{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,25]],"date-time":"2026-03-25T21:07:15Z","timestamp":1774472835147,"version":"3.50.1"},"reference-count":50,"publisher":"MDPI AG","issue":"18","license":[{"start":{"date-parts":[[2020,9,11]],"date-time":"2020-09-11T00:00:00Z","timestamp":1599782400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61902098"],"award-info":[{"award-number":["61902098"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The publish\/subscribe model has gained prominence in the Internet of things (IoT) network, and both Message Queue Telemetry Transport (MQTT) and Constrained Application Protocol (CoAP) support it. However, existing coverage-based fuzzers may miss some paths when fuzzing such publish\/subscribe protocols, because they implicitly assume that there are only two parties in a protocol, which is not true now since there are three parties, i.e., the publisher, the subscriber and the broker. In this paper, we propose MultiFuzz, a new coverage-based multiparty-protocol fuzzer. First, it embeds multiple-connection information in a single input. Second, it uses a message mutation algorithm to stimulate protocol state transitions, without the need of protocol specifications. Third, it uses a new desockmulti module to feed the network messages into the program under test. desockmulti is similar to desock (Preeny), a tool widely used by the community, but it is specially designed for fuzzing and is 10x faster. We implement MultiFuzz based on AFL, and use it to fuzz two popular projects Eclipse Mosquitto and libCoAP. We reported discovered problems to the projects. In addition, we compare MultiFuzz with AFL and two state-of-the-art fuzzers, MOPT and AFLNET, and find it discovering more paths and crashes.<\/jats:p>","DOI":"10.3390\/s20185194","type":"journal-article","created":{"date-parts":[[2020,9,13]],"date-time":"2020-09-13T21:11:32Z","timestamp":1600031492000},"page":"5194","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":29,"title":["MultiFuzz: A Coverage-Based Multiparty-Protocol Fuzzer for IoT Publish\/Subscribe Protocols"],"prefix":"10.3390","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6294-4889","authenticated-orcid":false,"given":"Yingpei","family":"Zeng","sequence":"first","affiliation":[{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou 310000, China"},{"name":"State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing 210000, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mingmin","family":"Lin","sequence":"additional","affiliation":[{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou 310000, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shanqing","family":"Guo","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Shandong University, Jinan 250000, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yanzhao","family":"Shen","sequence":"additional","affiliation":[{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou 310000, China"},{"name":"Science and Technology on Communication Security Laboratory, Chengdu 610041, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tingting","family":"Cui","sequence":"additional","affiliation":[{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou 310000, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ting","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou 310000, China"},{"name":"Hangzhou Innovation Institute, Beihang University, Hangzhou 310000, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qiuhua","family":"Zheng","sequence":"additional","affiliation":[{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou 310000, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qiuhua","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou 310000, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2020,9,11]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1145\/96267.96279","article-title":"An Empirical Study of the Reliability of UNIX Utilities","volume":"33","author":"Miller","year":"1990","journal-title":"Commun. ACM."},{"key":"ref_2","unstructured":"Manes, V.J.M., Han, H.S., Han, C., Cha, S.K., Egele, M., Schwartz, E.J., and Woo, M. (2019). The Art, Science, and Engineering of Fuzzing: A Survey. IEEE T. Software. Eng., 1\u201321."},{"key":"ref_3","unstructured":"Zalewski, M. (2020, July 29). AFL\u2014American Fuzzy Lop. Available online: http:\/\/lcamtuf.coredump.cx\/afl\/."},{"key":"ref_4","unstructured":"(2020, July 29). libFuzzer. Available online: http:\/\/llvm.org\/docs\/LibFuzzer.html."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"B\u00f6hme, M., Pham, V.T., and Roychoudhury, A. (2016, January 24\u201328). Coverage-based Greybox Fuzzing as Markov Chain. Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS), Vienna, Austria.","DOI":"10.1145\/2976749.2978428"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"1199","DOI":"10.1109\/TR.2018.2834476","article-title":"Fuzzing: State of the Art","volume":"67","author":"Liang","year":"2018","journal-title":"IEEE T. Reliab."},{"key":"ref_7","unstructured":"(2020, July 29). zzuf. Available online: http:\/\/caca.zoy.org\/wiki\/zzuf."},{"key":"ref_8","unstructured":"Peach Tech (2020, July 29). Peach Fuzzer. Available online: https:\/\/www.peach.tech."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Godefroid, P., Kiezun, A., and Levin, M.Y. (2008, January 7\u201313). Grammar-based whitebox fuzzing. Proceedings of the ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI), Tucson, AZ, USA.","DOI":"10.1145\/1375581.1375607"},{"key":"ref_10","unstructured":"Google Security Team (2020, July 29). A New Chapter for OSS-Fuzz. Available online: https:\/\/security.googleblog.com\/2018\/11\/a-new-chapter-for-oss-fuzz.html."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Gan, S., Zhang, C., Qin, X., Tu, X., Li, K., Pei, Z., and Chen, Z. (2018, January 21\u201323). CollAFL: Path Sensitive Fuzzing. Proceedings of the IEEE Symposium on Security and Privacy (S&P), San Francisco, CA, USA.","DOI":"10.1109\/SP.2018.00040"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Chen, P., and Chen, H. (2018, January 21\u201323). Angora: Efficient Fuzzing by Principled Search. Proceedings of the IEEE Symposium on Security and Privacy (S&P), San Francisco, CA, USA.","DOI":"10.1109\/SP.2018.00046"},{"key":"ref_13","unstructured":"Yun, I., Lee, S., Xu, M., Jang, Y., and Kim, T. (2018, January 15\u201317). QSYM: A Practical Concolic Execution Engine Tailored for Hybrid Fuzzing. Proceedings of the 27th USENIX Security Symposium (Security), Baltimore, MD, USA."},{"key":"ref_14","unstructured":"Lyu, C., Ji, S., Zhang, C., Li, Y., Lee, W.H., Song, Y., and Beyah, R. (2019, January 14\u201316). MOPT: Optimize Mutation Scheduling for Fuzzers. Proceedings of the 28th USENIX Security Symposium (Security), Santa Clara, CA, USA."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Pham, V.t., Boehme, M., and Roychoudhury, A. (2020, January 24\u201328). AFLNet: A Greybox Fuzzer for Network Protocols. Proceedings of the 13rd IEEE International Conference on Software Testing, Verification and Validation: Testing Tools Track, Porto, Portugal.","DOI":"10.1109\/ICST46399.2020.00062"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Aschermann, C., Schumilo, S., Abbasi, A., and Holz, T. (2020, January 17\u201321). IJON: Exploring Deep State Spaces via Fuzzing. Proceedings of the IEEE Symposium on Security and Privacy (S&P), San Francisco, CA, USA.","DOI":"10.1109\/SP40000.2020.00117"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"2347","DOI":"10.1109\/COMST.2015.2444095","article-title":"Internet of Things: A Survey on Enabling Technologies, Protocols, and Applications","volume":"17","author":"Guizani","year":"2015","journal-title":"IEEE. Commun. Surv. Tutor."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Yassein, M.B., Shatnawi, M.Q., and Al-Zoubi, D. (2016, January 22\u201324). Application layer protocols for the Internet of Things: A survey. Proceedings of the 2016 International Conference on Engineering and MIS (ICEMIS), Agadir, Morocco.","DOI":"10.1109\/ICEMIS.2016.7745303"},{"key":"ref_19","first-page":"1","article-title":"A survey of communication protocols for internet of things and related challenges of fog and cloud computing integration","volume":"51","author":"Carpio","year":"2019","journal-title":"ACM. Comput. Surv."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"19582","DOI":"10.3390\/s141019582","article-title":"Towards efficient mobile M2M communications: Survey and open challenges","volume":"14","author":"Pereira","year":"2014","journal-title":"Sensors"},{"key":"ref_21","unstructured":"Banks, A., Briggs, E., Borgendale, K., and Gupta, R. (2019). MQTT Version 5.0, OASIS Standard."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Shelby, Z., Hartke, K., and Bormann, C. (2014). The Constrained Application Protocol (CoAP). RFC 7252 2014, Internet Engineering Task Force (IETF).","DOI":"10.17487\/rfc7252"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Hartke, K. (2015). Observing Resources in the Constrained Application Protocol (CoAP). RFC 7641 2015, Internet Engineering Task Force (IETF).","DOI":"10.17487\/RFC7641"},{"key":"ref_24","unstructured":"Team, T.H. (2020, July 29). Comparison of MQTT Support by IoT Cloud Platforms. Available online: https:\/\/www.hivemq.com\/blog\/hivemq-cloud-vs-aws-iot\/."},{"key":"ref_25","unstructured":"Ptone (2020, July 29). IoT Core CoAP proxy demonstration. Available online: https:\/\/cloud.google.com\/community\/tutorials\/cloud-iot-coap-proxy."},{"key":"ref_26","unstructured":"(2020, July 29). Boofuzz: Network Protocol Fuzzing for Humans. Available online: https:\/\/github.com\/jtpereyda\/boofuzz."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Somorovsky, J. (2016, January 24\u201328). Systematic Fuzzing and Testing of TLS Libraries. Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS), Vienna, Austria.","DOI":"10.1145\/2976749.2978411"},{"key":"ref_28","unstructured":"(2020, July 29). Preeny. Available online: https:\/\/github.com\/zardus\/preeny."},{"key":"ref_29","unstructured":"(2020, July 29). Eclipse Mosquitto. Available online: https:\/\/mosquitto.org\/."},{"key":"ref_30","unstructured":"(2020, July 29). libcoap. Available online: https:\/\/libcoap.net\/."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Klees, G., Ruef, A., Cooper, B., Wei, S., and Hicks, M. (2018, January 15\u201319). Evaluating Fuzz Testing. Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS), Toronto, ON, Canada.","DOI":"10.1145\/3243734.3243804"},{"key":"ref_32","unstructured":"Godefroid, P., Levin, M.Y., and Molnar, D. (2008, January 10\u201313). Automated whitebox fuzz testing. Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA."},{"key":"ref_33","unstructured":"Aitel, D. (2002). The Advantages of Block-Based Protocol Analysis for Security Testing, Technical Report; Immunity Inc."},{"key":"ref_34","unstructured":"Roning, J., Laakso, M., and Takanen, A. (2020, July 29). PROTOS Presentations. Available online: https:\/\/www.ee.oulu.fi\/research\/ouspg\/."},{"key":"ref_35","unstructured":"Banks, G., Cova, M., Felmetsger, V., Almeroth, K.C., Kemmerer, R.A., and Vigna, G. (September, January 30). SNOOZE: Toward a Stateful NetwOrk prOtocol fuzZEr. Proceedings of the Information Security, 9th International Conference (ISC), Samos Island, Greece."},{"key":"ref_36","unstructured":"Bratus, S., Hansen, A., and Shubina, A. (2008). LZfuzz: A fast Compression-Based Fuzzer for Poorly Documented Protocols, Department of Computer Science, Dartmouth College. Technical Report."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Voyiatzis, A.G., Katsigiannis, K., and Koubias, S. (2015, January 8\u201311). A Modbus\/TCP Fuzzer for testing internetworked industrial systems. Proceedings of the IEEE International Conference on Emerging Technologies and Factory Automation (ETFA), Luxembourg.","DOI":"10.1109\/ETFA.2015.7301400"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Chen, J., Diao, W., Zhao, Q., Zuo, C., Lin, Z., Wang, X., Lau, W.C., Sun, M., Yang, R., and Zhang, K. (2018, January 18\u201321). IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based Fuzzing. Proceedings of the 25th Annual Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA.","DOI":"10.14722\/ndss.2018.23159"},{"key":"ref_39","unstructured":"Zheng, Y., Davanian, A., Yin, H., Song, C., Zhu, H., and Sun, L. (2019, January 14\u201316). FIRM-AFL: High-throughput greybox fuzzing of IoT firmware via augmented process emulation. Proceedings of the 28th USENIX Security Symposium (Security), Santa Clara, CA, USA."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Hern\u00e1ndez Ramos, S., Villalba, M.T., and Lacuesta, R. (2018). MQTT Security: A Novel Fuzzing Approach. Wirel. Commun. Mob. Com., 2018.","DOI":"10.1155\/2018\/8261746"},{"key":"ref_41","unstructured":"(2020, July 29). mqtt_fuzz tool. Available online: https:\/\/github.com\/F-Secure\/mqtt_fuzz."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"7648","DOI":"10.3390\/s120607648","article-title":"A Communication model to integrate the Request-Response and the publish-subscribe paradigms into ubiquitous systems","volume":"12","author":"Benghazi","year":"2012","journal-title":"Sensors"},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"648","DOI":"10.3390\/s130100648","article-title":"Improving packet delivery performance of publish\/subscribe protocols in wireless sensor networks","volume":"13","author":"Davis","year":"2013","journal-title":"Sensors"},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Akasiadis, C., Pitsilis, V., and Spyropoulos, C.D. (2019). A multi-protocol IoT platform based on open-source frameworks. Sensors, 19.","DOI":"10.3390\/s19194217"},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Larmo, A., Ratilainen, A., and Saarinen, J. (2019). Impact of CoAP and MQTT on NB-IoT system performance. Sensors, 19.","DOI":"10.3390\/s19010007"},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Bormann, C., Lemay, S., Tschofenig, H., Hartke, K., Silverajan, B., and Raymor, B. (2018). CoAP (Constrained Application Protocol) over TCP, TLS, and WebSockets. RFC 8323 2018, Internet Engineering Task Force (IETF).","DOI":"10.17487\/RFC8323"},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Houimli, M., Kahloul, L., and Benaoun, S. (2017, January 4\u20135). Formal specification, verification and evaluation of the MQTT protocol in the Internet of Things. Proceedings of the 2017 International Conference on Mathematics and Information Technology (ICMIT), Adrar, Algeria.","DOI":"10.1109\/MATHIT.2017.8259720"},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Vaccari, I., Aiello, M., and Cambiaso, E. (2020). SlowITe, a novel denial of service attack affecting MQTT. Sensors, 20.","DOI":"10.3390\/s20102932"},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Granjal, J., Silva, J.M., and Louren\u00e7o, N. (2018). Intrusion detection and prevention in CoAP wireless sensor networks using anomaly detection. Sensors, 18.","DOI":"10.3390\/s18082445"},{"key":"ref_50","unstructured":"Serebryany, K., Bruening, D., Potapenko, A., and Vyukov, D. (2012, January 13\u201315). AddressSanitizer: A fast address sanity checker. Proceedings of the USENIX Annual Technical Conference (ATC), Boston, MA, USA."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/18\/5194\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T10:09:18Z","timestamp":1760177358000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/18\/5194"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,9,11]]},"references-count":50,"journal-issue":{"issue":"18","published-online":{"date-parts":[[2020,9]]}},"alternative-id":["s20185194"],"URL":"https:\/\/doi.org\/10.3390\/s20185194","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,9,11]]}}}