol state fuzzing of TLS implementations. In 24th USENIX Security Symposium (USENIX Security). 193\u2013206."},{"key":"e_1_3_3_41_2","doi-asserted-by":"crossref","unstructured":"T. Dierks. 2008. RFC5246: The Transport Layer Security (TLS) Protocol Version 1.2.https:\/\/www.rfc-editor.org\/rfc\/rfc5246","DOI":"10.17487\/rfc5246"},{"key":"e_1_3_3_42_2","unstructured":"M. Eddington. 2014. Peach fuzzing platform. Available:http:\/\/community.peachfuzzer.com\/WhatIsPeach.html"},{"key":"e_1_3_3_43_2","unstructured":"Schneider Electric. 2009. TwidoSuite Programming Software.https:\/\/www.se.com\/ww\/en\/download\/document\/TwidoSuite_V0220_11_SP\/"},{"key":"e_1_3_3_44_2","unstructured":"ETSI. 2002. Universal Mobile Telecommunications System (UMTS); Multimedia Messaging Service (MMS); Stage 1 (3GPP TS 22.140 version 5.3.0 Release 5). https:\/\/www.etsi.org\/deliver\/etsi_ts\/122100_122199\/122140\/05.03.00_60\/ts_122140v050300p.pdf"},{"key":"e_1_3_3_45_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-89500-0_53"},{"key":"e_1_3_3_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3488028"},{"key":"e_1_3_3_47_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484543"},{"key":"e_1_3_3_48_2","first-page":"2523","volume-title":"29th USENIX Security Symposium (USENIX Security)","author":"Fiterau-Brostean Paul","year":"2020","unstructured":"Paul Fiterau-Brostean, Bengt Jonsson, Robert Merget, Joeri de Ruiter, Konstantinos Sagonas, and Juraj Somorovsky. 2020. Analysis of DTLS implementations using protocol state fuzzing. In 29th USENIX Security Symposium (USENIX Security). 2523\u20132540."},{"key":"e_1_3_3_49_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICST53961.2022.00051"},{"key":"e_1_3_3_50_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.23068"},{"key":"e_1_3_3_51_2","unstructured":"Open Networking Foundation. 2015. OpenFlow Switch Specification."},{"key":"e_1_3_3_52_2","article-title":"A framework of high-speed network protocol fuzzing based on shared memory","author":"Fu Junsong","year":"2023","unstructured":"Junsong Fu, Shuai Xiong, Na Wang, Ruiping Ren, Ang Zhou, and Bharat K. Bhargava. 2023. A framework of high-speed network protocol fuzzing based on shared memory. IEEE Transactions on Dependable and Secure Computing (2023).","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"e_1_3_3_53_2","doi-asserted-by":"publisher","DOI":"10.1002\/cpe.5756"},{"key":"e_1_3_3_54_2","first-page":"1025","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Garbelini Matheus E.","year":"2022","unstructured":"Matheus E. Garbelini, Vaibhav Bedi, Sudipta Chattopadhyay, Sumei Sun, and Ernest Kurniawan. 2022. BrakTooth: Causing havoc on Bluetooth link manager via directed fuzzing. In 31st USENIX Security Symposium (USENIX Security 22). 1025\u20131042."},{"key":"e_1_3_3_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM48099.2022.10001673"},{"key":"e_1_3_3_56_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3014624"},{"key":"e_1_3_3_57_2","first-page":"911","volume-title":"2020 USENIX Annual Technical Conference (USENIX ATC 20)","author":"Garbelini Matheus E.","year":"2020","unstructured":"Matheus E. Garbelini, Chundong Wang, Sudipta Chattopadhyay, Sun Sumei, and Ernest Kurniawan. 2020. SweynTooth: Unleashing mayhem over Bluetooth low energy. In 2020 USENIX Annual Technical Conference (USENIX ATC 20). 911\u2013925."},{"key":"e_1_3_3_58_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-28865-9_18"},{"key":"e_1_3_3_59_2","unstructured":"Brian Gorenc and Matt Molinyawe. 2014. Blowing up the Celly: Building Your Own SMS\/MMS Fuzzer.https:\/\/media.defcon.org\/DEF%20CON%2022\/DEF%20CON%2022%20presentations\/DEF%20CON%2022%20-%20Brian-Gorenc-Matt-Molinyawe-Blowing-Up-The-Celly.pdf"},{"key":"e_1_3_3_60_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30579-8_24"},{"key":"e_1_3_3_61_2","unstructured":"The Open Group. 2018. Single Sign-On. http:\/\/www.opengroup.org\/security\/sso\/"},{"key":"e_1_3_3_62_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2015.2495297"},{"key":"e_1_3_3_63_2","unstructured":"Ben Hawkes. 2022. 0day In the Wild.https:\/\/googleprojectzero.blogspot.com\/p\/0day.html"},{"key":"e_1_3_3_64_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCN54977.2022.9868872"},{"key":"e_1_3_3_65_2","volume-title":"14th USENIX Workshop on Offensive Technologies (WOOT)","author":"Heinze Dennis","unstructured":"Dennis Heinze, Jiska Classen, and Matthias Hollick. 2020. ToothPicker: Apple picking in the iOS Bluetooth stack. In 14th USENIX Workshop on Offensive Technologies (WOOT)."},{"key":"e_1_3_3_66_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2017.36"},{"key":"e_1_3_3_67_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485388"},{"key":"e_1_3_3_68_2","doi-asserted-by":"crossref","unstructured":"Jana Iyengar and Martin Thomson. 2021. QUIC: A UDP-Based Multiplexed and Secure Transport. RFC 9000. https:\/\/www.rfc-editor.org\/info\/rfc9000","DOI":"10.17487\/RFC9000"},{"key":"e_1_3_3_69_2","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2011.120811.00063"},{"key":"e_1_3_3_70_2","volume-title":"25th Annual Network and Distributed System Security Symposium (NDSS)","author":"Jero Samuel","year":"2018","unstructured":"Samuel Jero, Md. Endadul Hoque, David R. Choffnes, Alan Mislove, and Cristina Nita-Rotaru. 2018. Automated attack discovery in TCP congestion control using a model-guided approach. In 25th Annual Network and Distributed System Security Symposium (NDSS)."},{"key":"e_1_3_3_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2015.22"},{"key":"e_1_3_3_72_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33019478"},{"key":"e_1_3_3_73_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179438"},{"key":"e_1_3_3_74_2","doi-asserted-by":"publisher","DOI":"10.1145\/505202.505223"},{"key":"e_1_3_3_75_2","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2006.60"},{"key":"e_1_3_3_76_2","article-title":"Oracle-based protocol testing with Eywa","author":"Kakarla Siva Kesava Reddy","year":"2023","unstructured":"Siva Kesava Reddy Kakarla and Ryan Beckett. 2023. Oracle-based protocol testing with Eywa. arXiv:2312.06875 (2023).","journal-title":"arXiv:2312.06875"},{"key":"e_1_3_3_77_2","doi-asserted-by":"publisher","DOI":"10.1007\/11761679_6"},{"key":"e_1_3_3_78_2","first-page":"5845","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Kim Kyungtae","year":"2023","unstructured":"Kyungtae Kim, Sungwoo Kim, Kevin R. B. Butler, Antonio Bianchi, Rick Kennell, and Dave Jing Tian. 2023. Fuzz the power: Dual-role state guided black-box fuzzing for USB power delivery. In 32nd USENIX Security Symposium (USENIX Security 23). 5845\u20135861."},{"key":"e_1_3_3_79_2","volume-title":"38th IEEE Symposium on Poster presented at Security and Privacy","author":"Kim Seulbae","year":"2017","unstructured":"Seulbae Kim, Seunghoon Woo, Heejo Lee, and Hakjoo Oh. 2017. Poster: Iotcube: An automated analysis platform for finding security vulnerabilities. In 38th IEEE Symposium on Poster presented at Security and Privacy."},{"key":"e_1_3_3_80_2","first-page":"1043","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Krupp Johannes","year":"2022","unstructured":"Johannes Krupp, Ilya Grishchenko, and Christian Rossow. 2022. AmpFuzz: Fuzzing for amplification DDoS vulnerabilities. In 31st USENIX Security Symposium (USENIX Security 22). 1043\u20131060."},{"key":"e_1_3_3_81_2","volume-title":"BlackHat US 2018","author":"Lee Seungsoo","year":"2018","unstructured":"Seungsoo Lee, Jinwoo Kim, Seungwon Woo, and Seungwon Shin. 2018. The finest penetration testing framework for software-defined networks. In BlackHat US 2018."},{"key":"e_1_3_3_82_2","unstructured":"Ao Li Rohan Padhye and Vyas Sekar. 2022. SPIDER: A Practical Fuzzing Framework to Uncover Stateful Performance Issues in SDN Controllers. https:\/\/arxiv.org\/abs\/2209.04026"},{"key":"e_1_3_3_83_2","unstructured":"Junqiang Li Senyi Li Gang Sun Ting Chen and Hongfang Yu. 2022. SNPSFuzzer: A fast greybox fuzzer for stateful network protocols using snapshots. (2022). arXiv:2202.03643"},{"key":"e_1_3_3_84_2","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2018.2834476"},{"key":"e_1_3_3_85_2","doi-asserted-by":"publisher","DOI":"10.1145\/3324884.3416629"},{"key":"e_1_3_3_86_2","doi-asserted-by":"publisher","DOI":"10.1109\/SANER53432.2022.00089"},{"key":"e_1_3_3_87_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.sysarc.2022.102483"},{"key":"e_1_3_3_88_2","doi-asserted-by":"publisher","DOI":"10.1109\/ASE51524.2021.9678653"},{"key":"e_1_3_3_89_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.24083"},{"key":"e_1_3_3_90_2","first-page":"1","volume-title":"ACM SIGBED International Conference on Embedded Software (EMSOFT)","author":"Luo Zhengxiong","year":"2024","unstructured":"Zhengxiong Luo, Junze Yu, Qingpeng Du, Yanyang Zhao, Feifan Wu, and Heyuan Shi. 2024. Parallel fuzzing of IoT messaging protocols through collaborative packet generation. In ACM SIGBED International Conference on Embedded Software (EMSOFT). 1\u201312."},{"key":"e_1_3_3_91_2","first-page":"4481","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Luo Zhengxiong","year":"2023","unstructured":"Zhengxiong Luo, Junze Yu, Feilong Zuo, Jianzhong Liu, Yu Jiang, Ting Chen, Abhik Roychoudhury, and Jiaguang Sun. 2023. Bleem: Packet sequence oriented fuzzing for protocol implementations. In 32nd USENIX Security Symposium (USENIX Security 23). 4481\u20134498."},{"key":"e_1_3_3_92_2","doi-asserted-by":"publisher","DOI":"10.1145\/3358227"},{"key":"e_1_3_3_93_2","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218603"},{"key":"e_1_3_3_94_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.24078"},{"key":"e_1_3_3_95_2","first-page":"4783","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Ma Xiaoyue","year":"2024","unstructured":"Xiaoyue Ma, Lannan Luo, and Qiang Zeng. 2024. From one thousand pages of specification to unveiling hidden bugs: Large language model assisted fuzzing of matter IoT devices. In 33rd USENIX Security Symposium (USENIX Security 24). 4783\u20134800."},{"key":"e_1_3_3_96_2","doi-asserted-by":"publisher","DOI":"10.1145\/3581791.3596857"},{"key":"e_1_3_3_97_2","doi-asserted-by":"crossref","unstructured":"Dominik Maier Lukas Seidel and Shinjo Park. 2020. BaseSAFE: Baseband sanitized fuzzing through emulation. (2020). arXiv:2005.07797","DOI":"10.1145\/3395351.3399360"},{"key":"e_1_3_3_98_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2019.2946563"},{"key":"e_1_3_3_99_2","unstructured":"Eldar Marcussen. 2018. Doona - Network fuzzing tool. Available: https:\/\/github.com\/wireghoul\/doona"},{"key":"e_1_3_3_100_2","volume-title":"Communication Network Protocols","author":"Marsden B. W.","year":"1986","unstructured":"B. W. Marsden. 1986. Communication Network Protocols. lc89188307"},{"key":"e_1_3_3_101_2","doi-asserted-by":"publisher","DOI":"10.1145\/3314221.3314651"},{"key":"e_1_3_3_102_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-99073-6_16"},{"key":"e_1_3_3_103_2","first-page":"2265-\u20132278","volume-title":"2022 ACM SIGSAC Conference on Computer and Communications Security (CCS)","author":"Stone Chris McMahon","year":"2022","unstructured":"Chris McMahon Stone, Sam L. Thomas, Mathy Vanhoef, James Henderson, Nicolas Bailluet, and Tom Chothia. 2022. The closer you look, the more you learn: A grey-box approach to protocol state machine learning. In 2022 ACM SIGSAC Conference on Computer and Communications Security (CCS). 2265-\u20132278."},{"key":"e_1_3_3_104_2","article-title":"Finding counterexamples of temporal logic properties in software implementations via greybox fuzzing","volume":"2109","author":"Meng Ruijie","year":"2021","unstructured":"Ruijie Meng, Zhen Dong, Jialin Li, Ivan Beschastnikh, and Abhik Roychoudhury. 2021. Finding counterexamples of temporal logic properties in software implementations via greybox fuzzing. CoRR abs\/2109.02312 (2021). arXiv:2109.02312","journal-title":"CoRR"},{"key":"e_1_3_3_105_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.24556"},{"key":"e_1_3_3_106_2","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623097"},{"key":"e_1_3_3_107_2","unstructured":"Microsoft. 2007. Remote Desktop Protocol: Basic Connectivity and Graphics Remoting.https:\/\/learn.microsoft.com\/en-us\/openspecs\/windows_protocols\/ms-rdpbcgr\/5073f4ed-1e93-45e1-b039-6e30c385867c"},{"key":"e_1_3_3_108_2","doi-asserted-by":"publisher","DOI":"10.1145\/96267.96279"},{"key":"e_1_3_3_109_2","first-page":"12","volume-title":"First Symposium on Networked Systems Design and Implementation (NSDI 04)","author":"Musuvathi Madanlal","year":"2004","unstructured":"Madanlal Musuvathi and Dawson R. Engler. 2004. Model checking large network protocol implementations. In First Symposium on Networked Systems Design and Implementation (NSDI 04). 12."},{"key":"e_1_3_3_110_2","unstructured":"Paul Mutton. 2014. Half a million widely trusted websites vulnerable to Heartbleed bug.https:\/\/news.netcraft.com\/archives\/2014\/04\/08\/half-a-million-widely-trusted-websites-vulnerable-to-heartbleed-bug.html"},{"key":"e_1_3_3_111_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-022-10233-3"},{"key":"e_1_3_3_112_2","article-title":"TSpec-LLM: An open-source dataset for LLM understanding of 3GPP specifications","author":"Nikbakht Rasoul","year":"2024","unstructured":"Rasoul Nikbakht, Mohamed Benzaghta, and Giovanni Geraci. 2024. TSpec-LLM: An open-source dataset for LLM understanding of 3GPP specifications. arXiv:2406.01768 (2024).","journal-title":"arXiv:2406.01768"},{"key":"e_1_3_3_113_2","unstructured":"NOCHVAY. 2019. Security research: CODESYS Runtime a PLC control framework. https:\/\/ics-cert.kaspersky.com\/publications\/reports\/2019\/09\/18\/security-research-codesys-runtime-a-plc-control-framework-part-1\/"},{"key":"e_1_3_3_114_2","unstructured":"OASIS. 2019. MQTT Version 5.0.https:\/\/docs.oasis-open.org\/mqtt\/mqtt\/v5.0\/mqtt-v5.0.html"},{"key":"e_1_3_3_115_2","doi-asserted-by":"publisher","DOI":"10.1109\/RoSE.2019.00014"},{"key":"e_1_3_3_116_2","unstructured":"OMG. 2018. The Real-time Publish-Subscribe Protocol (RTPS) DDS Interoperability Wire Protocol Specification.https:\/\/www.omg.org\/spec\/DDSI-RTPS\/2.3\/Beta1\/PDF"},{"key":"e_1_3_3_117_2","unstructured":"openvpn. 2014. OpenVPN: OpenVPN source code documentation.https:\/\/build.openvpn.net\/doxygen\/"},{"key":"e_1_3_3_118_2","volume-title":"DEFCON 21","author":"Ozavci Fatih","year":"2013","unstructured":"Fatih Ozavci. 2013. VoIP wars : Return of the SIP. In DEFCON 21."},{"key":"e_1_3_3_119_2","doi-asserted-by":"crossref","unstructured":"Maria Leonor Pacheco Max von Hippel Ben Weintraub Dan Goldwasser and Cristina Nita-Rotaru. 2022. Automated attack synthesis by extracting finite state machines from protocol specification documents. (2022). arXiv:2202.09470","DOI":"10.1109\/SP46214.2022.9833673"},{"key":"e_1_3_3_120_2","unstructured":"Chun Sung Park Yeongjin Jang Seungjoo Kim and Ki Taek Lee. 2019. Fuzzing and Exploiting Virtual Channels in Microsoft Remote Desktop Protocol for Fun and Profit.https:\/\/www.blackhat.com\/eu-19\/briefings\/schedule\/#fuzzing-and-exploiting-virtual-channels-in-microsoft-remote-desktop-protocol-for-fun-and-profit-17789"},{"key":"e_1_3_3_121_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN53405.2022.00043"},{"key":"e_1_3_3_122_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM48880.2022.9796755"},{"key":"e_1_3_3_123_2","first-page":"225","volume-title":"23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID)","author":"Peterson Anthony","year":"2020","unstructured":"Anthony Peterson, Samuel Jero, Endadul Hoque, David Choffnes, and Cristina Nita-Rotaru. 2020. aBBRate: Automating BBR attack exploration using a model-based approach. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID). 225\u2013240."},{"key":"e_1_3_3_124_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICST46399.2020.00062"},{"issue":"9","key":"e_1_3_3_125_2","first-page":"1980","article-title":"Smart greybox fuzzing","volume":"47","author":"Pham Van-Thuan","year":"2019","unstructured":"Van-Thuan Pham, Marcel B\u00f6hme, Andrew E. Santosa, Alexandru R\u0103zvan C\u0103ciulescu, and Abhik Roychoudhury. 2019. Smart greybox fuzzing. IEEE Transactions on Software Engineering 47, 9 (2019), 1980\u20131997.","journal-title":"IEEE Transactions on Software Engineering"},{"key":"e_1_3_3_126_2","doi-asserted-by":"publisher","DOI":"10.1145\/3551349.3556946"},{"key":"e_1_3_3_127_2","unstructured":"OpenSSL Project. 2022. OpenSSL. Available: https:\/\/github.com\/openssl\/openssl"},{"key":"e_1_3_3_128_2","doi-asserted-by":"publisher","DOI":"10.1145\/3580598"},{"key":"e_1_3_3_129_2","volume-title":"BlackHat EU 2021","author":"Qu Lewei","year":"2021","unstructured":"Lewei Qu, Dongxiang Ke, Ye Zhang, and Ying Wang. 2021. BadMesher: New attack surfaces of Wi-Fi mesh network. In BlackHat EU 2021."},{"key":"e_1_3_3_130_2","article-title":"Unicorn: Next generation CPU emulator framework","volume":"476","author":"Quynh Nguyen Anh","year":"2015","unstructured":"Nguyen Anh Quynh and Dang Hoang Vu. 2015. Unicorn: Next generation CPU emulator framework. BlackHat USA 476 (2015).","journal-title":"BlackHat USA"},{"key":"e_1_3_3_131_2","doi-asserted-by":"publisher","DOI":"10.1109\/EDOC49727.2020.00026"},{"key":"e_1_3_3_132_2","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427662"},{"key":"e_1_3_3_133_2","doi-asserted-by":"publisher","DOI":"10.1145\/3448300.3468296"},{"key":"e_1_3_3_134_2","first-page":"467","volume-title":"European Symposium on Research in Computer Security (ESORICS)","author":"Ren Mengfei","year":"2023","unstructured":"Mengfei Ren, Haotian Zhang, Xiaolei Ren, Jiang Ming, and Yu Lei. 2023. Intelligent Zigbee protocol fuzzing via constraint-field dependency inference. In European Symposium on Research in Computer Security (ESORICS). 467\u2013486."},{"key":"e_1_3_3_135_2","doi-asserted-by":"crossref","unstructured":"E. Rescorla. 2012. RFC6347: Datagram Transport Layer Security Version 1.2. https:\/\/datatracker.ietf.org\/doc\/html\/rfc6347","DOI":"10.17487\/rfc6347"},{"key":"e_1_3_3_136_2","doi-asserted-by":"publisher","DOI":"10.1109\/CNS53000.2021.9705023"},{"key":"e_1_3_3_137_2","volume-title":"DEFCON 27","author":"Romero Daniel","year":"2019","unstructured":"Daniel Romero and Mario Rivas. 2019. Why you should fear your \u2019mundane\u2019 office equipment. In DEFCON 27."},{"key":"e_1_3_3_138_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23233"},{"key":"e_1_3_3_139_2","first-page":"19","volume-title":"29th USENIX Security Symposium (USENIX Security)","author":"Ruge Jan","unstructured":"Jan Ruge, Jiska Classen, Francesco Gringoli, and Matthias Hollick. 2020. Frankenstein: Advanced wireless fuzzing to exploit new Bluetooth escalation targets. In 29th USENIX Security Symposium (USENIX Security). 19\u201336."},{"key":"e_1_3_3_140_2","doi-asserted-by":"publisher","DOI":"10.1145\/3597926.3604922"},{"key":"e_1_3_3_141_2","doi-asserted-by":"publisher","DOI":"10.1145\/1460412.1460485"},{"key":"e_1_3_3_142_2","doi-asserted-by":"publisher","DOI":"10.1145\/3448300.3468261"},{"key":"e_1_3_3_143_2","doi-asserted-by":"publisher","DOI":"10.1145\/3492321.3519591"},{"key":"e_1_3_3_144_2","first-page":"309","volume-title":"2012 USENIX Annual Technical Conference (USENIX ATC 12)","author":"Serebryany Konstantin","year":"2012","unstructured":"Konstantin Serebryany, Derek Bruening, Alexander Potapenko, and Dmitriy Vyukov. 2012. AddressSanitizer: A fast address sanity checker. In 2012 USENIX Annual Technical Conference (USENIX ATC 12). 309\u2013318."},{"key":"e_1_3_3_145_2","doi-asserted-by":"publisher","DOI":"10.1145\/1791194.1791203"},{"key":"e_1_3_3_146_2","unstructured":"Eric Sesterhenn and Martin J. Muench. 2013. Bruteforce Exploit Detector. Available: https:\/\/gitlab.com\/kalilinux\/packages\/bed"},{"key":"e_1_3_3_147_2","doi-asserted-by":"crossref","unstructured":"Z. Shelby. 2014. RFC7252: The Constrained Application Protocol (CoAP). https:\/\/www.rfc-editor.org\/rfc\/rfc7252","DOI":"10.17487\/rfc7252"},{"key":"e_1_3_3_148_2","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616614"},{"key":"e_1_3_3_149_2","first-page":"7019","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Shi Qingkai","year":"2023","unstructured":"Qingkai Shi, Xiangzhe Xu, and Xiangyu Zhang. 2023. Extracting protocol format as state machine via controlled static loop analysis. In 32nd USENIX Security Symposium (USENIX Security 23). 7019\u20137036."},{"key":"e_1_3_3_150_2","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329801"},{"key":"e_1_3_3_151_2","unstructured":"Bluetooth SIG. 2016. Bluetooth Core Specifications.https:\/\/www.bluetooth.com\/specifications\/bluetooth-core-specification"},{"key":"e_1_3_3_152_2","volume-title":"BlackHat US 2017","author":"Sommer Manuel","year":"2017","unstructured":"Manuel Sommer, Nicholas Gray, Phuoc Tran-Gia, and Thomas Zinner. 2017. FlowFuzz: A framework for fuzzing openflow-enabled software and hardware switches. In BlackHat US 2017."},{"key":"e_1_3_3_153_2","volume-title":"DEFCON 26","author":"Sommer Manuel","year":"2018","unstructured":"Manuel Sommer, Nicholas Gray, Phuoc Tran-Gia, and Thomas Zinner. 2018. Designing and applying extensible RF fuzzing tools to expose PHY layer vulnerabilities. In DEFCON 26."},{"key":"e_1_3_3_154_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978411"},{"key":"e_1_3_3_155_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00010"},{"key":"e_1_3_3_156_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2014.2323977"},{"key":"e_1_3_3_157_2","volume-title":"DEFCON 30","author":"Song Jonghyuk","year":"2022","unstructured":"Jonghyuk Song, Soohwan Oh, and Woongjo Choi. 2022. Automotive Ethernet fuzzing: From purchasing ECU to SOME\/IP fuzzing. In DEFCON 30."},{"key":"e_1_3_3_158_2","doi-asserted-by":"publisher","DOI":"10.1109\/CGO.2015.7054186"},{"key":"e_1_3_3_159_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23368"},{"key":"e_1_3_3_160_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23286"},{"key":"e_1_3_3_161_2","doi-asserted-by":"publisher","DOI":"10.1145\/3092703.3092706"},{"key":"e_1_3_3_162_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2018.8422949"},{"key":"e_1_3_3_163_2","first-page":"719","volume-title":"16th USENIX Symposium on Networked Systems Design and Implementation (NSDI 19)","author":"Sun Wei","year":"2019","unstructured":"Wei Sun, Lisong Xu, Sebastian Elbaum, and Di Zhao. 2019. Model-agnostic and efficient exploration of numerical state space of real-world TCP congestion control implementations. In 16th USENIX Symposium on Networked Systems Design and Implementation (NSDI 19). 719\u2013734."},{"key":"e_1_3_3_164_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3228076"},{"key":"e_1_3_3_165_2","volume-title":"Satellite Networking: Principles and Protocols (2nd ed.)","author":"Sun Zhili","year":"2014","unstructured":"Zhili Sun. 2014. Satellite Networking: Principles and Protocols (2nd ed.). Wiley Publishing."},{"key":"e_1_3_3_166_2","article-title":"Sequence to sequence learning with neural networks","volume":"27","author":"Sutskever Ilya","year":"2014","unstructured":"Ilya Sutskever, Oriol Vinyals, and Quoc V. Le. 2014. Sequence to sequence learning with neural networks. Advances in Neural Information Processing Systems 27 (2014).","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_3_167_2","unstructured":"Inc. Synopsys. 2014. Heartbleed Vulnerability. Available: https:\/\/heartbleed.com\/"},{"key":"e_1_3_3_168_2","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2014.2331672"},{"key":"e_1_3_3_169_2","doi-asserted-by":"publisher","DOI":"10.1145\/2483760.2483787"},{"key":"e_1_3_3_170_2","volume-title":"BlackHat US 2017","author":"Vanhoef Mathy","year":"2017","unstructured":"Mathy Vanhoef. 2017. WiFuzz: Detecting and exploiting logical flaws in the Wi-Fi cryptographic handshake. In BlackHat US 2017."},{"key":"e_1_3_3_171_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2017.2763947"},{"key":"e_1_3_3_172_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.23"},{"key":"e_1_3_3_173_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00211"},{"key":"e_1_3_3_174_2","first-page":"4205","volume-title":"30th USENIX Security Symposium (USENIX Security)","author":"Wang Qinying","year":"2021","unstructured":"Qinying Wang, Shouling Ji, Yuan Tian, Xuhong Zhang, Binbin Zhao, Yuhong Kan, Zhaowei Lin, Changting Lin, Shuiguang Deng, Alex X. Liu, and Raheem Beyah. 2021. MPInspector: A systematic and automatic approach for evaluating the security of IoT messaging protocols. In 30th USENIX Security Symposium (USENIX Security). 4205\u20134222."},{"key":"e_1_3_3_175_2","article-title":"NLP-based cross-layer 5G vulnerabilities detection via fuzzing generated run-time profiling","author":"Wang Zhuzhu","year":"2023","unstructured":"Zhuzhu Wang and Ying Wang. 2023. NLP-based cross-layer 5G vulnerabilities detection via fuzzing generated run-time profiling. arXiv:2305.08226 (2023).","journal-title":"arXiv:2305.08226"},{"key":"e_1_3_3_176_2","doi-asserted-by":"publisher","DOI":"10.1145\/3650212.3680394"},{"key":"e_1_3_3_177_2","volume-title":"BlackHat Asia 2021","author":"Wu Huiyu","year":"2021","unstructured":"Huiyu Wu and Yuxiang Li. 2021. X-in-the-Middle: Attacking fast charging piles and electric vehicles. In BlackHat Asia 2021."},{"key":"e_1_3_3_178_2","first-page":"339","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Wu Jianliang","year":"2021","unstructured":"Jianliang Wu, Ruoyu Wu, Daniele Antonioli, Mathias Payer, Nils Ole Tippenhauer, Dongyan Xu, Dave (Jing) Tian, and Antonio Bianchi. 2021. LIGHTBLUE: Automatic profile-aware debloating of Bluetooth stacks. In 30th USENIX Security Symposium (USENIX Security 21). 339\u2013356."},{"key":"e_1_3_3_179_2","volume-title":"BlackHat Asia 2020","author":"Xie Haikuo","year":"2020","unstructured":"Haikuo Xie, Ying Wang, and Ye Zhang. 2020. WIFI-Important remote attack surface: Threat is expanding. In BlackHat Asia 2020."},{"key":"e_1_3_3_180_2","volume-title":"BlackHat US 2022","author":"Yan Han","year":"2022","unstructured":"Han Yan, Lewei Qu, and Dongxiang Ke. 2022. BrokenMesh: New attack surfaces of Bluetooth Mesh. In BlackHat US 2022."},{"key":"e_1_3_3_181_2","first-page":"349","volume-title":"15th USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Yang Youngseok","year":"2021","unstructured":"Youngseok Yang, Taesoo Kim, and Byung-Gon Chun. 2021. Finding consensus bugs in Ethereum via multi-transaction differential fuzzing. In 15th USENIX Symposium on Operating Systems Design and Implementation (OSDI). 349\u2013365."},{"key":"e_1_3_3_182_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2971712"},{"key":"e_1_3_3_183_2","doi-asserted-by":"publisher","DOI":"10.1145\/3597926.3598057"},{"key":"e_1_3_3_184_2","volume-title":"BlackHat EU 2021","author":"Yen Ta-Lun","year":"2021","unstructured":"Ta-Lun Yen, Federico Maggi, Erik Boasson, Victor Mayoral-Vilches, Mars Cheng, Patrick Kuo, and Chizuru Toyama. 2021. The data distribution service (DDS) protocol is critical let\u2019s use it securely!. In BlackHat EU 2021."},{"key":"e_1_3_3_185_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363247"},{"key":"e_1_3_3_186_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS57875.2023.00132"},{"key":"e_1_3_3_187_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2022.3183952"},{"key":"e_1_3_3_188_2","first-page":"745","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Yun Insu","year":"2018","unstructured":"Insu Yun, Sangho Lee, Meng Xu, Yeongjin Jang, and Taesoo Kim. 2018. QSYM: A practical concolic execution engine tailored for hybrid fuzzing. In 27th USENIX Security Symposium (USENIX Security 18). 745\u2013761."},{"key":"e_1_3_3_189_2","unstructured":"Michal Zalewski. 2015. American fuzzy lop. https:\/\/github.com\/google\/AFL"},{"key":"e_1_3_3_190_2","unstructured":"zardus. 2019. Preeny: Some helpful preload libraries for pwning stuff. https:\/\/github.com\/zardus\/preeny"},{"key":"e_1_3_3_191_2","doi-asserted-by":"publisher","DOI":"10.5555\/3620237.3620398"},{"key":"e_1_3_3_192_2","first-page":"2811","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Zhang Cen","year":"2021","unstructured":"Cen Zhang, Xingwei Lin, Yuekang Li, Yinxing Xue, Jundong Xie, Hongxu Chen, Xinlei Ying, Jiashui Wang, and Yang Liu. 2021. APICraft: Fuzz driver generation for closed-source SDK libraries. In 30th USENIX Security Symposium (USENIX Security 21). 2811\u20132828."},{"key":"e_1_3_3_193_2","doi-asserted-by":"publisher","DOI":"10.1145\/3650212.3680355"},{"issue":"2","key":"e_1_3_3_194_2","first-page":"1","article-title":"Fuzzing configurations of program options","volume":"32","author":"Zhang Zenong","year":"2023","unstructured":"Zenong Zhang, George Klees, Eric Wang, Michael Hicks, and Shiyi Wei. 2023. Fuzzing configurations of program options. ACM Trans. Softw. Eng. Methodol. 32, 2 (2023), 1\u201321.","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"e_1_3_3_195_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2019.00016"},{"key":"e_1_3_3_196_2","doi-asserted-by":"publisher","DOI":"10.1145\/3649854"},{"key":"e_1_3_3_197_2","doi-asserted-by":"publisher","DOI":"10.1145\/3533767.3534414"},{"key":"e_1_3_3_198_2","doi-asserted-by":"crossref","first-page":"356","DOI":"10.1007\/978-3-031-09234-3_18","volume-title":"Applied Cryptography and Network Security: 20th International Conference (ACNS)","volume":"13269","author":"Zheng Yaowen","year":"2022","unstructured":"Yaowen Zheng and Limin Sun. 2022. IPSpex: Enabling efficient fuzzing via specification extraction on ICS protocol. In Applied Cryptography and Network Security: 20th International Conference (ACNS), Vol. 13269. 356."},{"key":"e_1_3_3_199_2","doi-asserted-by":"publisher","DOI":"10.1145\/3512345"},{"key":"e_1_3_3_200_2","unstructured":"Qingtian Zou Anoop Singhal Xiaoyan Sun and Peng Liu. 2020. Generating comprehensive data with protocol fuzzing for applying deep learning to detect network attacks. (2020). arXiv:2012.12743"},{"key":"e_1_3_3_201_2","first-page":"489","volume-title":"2021 USENIX Annual Technical Conference (USENIX ATC)","author":"Zou Yong-Hao","unstructured":"Yong-Hao Zou, Jia-Ju Bai, Jielong Zhou, Jianfeng Tan, Chenggang Qin, and Shi-Min Hu. 2021. TCP-Fuzz: Detecting memory and semantic bugs in TCP stacks with fuzzing. In 2021 USENIX Annual Technical Conference (USENIX ATC). 489\u2013502."},{"key":"e_1_3_3_202_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2022.3201471"},{"key":"e_1_3_3_203_2","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18074.2021.9586321"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3696788","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3696788","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:57:45Z","timestamp":1750294665000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3696788"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,10]]},"references-count":202,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2025,2,28]]}},"alternative-id":["10.1145\/3696788"],"URL":"https:\/\/doi.org\/10.1145\/3696788","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,10,10]]},"assertion":[{"value":"2022-12-08","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-09-12","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-10-10","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}