Skip to content
Book Open access

Shark2Pit: Automated Test Template Generation for Protocol Fuzzing Based on Packet Parser

Jul 2026 · SIGSOFT FSE Companion · pp. 137-141 · 0 citations · 18 references
Computer Science

TL;DR

Shark2Pit is an automated tool that generates Pit files from network traffic that uses Tshark to parse traffic, extract protocol metadata, and construct data models, and combines these models with predefined configurations to generate a Pit file.

Abstract

The effectiveness of protocol fuzzing depends on the quality of test templates, specifically the Pit file (XML-based definitions used by the Peach frameworks). These Pit files define both data models and state models. However, manually creating these Pit files is not only time-consuming and error-prone but also requires specialized domain knowledge, hindering the automation process. In this paper, we introduce Shark2Pit, an automated tool that generates Pit files from network traffic. Shark2Pit uses Tshark to parse traffic, extract protocol metadata, and construct data models. Then Shark2Pit synthesizes new data models while preserving their structure. The state model is built from data model sequences, further enhanced by state recombination and repetition. Shark2Pit combines these models with predefined configurations to generate a Pit file. We evaluated Shark2Pit on 8 open-source protocols. The branch coverage of the generated Pit files is comparable to or even higher than that of manually created Pit files (99.4%-106.3% for Peach and 90.6%-102.3% for Peach*). Furthermore, fuzzing with these Pit files revealed 5 previously unknown bugs.

Read PDF

Similar papers

Preprint Sep 2026

Dynamic Conformance Testing of WebGPU Through Specification-Driven Mutation

LANTERN, a specification-guided dynamic conformance testing framework that mutates CTS tests using constraints extracted from the WebGPU specification, is introduced, demonstrating that syntactically seeded, semantics-aware mutation of conformance tests provides a way to uncover browser bugs during WebGPU testing.

Mahya Samdaliri, Zhi-Hao Yao, Kasthuri Jayarajah · 0 citations
Aug 2026

Improving the Recall of Static Analysis of Applications Based on Frameworks by Generating Equivalent Code

An approach to improving the recall of static analysis of .NET applications using frameworks, such as WPF and Entity Framework Core, is proposed, based on generating an equivalent C# code that models user interaction scenarios that significantly improves the recall of static analysis of framework-based applications.

N. A. Borodavko, V. Ignatiev · 0 citations
Open access Oct 2026

SmartFuzz: Leveraging Large Language Models and Feature Composition to Generate High-Quality Seeds for Database Fuzzing

Mutation-based fuzzing is one of the most effective techniques for uncovering bugs in Database Management Systems (DBMSs). However, its effectiveness critically depends on the quality of the initial seed queries. High-quality seeds should be syntactically and semantically valid, incorporate diverse SQL features, and en...

Li Lin, Jin-Tai Hong, Yan Zhuang et al. · 0 citations
Preprint Aug 2026

Harnessing LLMs for Document-Guided Fuzzing of Python Libraries

VistaFuzz is introduced, a document-guided fuzzing technique that uses a locally served open-sourced LLM to extract parameter specifications from API documents and generate inputs that satisfy both parameter constraints and inter-parameter dependencies.

Bin Duan, Tarek Mahmud, Meiru Che et al. · 0 citations
Preprint Sep 2026

LLM-enabled Behavior Driven Development Workflow for Formally Verified Hardware Designs

This work proposes an integrated view on the use of LLMs for EDA and establishes an LLM-enabled behavior driven hardware development workflow, introducing and defining Formal Verification Gherkin Scenarios (FV Gherkin Scenarios), unlocking CNL specifications as the foundation for formally verified hardware designs via...

Luca Müller, Qian Liu, Rolf Drechsler · 0 citations
Preprint Aug 2026

DSpec2Test: Specification-Driven Test Generation in Dafny

DSpec2Test is presented, a specification-driven test generation tool for Dafny that automatically derives tests from formal specifications, without considering implementation details, and achieves a 93.9% mutation kill rate on a dataset of 131 mutants, outperforming Block's 82.4%, and uniquely killing 17 mutants.

Sofia Vieira Pinto, Álvaro F.Silva, João Pascoal Faria et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.