Skip to content
Open access

NCFuzz: Configuration-Guided Network Service Fuzzing

Oct 2026 · Proceedings of the ACM on Software Engineering · Vol 3, pp. 3613 - 3636 · 0 citations · 63 references

TL;DR

This work tackles the problem of finding bugs under non-default configurations, termed ConfBug, by designing a new fuzzer called NCFuzz, which achieves higher coverage than baseline fuzzers and uses configuration knowledge and the relationships between configurations and network messages to guide the fuzzer toward new software states.

Abstract

Network services like FTP and DNS are critical components of modern reliable Internet infrastructure. Software fuzzing, especially network protocol fuzzing, is widely used to uncover flaws in these systems. However, conventional fuzzers operate under a single, fixed configuration throughout the fuzzing campaign, leaving the service’s rich configuration space unexplored. Incorporating configurations as a dynamic input dimension is challenging due to complex semantics, trigger conditions, and the resulting enlarged search space. We tackle the problem of finding bugs under non-default configurations, termed ConfBug, by designing a new fuzzer called NCFuzz. The non-default configurations can be uncommon but administrators may enable them, which cannot be exercised by conventional fuzzers. With the assumption that software documentation that describes configuration options is available, NCFuzz leverages two key observations: 1) software documentation contains rich information about configurations; 2) interactions between configuration and network messages can be tracked through code instrumentation and data-flow analysis. Using these insights, NCFuzz uses configuration knowledge and the relationships between configurations and network messages to guide the fuzzer toward new software states. The quality and completeness of the documentation will affect the effectiveness of NCFuzz. Evaluation on six network service implementations shows NCFuzz achieves higher coverage than baseline fuzzers. Five ConfBugs were discovered during fuzzing.

Read PDF

Similar papers

Preprint Sep 2026

NetInspector: Measuring and Improving LLM Capabilities for Reliable Intent-Based Networking Policy Generation

Modern networks are large in scale and heterogeneous in configuration, making manual policy management increasingly impractical. Intent-Based Networking (IBN) addresses this by automating the translation of high-level operator goals into low-level network configurations. Yet existing IBN systems rely on static heuristi...

Yuxuan Zhang, Hongxin Hu, Guo-Fei Gu · 1 citation
Book Open access Aug 2026

Explainable Network Verification via Localized Subspecification

Network verification, synthesis, and repair tools help enforce high-level operational intent, but their limited explainability makes configuration maintenance costly in practice, as operators must still manually reason about large, low-level configurations. We propose localized subspecifications, which explain how indi...

Yongzheng Zhang, Yaxuan Lin, Hao-Xian Chen et al. · 0 citations
Open access Oct 2026

NSync: Automated Cloud Infrastructure-as-Code Reconciliation with AI Agents

Cloud infrastructure is managed through a mix of interfaces—traditionally, cloud consoles, command-line interfaces (CLI), and SDKs are the tools of choice. Recently, Infrastructure-as-Code/IaC frameworks (e.g., Terraform) have quickly gained popularity. Unlike conventional tools, IaC frameworks encode the infrastructur...

Zhenning Yang, Hui Guan, Victor Nicolet et al. · 0 citations
Book Open access Aug 2026

Evolution of AliYANG: Model-driven and LLM-assisted Network Configuration Management

AliYANG is introduced, a YANG-based configuration modeling framework that unifies configuration representation across vendors and management interfaces and incorporates LLM-assisted automation to facilitate vendor model augmentation, core model design, and bidirectional translation code generation.

Mohan Yu, Xu-Miao Zhang, Zhecheng An et al. · 0 citations
Preprint Aug 2026

Dissecting Software Graphs: Structural Insights for Driver-Guided Fuzzing

A structural abstraction is proposed that uses a static call graph as a shared backbone and projects driver-specific dynamic coverage onto it to derive driver-induced subgraphs and shows that multi-driver fuzzing is fundamentally a structural exploration problem.

Bai-Hong Chen, Ming Hua, Wei-Feng Pan et al. · 0 citations

Improving state coverage of greybox fuzzing

AFLWalk is created, a variant of AFLNet, as an attempt to address the challenge of testing stateful protocols by focusing exclusively on message-sequence mutations to steer exploration through protocol state machines, rather than applying byte-level mutations such as bit-flipping.

Philip-Ricardo Schoots, Ir. Erik Poll, F. Vaandrager · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.