For many proprietary systems source code and documentation are not available which makes them hard to test leaving only black- box approaches. In this work, we present an experience of fuzzing a protocol for drone control and the developed tool BinFuzz. BinFuzz is a man-in-the-middle stateful black-box protocol fuzzer. Listening to real communication as a man-in-the-middle, the fuzzer reconstructs states of the protocol as well as detects message types and their variable fields. The collected knowledge is used during the fuzzing to improve the quality of the generated inputs. For the application, we first test BinFuzz on an FTP protocol and then use it to fuzz the protocol for drone control.
Baranov, E., Legay, A., & Vivian, M. (2024). Fuzzing an Industrial Proprietary Protocol. Lecture Notes in Computer Science, 14952(1), 119-135. https://doi.org/10.1007/978-3-031-68150-9_7 (Original work published 2024)