EDBT 2026 Demo / reviewers in the wild / expert
Feilong Zuo
dblp:253/1694
· DBLP profile ↗
5ranked-venue papers
2as first author
3since 2021 · last 2023
0000-0003-2589-2255ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 2 first-author · 2 since 2021Security and privacy · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
4 papers |
Systems and software security · 67% Cyber-physical and IoT security · 23% Network security · 10% | |
| Software engineering, system software, and programming languages
1 paper |
Software testing · 100% |
Topics — the 9 heaviest of 9, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security › vulnerability discovery › fuzzing
protocol fuzzing |
1.6 | 3 | 2023 | Bleem: Packet Sequence Oriented Fuzzing for Protocol Implementations · USENIX Security Symposium 2023 PAVFuzz: State-Sensitive Fuzz Testing of Protocols in Autonomous Vehicles · DAC 2021 ICS Protocol Fuzzing: Coverage Guided Packet Crack and Generation · DAC 2020 |
Systems and software security
vulnerability discovery |
1.2 | 3 | 2022 | Vulnerability Detection of ICS Protocols via Cross-State Fuzzing · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2022 ICS Protocol Fuzzing: Coverage Guided Packet Crack and Generation · DAC 2020 PAVFuzz: State-Sensitive Fuzz Testing of Protocols in Autonomous Vehicles · DAC 2021 |
Cyber-physical and IoT security
industrial control system security |
1.0 | 2 | 2022 | Vulnerability Detection of ICS Protocols via Cross-State Fuzzing · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2022 ICS Protocol Fuzzing: Coverage Guided Packet Crack and Generation · DAC 2020 |
Systems and software security › vulnerability discovery
fuzzing |
0.7 | 2 | 2022 | Vulnerability Detection of ICS Protocols via Cross-State Fuzzing · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2022 PAVFuzz: State-Sensitive Fuzz Testing of Protocols in Autonomous Vehicles · DAC 2021 |
Network security › protocol security
protocol implementation security |
0.7 | 1 | 2023 | Bleem: Packet Sequence Oriented Fuzzing for Protocol Implementations · USENIX Security Symposium 2023 |
Cyber-physical and IoT security
automotive security |
0.5 | 1 | 2021 | PAVFuzz: State-Sensitive Fuzz Testing of Protocols in Autonomous Vehicles · DAC 2021 |
Systems and software security › vulnerability discovery › fuzzing
state-aware fuzzing |
0.5 | 1 | 2021 | PAVFuzz: State-Sensitive Fuzz Testing of Protocols in Autonomous Vehicles · DAC 2021 |
Systems and software security › vulnerability discovery › fuzzing
coverage-guided fuzzing |
0.4 | 1 | 2020 | ICS Protocol Fuzzing: Coverage Guided Packet Crack and Generation · DAC 2020 |
Software testing
fuzzing |
0.2 | 1 | 2023 | Bleem: Packet Sequence Oriented Fuzzing for Protocol Implementations · USENIX Security Symposium 2023 |
Methods — techniques the papers use, named apart from their topics
fuzzing · 1.3state guidance · 0.6program status inferring · 0.6cross-state fuzzing · 0.6state relation learning · 0.5mutation weight calculation · 0.5packet cracking · 0.4coverage-guided fuzzing · 0.4
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Bleem: Packet Sequence Oriented Fuzzing for Protocol Implementations
Zhengxiong Luo 0002, Junze Yu, Feilong Zuo, Jianzhong Liu, Yu Jiang 0001, Ting Chen 0002, Abhik Roychoudhury, Jia-Guang Sun 0001 |
USENIX Security Symposium | 3 |
| 2022 | Vulnerability Detection of ICS Protocols via Cross-State FuzzingabstractIndustrial control system (ICS) employs complex multistate protocols to realize high-reliability communication and intelligent control over automation equipment. ICS has been widely used in various embedded fields, such as autonomous vehicle systems, power automation systems, etc. However, in recent years, many attacks have been performed on ICS, especially its protocols, such as the hijacks over Jeep Uconnect and Tesla Autopilot autonomous systems, also the Stuxnet and DragonFly viruses over national infrastructures. It is important to guarantee the security of ICS protocols. In this article, we presentCharon, an efficient fuzzing platform for the vulnerability detection of ICS protocol implementations. InCharon, we propose an innovative fuzzing strategy that leverages state guidance to maximize cross-state code coverage instead of focusing on isolated states during the fuzzing of ICS protocols. Moreover, we devise a novel feedback collection method that employs program status inferring to avoid the restart of the ICS protocol at each iteration, allowing for continuous fuzzing. We evaluateCharonon several popular ICS protocol implementations, including real-time publish subscribe, IEC61850-MMS, MQTT, etc. Compared with typical fuzzers, such as American fuzzy lop, Polar, AFLNET, Boofuzz, and Peach, it averagely improves branch coverage by 234.2%, 194.4%, 215.9%, 52.58%, and 35.18%, respectively. Moreover, it has already confirmed 21 previously unknown vulnerabilities (e.g., stack buffer overflow) among these ICS protocols, most of which are security critical and corresponding patches from vendors have been released accordingly. Feilong Zuo, Zhengxiong Luo 0002, Junze Yu, Ting Chen 0002, Zichen Xu 0001, Aiguo Cui, Yu Jiang 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2021 | PAVFuzz: State-Sensitive Fuzz Testing of Protocols in Autonomous VehiclesabstractThe rapid development of in-vehicle networks and protocols brings efficient communication service but also increases the risk of attack. Any vulnerability may be leveraged to cause serious consequences. It is of vital importance to guarantee their security. However, the vulnerability detection efficiency of traditional techniques such as fuzzing is challenged by the complex relations among protocol states.In this paper, we propose PAVFuzz, a state-sensitive fuzz testing framework to secure those protocols used in autonomous vehicles. It automatically learns relations between two data elements in different protocol states. The relations will then be used to calculate and update the mutation weight of each data element continuously. Accordingly, PAVFuzz is able to select the target data elements and perform state-sensitive mutation to boost the efficiency. Experiments show that, compared with state-of-the-art fuzzers Peach and AFL, PAVFuzz increases branch coverage by averagely 22.51% and 369.19% within 24 hours. It has successfully exposed 12 serious previously unknown vulnerabilities among several protocols that are widely used in autonomous vehicles, such as RTPS and SOME/IP. We have reported them to the developers and corresponding patches have been released. Feilong Zuo, Zhengxiong Luo 0002, Junze Yu, Zhe Liu 0001, Yu Jiang 0001 |
DAC | 1 |
| 2020 | ICS Protocol Fuzzing: Coverage Guided Packet Crack and GenerationabstractIndustrial Control System (ICS) protocols play an essential role in building communications among system components. Recently, many severe vulnerabilities, such as Stuxnet and DragonFly, exposed in ICS protocols have affected a wide distribution of devices. Therefore, it is of vital importance to ensure their correctness. However, the vulnerability detection efficiency of traditional techniques such as fuzzing is challenged by the complexity and diversity of the protocols.In this paper, we propose to equip the traditional protocol fuzzing with coverage-guided packet crack and generation. We collect the coverage information during the testing procedure, save those valuable packets that trigger new path coverage and crack them into pieces, based on which, we can construct higher-quality new packets for further testing. For evaluation, we build Peach*on top of Peach, which is one of the most widely used protocol fuzzers, and conduct experiments on several ICS protocols such as Modbus and DNP3. Results show that, compared with the original Peach, Peach*achieves the same code coverage and bug detection numbers at the speed of 1.2X-25X. It also gains final increase with 8.35%-36.84% more paths within 24 hours and has exposed 9 previously unknown vulnerabilities. Zhengxiong Luo 0002, Feilong Zuo, Yuheng Shen, Xun Jiao 0002, Wanli Chang 0001, Yu Jiang 0001 |
DAC | 2 |
| 2019 | Polar: Function Code Aware Fuzz Testing of ICS ProtocolabstractIndustrial Control System (ICS) protocols are widely used to build communications among system components. Compared with common internet protocols, ICS protocols have more control over remote devices by carrying a specific field called “function code”, which assigns what the receive end should do. Therefore, it is of vital importance to ensure their correctness. However, traditional vulnerability detection techniques such as fuzz testing are challenged by the increasing complexity of these diverse ICS protocols. In this paper, we present a function code aware fuzzing framework — Polar, which automatically extracts semantic information from the ICS protocol and utilizes this information to accelerate security vulnerability detection. Based on static analysis and dynamic taint analysis, Polar initiates the values of the function code field and identifies some vulnerable operations. Then, novel semantic aware mutation and selection strategies are designed to optimize the fuzzing procedure. For evaluation, we implement Polar on top of two popular fuzzers — AFL and AFLFast, and conduct experiments on several widely used ICS protocols such as Modbus, IEC104, and IEC 61850. Results show that, compared with AFL and AFLFast, Polar achieves the same code coverage and bug detection numbers at the speed of 1.5X-12X. It also gains increase with 0%--91% more paths within 24 hours. Furthermore, Polar has exposed 10 previously unknown vulnerabilities in those protocols, 6 of which have been assigned unique CVE identifiers in the US National Vulnerability Database. Zhengxiong Luo 0002, Feilong Zuo, Yu Jiang 0001, Jian Gao 0008, Xun Jiao 0002, Jia-Guang Sun 0001 |
ACM Trans. Embed. Comput. Syst. | 2 |