We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

cs

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Cryptography and Security

Title: L2Fuzz: Discovering Bluetooth L2CAP Vulnerabilities Using Stateful Fuzz Testing

Abstract: Bluetooth Basic Rate/Enhanced Data Rate (BR/EDR) is a wireless technology used in billions of devices. Recently, several Bluetooth fuzzing studies have been conducted to detect vulnerabilities in Bluetooth devices, but they fall short of effectively generating malformed packets. In this paper, we propose L2FUZZ, a stateful fuzzer to detect vulnerabilities in Bluetooth BR/EDR Logical Link Control and Adaptation Protocol (L2CAP) layer. By selecting valid commands for each state and mutating only the core fields of packets, L2FUZZ can generate valid malformed packets that are less likely to be rejected by the target device. Our experimental results confirmed that: (1) L2FUZZ generates up to 46 times more malformed packets with a much less packet rejection ratio compared to the existing techniques, and (2) L2FUZZ detected five zero-day vulnerabilities from eight real-world Bluetooth devices.
Comments: Updated version (2022.07.30)
Subjects: Cryptography and Security (cs.CR)
Journal reference: 2022 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
DOI: 10.1109/DSN53405.2022.00043
Cite as: arXiv:2208.00110 [cs.CR]
  (or arXiv:2208.00110v1 [cs.CR] for this version)

Submission history

From: Haram Park [view email]
[v1] Sat, 30 Jul 2022 01:12:38 GMT (4345kb,D)

Link back to: arXiv, form interface, contact.