Directed Greybox Fuzzing Method for Power System Terminal Firmware Based on Vulnerability Prediction


연구 분야: Analysis



학회: EITCE '24: Proceedings of the 2024 8th International Conference on Electronic Information Technology and Computer Engineering


초록

As power systems evolve and more IoT devices are integrated into system terminals, vulnerabilities in these devices increasingly pose serious threats to the safety of terminals and the entire system. To address the low accuracy of existing vulnerability prediction methods and the inefficiency of vulnerability detection, this paper proposes a directed greybox fuzzing method for power system terminal firmware based on vulnerability prediction. The proposed method consists of two main parts: (1) vulnerability point prediction and (2) directed greybox fuzzing targeting these vulnerability points. For vulnerability point prediction, a pretrained vulnerability prediction model is constructed to predict potential vulnerabilities in the target program. The regions with higher vulnerability scores are more likely to contain bugs. In fuzzing, the initial test case generation and mutation strategies are improved to account for power-specific protocols. Experimental results show that the proposed method effectively enhances the accuracy of vulnerability point prediction and improves vulnerability detection efficiency.


Author Profile
Hua Dai

State Grid Zhejiang Electric Power Co. Ltd. Research Institute Hangzhou Zhejiang China dai_hua@zj.sgcc.com.cn

China
Author Profile
Yifeng Wang

State Grid Zhejiang Electric Power Co. Ltd. Research Institute Hangzhou Zhejiang China 1253660252@qq.com

China
Author Profile
Changhua Sun

State Grid Zhejiang Electric Power Co. Ltd. Research Institute Hangzhou Zhejiang China 961744358@qq.com

China

📄 논문 정보

발행 연도 2025년
인용수 0
출판 국가 China
사이트 ACM
좋아요 수 0

연관 논문 목록 (97건)