In brief
Today’s brief covers advancements in fuzzing and reverse engineering, spanning industrial controllers to modern transport protocols.
A notable theme is extending vulnerability discovery beyond memory safety to uncover logical flaws and stateful logic bugs in specialized environments.
Industrial Control Systems (ICS) code is difficult to evaluate due to domain-specific languages like IEC 61131-3 Structured Text (ST) and closed ecosystems.
ICSQuartz is the first native fuzzer for ST, introducing novel scan-cycle mutation strategies that uncover stateful vulnerabilities unique to PLC execution models.
The fuzzer outperforms previous state-of-the-art ICS fuzzers by more than an order of magnitude in executions per second.
A large-scale fuzzing campaign across real-world ICS libraries resulted in multiple vulnerability disclosures and the discovery of a bug in the RuSTy compiler that could introduce memory corruption vulnerabilities (CWE-125, CWE-787).
Corban Villa, Constantine Doumanidis, Hithem Lamri, Prashant Hari Narayan Rajput, Michail Maniatakos. “ICSQuartz: Scan Cycle-Aware and Vendor-Agnostic Fuzzing for Industrial Control Systems.” NDSS — https://www.ndss-symposium.org/ndss-paper/icsquartz-scan-cycle-aware-and-vendor-agnostic-fuzzing-for-industrial-control-systems/
Existing QUIC testing tools primarily focus on memory-related vulnerabilities and are ill-equipped to detect logical vulnerabilities.
MerCuriuzz is a black-box fuzzing framework designed specifically to uncover logical vulnerabilities in QUIC by comparing differential implementations.
Evaluation across 16 widely used QUIC implementations (including quiche, xquic, and aioquic) discovered 14 previously unknown logical vulnerabilities, categorized into six attack types.
The vulnerabilities enabled denial-of-service (DoS) attacks, state inconsistencies, and resource exhaustion, leading to 11 confirmed bugs and rewards from vendors like Cloudflare and Alibaba Cloud.
Kaihua Wang, Jianjun Chen, Pinji Chen, Jianwei Zhuge, Jiaju Bai, Haixin Duan. “Identifying Logical Vulnerabilities in QUIC Implementations.” NDSS — https://www.ndss-symposium.org/ndss-paper/identifying-logical-vulnerabilities-in-quic-implementations/
Neural decompilers have the potential to vastly outperform traditional, deterministic decompilers which struggle to recover source-level features like variable and type names.
IDIOMS is a neural decompilation approach that finetunes LLMs to explicitly reconstruct user-defined type (UDT) definitions alongside the decompiled code.
A new dataset, REALTYPE, containing 154,301 training functions with complete, realistic UDT definitions, was built to support the model.
IDIOMS achieved 54.4% accuracy on the EXEBENCH benchmark (compared to 46.3% for LLM4Decompile), demonstrating state-of-the-art neural decompilation performance.
Luke Dramko, Claire Le Goues, Edward J. Schwartz. “Idioms: A Simple and Effective Framework for Turbo-Charging Local Neural Decompilation with Well-Defined Types.” NDSS — https://www.ndss-symposium.org/ndss-paper/idioms-a-simple-and-effective-framework-for-turbo-charging-local-neural-decompilation-with-well-defined-types/