The importance of Internet of Things (IoT) systems security cannot be ignored, particularly in the realm of communication. IoT protocols serve as standards for communication and interaction among devices in IoT environments. This paper enhances IoT security by identifying and exposing protocol vulnerabilities through fuzzing, a crucial method for discovering security flaws. Traditional generation-based fuzzers require reverse engineering to understand protocol grammar and generate test cases. In this paper, we propose an intelligent method called GCFuzz, which generates high-quality test cases without prior knowledge of the protocol. To understand different classes of protocol grammar, GCFuzz applies Generative Adversarial Networks (GAN) with Conditional Variational Autoencoders (CVAE) to train a generative model on various classes of protocol messages. After training, the model generates fake but credible messages. Additionally, to accurately cluster real protocol messages, we devise a novel clustering method based on a keyword. Results show that, compared to GANFuzz, Peach, BooFuzz, and Sulley, the test cases generated by GCFuzz have stronger targeting and less redundancy, while GCFuzz has higher accurate testing efficiency.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

GCFuzz: An Intelligent Method for Generating IoT Protocols Test Cases Using GAN with CVAE

  • Ming Zhong,
  • Zisheng Zeng,
  • Yijia Guo,
  • Dandan Zhao,
  • Bo Zhang,
  • Shenghong Li,
  • Hao Peng,
  • Zhiguo Ding

摘要

The importance of Internet of Things (IoT) systems security cannot be ignored, particularly in the realm of communication. IoT protocols serve as standards for communication and interaction among devices in IoT environments. This paper enhances IoT security by identifying and exposing protocol vulnerabilities through fuzzing, a crucial method for discovering security flaws. Traditional generation-based fuzzers require reverse engineering to understand protocol grammar and generate test cases. In this paper, we propose an intelligent method called GCFuzz, which generates high-quality test cases without prior knowledge of the protocol. To understand different classes of protocol grammar, GCFuzz applies Generative Adversarial Networks (GAN) with Conditional Variational Autoencoders (CVAE) to train a generative model on various classes of protocol messages. After training, the model generates fake but credible messages. Additionally, to accurately cluster real protocol messages, we devise a novel clustering method based on a keyword. Results show that, compared to GANFuzz, Peach, BooFuzz, and Sulley, the test cases generated by GCFuzz have stronger targeting and less redundancy, while GCFuzz has higher accurate testing efficiency.