• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Bringing Light into the Darkness: Leveraging Hidden Markov Models for Blackbox Fuzzing
 
  • Details
  • Full
Options
2025
Conference Paper
Title

Bringing Light into the Darkness: Leveraging Hidden Markov Models for Blackbox Fuzzing

Abstract
Securing the network interfaces of industrial control systems is essential for protecting critical infrastructure like water treatment plants and nuclear centrifuges from potential attacks. A key strategy to mitigate risks of successful attacks involves identifying and closing vulnerabilities exploitable through network interfaces using testing techniques such as fuzzing. While established techniques exist for graybox fuzzing, which assume access to system binaries, industrial components often require blackbox testing due to the use of third-party components and regulatory constraints. We propose Palpebratum, an approach that leverages Hidden Markov Models to approximate missing information in blackbox test scenarios. We evaluate Palpebratum’s performance in terms of code coverage, comparing it with two baseline blackbox fuzzers and the graybox fuzzer AFLnwe. Our results demonstrate that Palpebratum significantly outperforms one blackbox fuzzer, achieving an average of 4,379.33 basic blocks compared to 4,307.60 (p-value < 0.001). For the second blackbox fuzzer, Palpebratum achieves comparable coverage but with only half the number of test cases, demonstrating effectiveness despite the Hidden Markov Model’s overhead. These findings suggest that Palpebratum enhances blackbox test case generation and emphasizes the importance of an efficient implementation to offset the added overhead.
Author(s)
Borcherding, Anne  
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Giraud, Mark Leon
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Häring, Johannes
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Mainwork
IEEE/ACM International Conference on Automation of Software Test, AST 2025. Proceedings  
Conference
International Conference on Automation of Software Test 2025  
Open Access
File(s)
Download (522.53 KB)
Rights
CC BY 4.0: Creative Commons Attribution
DOI
10.1109/AST66626.2025.00021
10.24406/publica-4953
Additional link
Full text
Language
English
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Keyword(s)
  • Codes

  • Industrial control

  • Pipelines

  • Closed box

  • Hidden Markov models

  • Telecommunication traffic

  • Fuzzing

  • Critical infrastructure

  • Network interfaces

  • Testing

  • operational technology

  • blackbox

  • gray-box

  • coverage-guided

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024