Kunpeng Jian

dblp:253/7455 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
6since 2021 · last 2025
0009-0002-8304-1045ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 3 since 2021Software engineering, systems software and programming languages · 3 · 3 first-author · 3 since 2021
YearPublicationVenuePosition
2025 Fuzzing for Stateful Protocol Programs Based on Constraints between States and Message Types
abstract
Stateful protocol programs are a critical component of the network systems, and vulnerabilities in these programs can lead to severe consequences.Fuzzing, as an effective testing technique, has proven to be a powerful method for discovering vulnerabilities in stateful protocol programs, thereby enhancing their reliability and security.However, current stateful protocol fuzzers often rely on randomly mutating both the content and sequence of messages, leading to two major limitations.First, constraints between states and message types impose restrictions on the valid ordering of message types.Completely random sequence mutation frequently results in test cases that are partially valid but largely discarded by the program.Second, existing methods struggle to generate new message types that do not appear in the initial seed corpus.To overcome these limitations, we propose a stateful protocol fuzzing approach that leverages constraints between states and message types.We implement this approach in a prototype tool called STCFuzz.STCFuzz begins by identifying states, message types, and their associated constraints in the program code through static analysis.It then leverages this information to perform constraint-based sequence mutation to generate more effective test cases.Additionally, STC-Fuzz utilizes large language models to generate new message types absent from the original seed corpus.We conduct comparative experiments between STCFuzz and other state-of-the-art fuzzers.Experimental results demonstrate that STCFuzz achieves an average improvement of 13.4% in state transition coverage and 7.7% in code coverage compared to other fuzzers.Furthermore, STCFuzz triggers more crashes and discovers more vulnerabilities, highlighting its effectiveness in uncovering security flaws.
Kunpeng Jian, Yanyan Zou 0002, Wei Huo 0005
Internetware1
2025 State Significance-Guided Fuzzing for Stateful Protocol Program
Kunpeng Jian, Yanyan Zou 0002, Wei Huo 0005
TASE1
2025 From Constraints to Cracks: Constraint Semantic Inconsistencies as Vulnerability Beacons for Embedded Systems
Jiaxu Zhao 0004, Yuekang Li, Yanyan Zou 0002, Yang Xiao 0011, Naijia Jiang, Yeting Li, Nanyu Zhong, Bingwei Peng, Kunpeng Jian, Wei Huo 0005
USENIX Security Symposium9
2024 Fuzzing for Stateful Protocol Implementations: Are We There Yet?
Kunpeng Jian, Yanyan Zou 0002, Yeting Li, Jialun Cao, Wei Huo 0005
TASE1
2022 NDFuzz: a non-intrusive coverage-guided fuzzing framework for virtualized network devices
abstract
Abstract Network function virtualization provides programmable in-network middlewares by leveraging virtualization technologies and commodity hardware and has gained popularity among all mainstream network device manufacturers. Yet it is challenging to apply coverage-guided fuzzing, one of the state-of-the-art vulnerability discovery approaches, to those virtualized network devices, due to inevitable integrity protection adopted by those devices. In this paper, we propose a coverage-guided fuzzing framework NDFuzz for virtualized network devices with a novel integrity protection bypassing method, which is able to distinguish processes of virtualized network devices from hypervisors with a carefully designed non-intrusive page global directory inference technique. We implement NDFuzz atop of two black-box fuzzers and evaluate NDFuzz with three representative network protocols, SNMP , DHCP and NTP , on nine popular virtualized network devices. NDFuzz obtains an average 36% coverage improvement in comparison with its black-box counterparts. NDFuzz discovers 2 0-Day vulnerabilities and 1 1-Day vulnerability with coverage guidance while the black-box fuzzer can find only one of them. All discovered vulnerabilities are confirmed by corresponding vendors.
Nanyu Zhong, Wei You 0001, Yanyan Zou 0002, Kunpeng Jian, Jiahuan Xu, Baoxu Liu, Wei Huo 0005
Cybersecur.5
2021 ESRFuzzer: an enhanced fuzzing framework for physical SOHO router devices to discover multi-Type vulnerabilities
abstract
Abstract SOHO (small office/home office) routers provide services for end devices to connect to the Internet, playing an important role in cyberspace. Unfortunately, security vulnerabilities pervasively exist in these routers, especially in the web server modules, greatly endangering end users. To discover these vulnerabilities, fuzzing web server modules of SOHO routers is the most popular solution. However, its effectiveness is limited due to the lack of input specification, lack of routers’ internal running states, and lack of testing environment recovery mechanisms. Moreover, existing works for device fuzzing are more likely to detect memory corruption vulnerabilities.In this paper, we propose a solution ESRFuzzer to address these issues. It is a fully automated fuzzing framework for testing physical SOHO devices. It continuously and effectively generates test cases by leveraging two input semantic models, i.e., KEY-VALUE data model and CONF-READ communication model, and automatically recovers the testing environment with power management. It also coordinates diversified mutation rules with multiple monitoring mechanisms to trigger multi-type vulnerabilities. With the guidance of the two semantic models, ESRFuzzer can work in two ways: general mode fuzzing and D-CONF mode fuzzing. General mode fuzzing can discover both issues which occur in the CONF and READ operation, while D-CONF mode fuzzing focus on the READ-op issues especially missed by general mode fuzzing.We ran ESRFuzzer on 10 popular routers across five vendors. In total, it discovered 136 unique issues, 120 of which have been confirmed as 0-day vulnerabilities we found. As an improvement of SRFuzzer, ESRFuzzer have discovered 35 previous undiscovered READ-op issues that belong to three vulnerability types, and 23 of them have been confirmed as 0-day vulnerabilities by vendors. The experimental results show that ESRFuzzer outperforms state-of-the-art solutions in terms of types and number of vulnerabilities found.
Wei Huo 0005, Kunpeng Jian, Ji Shi 0002, Longquan Liu, Yanyan Zou 0002, Chao Zhang 0008, Baoxu Liu
Cybersecur.3
2019 SRFuzzer: an automatic fuzzing framework for physical SOHO router devices to discover multi-type vulnerabilities
abstract
SOHO (small office/home office) routers provide services for end devices to connect to the Internet, playing an important role in the cyberspace. Unfortunately, security vulnerabilities pervasively exist in these routers, especially in the web server modules, greatly endangering end users. To discover these vulnerabilities, fuzzing web server modules of SOHO routers is the most popular solution. However, its effectiveness is limited, due to the lack of input specification, lack of routers' internal running states, and lack of testing environment recovery mechanisms. Moreover, fuzzing in general only reports memory corruption vulnerabilities, and fails to discover other vulnerabilities, e.g., web-based vulnerabilities.
Wei Huo 0005, Kunpeng Jian, Ji Shi 0002, Haoliang Lu, Longquan Liu, Dandan Sun, Chao Zhang 0008, Baoxu Liu
ACSAC3