Feilong Zuo

dblp:253/1694 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
3since 2021 · last 2023
0000-0003-2589-2255ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 4 · 2 first-author · 2 since 2021Security and privacy · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
4 papers
Systems and software security · 67% Cyber-physical and IoT security · 23% Network security · 10%
Software engineering, system software, and programming languages
1 paper
Software testing · 100%

Topics — the 9 heaviest of 9, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › vulnerability discovery › fuzzing
protocol fuzzing
1.632023
Bleem: Packet Sequence Oriented Fuzzing for Protocol Implementations · USENIX Security Symposium 2023
PAVFuzz: State-Sensitive Fuzz Testing of Protocols in Autonomous Vehicles · DAC 2021
ICS Protocol Fuzzing: Coverage Guided Packet Crack and Generation · DAC 2020
Systems and software security
vulnerability discovery
1.232022
Vulnerability Detection of ICS Protocols via Cross-State Fuzzing · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2022
ICS Protocol Fuzzing: Coverage Guided Packet Crack and Generation · DAC 2020
PAVFuzz: State-Sensitive Fuzz Testing of Protocols in Autonomous Vehicles · DAC 2021
Cyber-physical and IoT security
industrial control system security
1.022022
Vulnerability Detection of ICS Protocols via Cross-State Fuzzing · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2022
ICS Protocol Fuzzing: Coverage Guided Packet Crack and Generation · DAC 2020
Systems and software security › vulnerability discovery
fuzzing
0.722022
Vulnerability Detection of ICS Protocols via Cross-State Fuzzing · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2022
PAVFuzz: State-Sensitive Fuzz Testing of Protocols in Autonomous Vehicles · DAC 2021
Network security › protocol security
protocol implementation security
0.712023
Bleem: Packet Sequence Oriented Fuzzing for Protocol Implementations · USENIX Security Symposium 2023
Cyber-physical and IoT security
automotive security
0.512021
PAVFuzz: State-Sensitive Fuzz Testing of Protocols in Autonomous Vehicles · DAC 2021
Systems and software security › vulnerability discovery › fuzzing
state-aware fuzzing
0.512021
PAVFuzz: State-Sensitive Fuzz Testing of Protocols in Autonomous Vehicles · DAC 2021
Systems and software security › vulnerability discovery › fuzzing
coverage-guided fuzzing
0.412020
ICS Protocol Fuzzing: Coverage Guided Packet Crack and Generation · DAC 2020
Software testing
fuzzing
0.212023
Bleem: Packet Sequence Oriented Fuzzing for Protocol Implementations · USENIX Security Symposium 2023

Methods — techniques the papers use, named apart from their topics

fuzzing · 1.3state guidance · 0.6program status inferring · 0.6cross-state fuzzing · 0.6state relation learning · 0.5mutation weight calculation · 0.5packet cracking · 0.4coverage-guided fuzzing · 0.4
YearPublicationVenuePosition
2023 Bleem: Packet Sequence Oriented Fuzzing for Protocol Implementations
Zhengxiong Luo 0002, Junze Yu, Feilong Zuo, Jianzhong Liu, Yu Jiang 0001, Ting Chen 0002, Abhik Roychoudhury, Jia-Guang Sun 0001
USENIX Security Symposium3
2022 Vulnerability Detection of ICS Protocols via Cross-State Fuzzing
abstract
Industrial control system (ICS) employs complex multistate protocols to realize high-reliability communication and intelligent control over automation equipment. ICS has been widely used in various embedded fields, such as autonomous vehicle systems, power automation systems, etc. However, in recent years, many attacks have been performed on ICS, especially its protocols, such as the hijacks over Jeep Uconnect and Tesla Autopilot autonomous systems, also the Stuxnet and DragonFly viruses over national infrastructures. It is important to guarantee the security of ICS protocols. In this article, we presentCharon, an efficient fuzzing platform for the vulnerability detection of ICS protocol implementations. InCharon, we propose an innovative fuzzing strategy that leverages state guidance to maximize cross-state code coverage instead of focusing on isolated states during the fuzzing of ICS protocols. Moreover, we devise a novel feedback collection method that employs program status inferring to avoid the restart of the ICS protocol at each iteration, allowing for continuous fuzzing. We evaluateCharonon several popular ICS protocol implementations, including real-time publish subscribe, IEC61850-MMS, MQTT, etc. Compared with typical fuzzers, such as American fuzzy lop, Polar, AFLNET, Boofuzz, and Peach, it averagely improves branch coverage by 234.2%, 194.4%, 215.9%, 52.58%, and 35.18%, respectively. Moreover, it has already confirmed 21 previously unknown vulnerabilities (e.g., stack buffer overflow) among these ICS protocols, most of which are security critical and corresponding patches from vendors have been released accordingly.
Feilong Zuo, Zhengxiong Luo 0002, Junze Yu, Ting Chen 0002, Zichen Xu 0001, Aiguo Cui, Yu Jiang 0001
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.1
2021 PAVFuzz: State-Sensitive Fuzz Testing of Protocols in Autonomous Vehicles
abstract
The rapid development of in-vehicle networks and protocols brings efficient communication service but also increases the risk of attack. Any vulnerability may be leveraged to cause serious consequences. It is of vital importance to guarantee their security. However, the vulnerability detection efficiency of traditional techniques such as fuzzing is challenged by the complex relations among protocol states.In this paper, we propose PAVFuzz, a state-sensitive fuzz testing framework to secure those protocols used in autonomous vehicles. It automatically learns relations between two data elements in different protocol states. The relations will then be used to calculate and update the mutation weight of each data element continuously. Accordingly, PAVFuzz is able to select the target data elements and perform state-sensitive mutation to boost the efficiency. Experiments show that, compared with state-of-the-art fuzzers Peach and AFL, PAVFuzz increases branch coverage by averagely 22.51% and 369.19% within 24 hours. It has successfully exposed 12 serious previously unknown vulnerabilities among several protocols that are widely used in autonomous vehicles, such as RTPS and SOME/IP. We have reported them to the developers and corresponding patches have been released.
Feilong Zuo, Zhengxiong Luo 0002, Junze Yu, Zhe Liu 0001, Yu Jiang 0001
DAC1
2020 ICS Protocol Fuzzing: Coverage Guided Packet Crack and Generation
abstract
Industrial Control System (ICS) protocols play an essential role in building communications among system components. Recently, many severe vulnerabilities, such as Stuxnet and DragonFly, exposed in ICS protocols have affected a wide distribution of devices. Therefore, it is of vital importance to ensure their correctness. However, the vulnerability detection efficiency of traditional techniques such as fuzzing is challenged by the complexity and diversity of the protocols.In this paper, we propose to equip the traditional protocol fuzzing with coverage-guided packet crack and generation. We collect the coverage information during the testing procedure, save those valuable packets that trigger new path coverage and crack them into pieces, based on which, we can construct higher-quality new packets for further testing. For evaluation, we build Peach*on top of Peach, which is one of the most widely used protocol fuzzers, and conduct experiments on several ICS protocols such as Modbus and DNP3. Results show that, compared with the original Peach, Peach*achieves the same code coverage and bug detection numbers at the speed of 1.2X-25X. It also gains final increase with 8.35%-36.84% more paths within 24 hours and has exposed 9 previously unknown vulnerabilities.
Zhengxiong Luo 0002, Feilong Zuo, Yuheng Shen, Xun Jiao 0002, Wanli Chang 0001, Yu Jiang 0001
DAC2
2019 Polar: Function Code Aware Fuzz Testing of ICS Protocol
abstract
Industrial Control System (ICS) protocols are widely used to build communications among system components. Compared with common internet protocols, ICS protocols have more control over remote devices by carrying a specific field called “function code”, which assigns what the receive end should do. Therefore, it is of vital importance to ensure their correctness. However, traditional vulnerability detection techniques such as fuzz testing are challenged by the increasing complexity of these diverse ICS protocols. In this paper, we present a function code aware fuzzing framework — Polar, which automatically extracts semantic information from the ICS protocol and utilizes this information to accelerate security vulnerability detection. Based on static analysis and dynamic taint analysis, Polar initiates the values of the function code field and identifies some vulnerable operations. Then, novel semantic aware mutation and selection strategies are designed to optimize the fuzzing procedure. For evaluation, we implement Polar on top of two popular fuzzers — AFL and AFLFast, and conduct experiments on several widely used ICS protocols such as Modbus, IEC104, and IEC 61850. Results show that, compared with AFL and AFLFast, Polar achieves the same code coverage and bug detection numbers at the speed of 1.5X-12X. It also gains increase with 0%--91% more paths within 24 hours. Furthermore, Polar has exposed 10 previously unknown vulnerabilities in those protocols, 6 of which have been assigned unique CVE identifiers in the US National Vulnerability Database.
Zhengxiong Luo 0002, Feilong Zuo, Yu Jiang 0001, Jian Gao 0008, Xun Jiao 0002, Jia-Guang Sun 0001
ACM Trans. Embed. Comput. Syst.2