Netinfo Security ›› 2025, Vol. 25 ›› Issue (12): 1847-1862.doi: 10.3969/j.issn.1671-1122.2025.12.002
Previous Articles Next Articles
YANG Liqun1,2,3(
), LI Zhen1, WEI Chaoren1, YAN Zhimin1, QIU Yongxin1
Received:2025-08-23
Online:2025-12-10
Published:2026-01-06
Contact:
YANG Liqun
E-mail:lqyang@buaa.edu.cn
CLC Number:
YANG Liqun, LI Zhen, WEI Chaoren, YAN Zhimin, QIU Yongxin. Research on Protocol Fuzzing Technology Guided by Large Language Models[J]. Netinfo Security, 2025, 25(12): 1847-1862.
Add to citation manager EndNote|Ris|BibTeX
URL: http://netinfo-security.org/EN/10.3969/j.issn.1671-1122.2025.12.002
| [1] | BA J, BÖHME M, MIRZAMOMEN Z, et al. Stateful Greybox Fuzzing[C]// USENIX. The 31st USENIX Security Symposium. Berkely: USENIX Association, 2022: 3255-3272. |
| [2] | LU Liyu, LIU Yuan, HONG Chao, et al. Screening Method of Fuzzy Test Seeds Based on Impact Orientation[J]. Network Security Technology & Application, 2024(2): 44-46. |
| 陆力瑜, 刘媛, 洪超, 等. 基于影响性导向的模糊测试种子筛选方法[J]. 网络安全技术与应用, 2024(2):44-46. | |
| [3] |
MILLER B P, ZHANG Mengxiao, HEYMANN E R. The Relevance of Classic Fuzz Testing: Have We Solved this One?[J]. IEEE Transactions on Software Engineering, 2022, 48(6): 2028-2039.
doi: 10.1109/TSE.2020.3047766 URL |
| [4] |
MANÈS V J M, HAN H, HAN C, et al. The Art, Science, and Engineering of Fuzzing: A Survey[J]. IEEE Transactions on Software Engineering, 2021, 47(11): 2312-2331.
doi: 10.1109/TSE.2019.2946563 URL |
| [5] | ZHANG Xiaohan, ZHANG Cen, LI Xinghua, et al. A Survey of Protocol Fuzzing[J]. ACM Computing Surveys, 2024, 57(2): 1-36. |
| [6] |
ZHAO Yiru, GAO Long, WEI Qiang, et al. Towards Tightly-Coupled Hybrid Fuzzing via Excavating Input Specifications[J]. IEEE Transactions on Dependable and Secure Computing, 2024, 21(5): 4801-4814.
doi: 10.1109/TDSC.2024.3361008 URL |
| [7] | PHAM V, BÖHME M, ROYCHOUDHURY A. AFLNet: A Greybox Fuzzer for Network Protocols[C]// IEEE. The 13th IEEE International Conference on Software Testing, Verification and Validation (ICST). New York: IEEE, 2020: 460-465. |
| [8] |
LUO Zhengxiong, YU Junze, DU Qingpeng, et al. Parallel Fuzzing of IoT Messaging Protocols through Collaborative Packet Generation[J]. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, 2024, 43(11): 3431-3442.
doi: 10.1109/TCAD.2024.3444705 URL |
| [9] |
MENG Ruijie, PHAM V-T, BÖHME M, et al. AFLNet Five Years Later: On Coverage-Guided Protocol Fuzzing[J]. IEEE Transactions on Software Engineering, 2025, 51(4): 960-974.
doi: 10.1109/TSE.2025.3535925 URL |
| [10] | Website. American Fuzzy Lop (AFL) Fuzzer[EB/OL]. [2025-07-30]. http://lcamtuf.coredump.cx/afl. |
| [11] |
LI Junqiang, LI Senyi, SUN Gang, et al. SNPSFuzzer: A Fast Greybox Fuzzer for Stateful Network Protocols Using Snapshots[J]. IEEE Transactions on Information Forensics and Security, 2022, 17: 2673-2687.
doi: 10.1109/TIFS.2022.3192991 URL |
| [12] | ANDRONIDIS A, CADAR C. SnapFuzz: High-Throughput Fuzzing of Network Applications[C]// ACM. The 31st ACM SIGSOFT International Symposium on Software Testing and Analysis. New York: ACM, 2022: 340-351. |
| [13] | QIN Shisong, HU Fan, MA Zheyu, et al. NSFuzz: Towards Efficient and State-Aware Network Service Fuzzing[J]. ACM Transactions on Software Engineering and Methodology, 2023, 32(6): 1-26. |
| [14] |
HUANG Tao, GAO Yansong, ZHENG Yifeng, et al. FineBID: Fine-Grained Protocol Reverse Engineering for Bit-Level Field Identification[J]. IEEE Transactions on Dependable and Secure Computing, 2025, 22(3): 2670-2686.
doi: 10.1109/TDSC.2024.3521592 URL |
| [15] |
KIM J, SEO M, MARIN E, et al. Ambusher: Exploring the Security of Distributed SDN Controllers through Protocol State Fuzzing[J]. IEEE Transactions on Information Forensics and Security, 2024, 19: 6264-6279.
doi: 10.1109/TIFS.2024.3402967 URL |
| [16] |
ZHANG Qingyu, LIN Jiayi, SUN Chenxin, et al. CherryPicker: A Parallel Solving and State Sharing Hybrid Fuzzing System[J]. IEEE Transactions on Dependable and Secure Computing, 2025, 22(4): 3324-3336.
doi: 10.1109/TDSC.2025.3530010 URL |
| [17] | HONG Xuanquan, JIA Peng, LIU Jiayong. AFLNeTrans: Fuzzing of Protocols with State Relationship Awareness[J]. Netinfo Security, 2024, 24(1): 121-132. |
| 洪玄泉, 贾鹏, 刘嘉勇. AFLNeTrans:状态间关系感知的网络协议模糊测试[J]. 信息网络安全, 2024, 24(1):121-132. | |
| [18] | VASWANI A, SHAZEER N, PARMAR N, et al. Attention is All You Need[C]// ACM. The 31st International Conference on Neural Information Processing Systems (NIPS’17). New York: ACM, 2017: 6000-6010. |
| [19] | BROWN T, MANN B, RYDER N, et al. Language Models are Few-Shot Learners[C]// ACM. The 34th International Conference on Neural Information Processing Systems (NIPS ‘20). New York: ACM, 2020: 1877-1901. |
| [20] |
ZHU Xiaogang, ZHOU Wei, HAN Q, et al. When Software Security Meets Large Language Models: A Survey[J]. IEEE/CAA Journal of Automatica Sinica, 2025, 12(2): 317-334.
doi: 10.1109/JAS.2024.124971 URL |
| [21] | LEMIEUX C, INALA J, LAHIRI S, et al. Codamosa: Escaping Coverage Plateaus in Test Generation with Pre-Trained Large Language Models[C]// IEEE. The 45th IEEE/ACM International Conference on Software Engineering (ICSE). New York: IEEE, 2023: 919-931. |
| [22] | DENG Yinlin, XIA C S, PENG Haoran, et al. Large Language Models are Zero-Shot Fuzzers: Fuzzing Deep-Learning Libraries via Large Language Models[C]// ACM. The 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis(ISSTA 2023). New York: ACM, 2023: 423-435. |
| [23] | DENG Yinlin, XIA C S, YANG Chenyuan, et al. Large Language Models are Edge-Case Generators: Crafting Unusual Programs for Fuzzing Deep Learning Libraries[C]// ACM. The IEEE/ACM 46th International Conference on Software Engineering (ICSE’24). New York: ACM, 2024: 1-13. |
| [24] |
ZHANG Qiang, SHEN Yuheng, LIU Jianzhong, et al. ECG: Augmenting Embedded Operating System Fuzzing via LLM-Based Corpus Generation[J]. IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, 2024, 43(11): 4238-4249.
doi: 10.1109/TCAD.2024.3447220 URL |
| [25] |
SHAHRIAR A, HISHAM S J, RAHMAN K M A, et al. 5GPT: 5G Vulnerability Detection by Combining Zero-Shot Capabilities of GPT-4 with Domain Aware Strategies through Prompt Engineering[J]. IEEE Transactions on Information Forensics and Security, 2025, 20: 7045-7060.
doi: 10.1109/TIFS.2025.3586480 URL |
| [26] |
ZHENG Tao, SHAO Jiang, DAI Jinqiao, et al. RESTLess: Enhancing State-of-the-Art REST API Fuzzing with LLMs in Cloud Service Computing[J]. IEEE Transactions on Services Computing, 2024, 17(6): 4225-4238.
doi: 10.1109/TSC.2024.3489441 URL |
| [27] | WANG Jincheng, YU Le, LUO Xiapu. LLMIF: Augmented Large Language Model for Fuzzing IoT Devices[C]// IEEE. The 2024 IEEE Symposium on Security and Privacy (SP). New York: IEEE, 2024: 881-896. |
| [28] | YANG Liqun, WEI Chaoren, YANG Jian, et al. Code Large Language Model-Based Fuzz Testing for Industrial IoT Programs[J]. IEEE Internet of Things Journal, 2024: 1-11. |
| [29] | PIYUSH J, JOSEPH S, JAYA S G, et al. BertRLFuzzer: A BERT and Reinforcement Learning Based Fuzzer[C]// ACM. The Thirty-Eighth AAAI Conference on Artificial Intelligence and Thirty-Sixth Conference on Innovative Applications of Artificial Intelligence and Fourteenth Symposium on Educational Advances in Artificial Intelligence (AAAI’24/IAAI’24/EAAI’24). New York: ACM, 2024: 23521-23522. |
| [30] | YANG Chenyuan, DENG Yinlin, LU Runyu, et al. WhiteFox: White-Box Compiler Fuzzing Empowered by Large Language Models[C]// ACM. The ACM on Programming Languages. New York: ACM, 2024, 8(2): 709-735. |
| [31] | EOM J, JEONG S, KWON T. Fuzzing JavaScript Interpreters with Coverage-Guided Reinforcement Learning for LLM-Based Mutation[C]// ACM. The 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA 2024). New York: ACM, 2024: 1656-1668. |
| [32] | XIA C S, PALTENGHI M, TIAN Jiale, et al. Fuzz4All: Universal Fuzzing with Large Language Models[C]// ACM. The 46th International Conference on Software Engineering. New York: ACM, 2024: 1-13. |
| [33] |
YE Kai, ZHU Xiaogang, XIAO Xi, et al. BazzAFL: Moving Fuzzing Campaigns towards Bugs via Grouping Bug-Oriented Seeds[J]. IEEE Transactions on Dependable and Secure Computing, 2025, 22(1): 179-191.
doi: 10.1109/TDSC.2024.3391795 URL |
| [34] |
LI Yuwei, JI Shouling, LYU Chenyang, et al. V-Fuzz: Vulnerability Prediction-Assisted Evolutionary Fuzzing for Binary Programs[J]. IEEE Transactions on Cybernetics, 2022, 52(5): 3745-3756.
doi: 10.1109/TCYB.2020.3013675 URL |
| [1] | WANG Lei, CHEN Jiongyi, WANG Jian, FENG Yuan. Intelligent Reverse Analysis Method of Firmware Program Interaction Relationships Based on Taint Analysis and Textual Semantics [J]. Netinfo Security, 2025, 25(9): 1385-1396. |
| [2] | FENG Wei, XIAO Wenming, TIAN Zheng, LIANG Zhongjun, JIANG Bin. Research on Semantic Intelligent Recognition Algorithms for Meteorological Data Based on Large Language Models [J]. Netinfo Security, 2025, 25(7): 1163-1171. |
| [3] | ZHANG Xuewang, LU Hui, XIE Haofei. A Data Augmentation Method Based on Graph Node Centrality and Large Model for Vulnerability Detection [J]. Netinfo Security, 2025, 25(4): 550-563. |
| [4] | CHANG Zhenxuan, ZHENG Zhihan, MEI Aohan, TAN Yu’an. An Efficient Gray-Box Fuzzing Approach for Firmware Network Applications [J]. Netinfo Security, 2025, 25(4): 654-663. |
| [5] | XIE Mengfei, FU Jianming, YAO Renyi. Research on LLM-Based Fuzzing of Native Multimedia Libraries [J]. Netinfo Security, 2025, 25(3): 403-414. |
| [6] | HU Longhui, SONG Hong, WANG Weiping, YI Jia, ZHANG Zhixiong. Research on the Application of Large Language Model in False Positive Handling for Managed Security Services [J]. Netinfo Security, 2025, 25(10): 1570-1578. |
| [7] | WANG Juan, ZHANG Boxian, ZHANG Zhijie, XIE Haining, FU Jintao, WANG Yang. Java Deserialization Vulnerability Mining Based on Fuzzing [J]. Netinfo Security, 2025, 25(1): 1-12. |
| [8] | ZHANG Liqiang, LU Mengjun, YAN Fei. A Cross-Contract Fuzzing Scheme Based on Function Dependencies [J]. Netinfo Security, 2024, 24(7): 1038-1049. |
| [9] | WANG Juan, GONG Jiaxin, LIN Ziqing, ZHANG Xiaojuan. Multidimensional Depth Oriented Fuzzing Method of Java Web Applications [J]. Netinfo Security, 2024, 24(2): 282-292. |
| [10] | MA Rupo, WANG Qun, YIN Qiang, GAO Gugang. Analysis of Security Risks and Countermeasures for Modbus TCP Protocol [J]. Netinfo Security, 2024, 24(11): 1710-1720. |
| [11] | ZHANG Zihan, LAI Qingnan, ZHOU Changling. Survey on Fuzzing Test in Deep Learning Frameworks [J]. Netinfo Security, 2024, 24(10): 1528-1536. |
| [12] | ZHANG Zhanpeng, WANG Juan, ZHANG Chong, WANG Jie, HU Yuyi. The Research on Efficient Web Fuzzing Technology Based on Graph Isomorphic Network [J]. Netinfo Security, 2024, 24(10): 1544-1552. |
| [13] | HONG Xuanquan, JIA Peng, LIU Jiayong. AFLNeTrans: Fuzzing of Protocols with State Relationship Awareness [J]. Netinfo Security, 2024, 24(1): 121-132. |
| [14] | WANG Juan, ZHANG Chong, GONG Jiaxin, LI Jun’e. Review of Fuzzing Based on Machine Learning [J]. Netinfo Security, 2023, 23(8): 1-16. |
| [15] | ZHONG Yuanxin, LIU Jiayong, JIA Peng. Directed Fuzzing Based on Dynamic Time Slicing and Efficient Mutation [J]. Netinfo Security, 2023, 23(8): 99-108. |
| Viewed | ||||||
|
Full text |
|
|||||
|
Abstract |
|
|||||