Unleashing the Power of LLM to Infer State Machine from the Protocol Implementation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wei, Haiyang, Chen, Ligeng, Du, Zhengjie, Wu, Yuhan, Huang, Haohui, Liu, Yue, Cheng, Guang, Xu, Fengyuan, Wang, Linzhang, Mao, Bing
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908285344415744
author Wei, Haiyang
Chen, Ligeng
Du, Zhengjie
Wu, Yuhan
Huang, Haohui
Liu, Yue
Cheng, Guang
Xu, Fengyuan
Wang, Linzhang
Mao, Bing
author_facet Wei, Haiyang
Chen, Ligeng
Du, Zhengjie
Wu, Yuhan
Huang, Haohui
Liu, Yue
Cheng, Guang
Xu, Fengyuan
Wang, Linzhang
Mao, Bing
contents State machines are essential for enhancing protocol analysis to identify vulnerabilities. However, inferring state machines from network protocol implementations is challenging due to complex code syntax and semantics. Traditional dynamic analysis methods often miss critical state transitions due to limited coverage, while static analysis faces path explosion issues. To overcome these challenges, we introduce a novel state machine inference approach utilizing Large Language Models (LLMs), named ProtocolGPT. This method employs retrieval augmented generation technology to enhance a pre-trained model with specific knowledge from protocol implementations. Through effective prompt engineering, we accurately identify and infer state machines. To the best of our knowledge, our approach represents the first state machine inference that leverages the source code of protocol implementations. Our evaluation of six protocol implementations shows that our method achieves a precision of over 90%, outperforming the baselines by more than 30%. Furthermore, integrating our approach with protocol fuzzing improves coverage by more than 20% and uncovers two 0-day vulnerabilities compared to baseline methods.
format Preprint
id arxiv_https___arxiv_org_abs_2405_00393
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Unleashing the Power of LLM to Infer State Machine from the Protocol Implementation
Wei, Haiyang
Chen, Ligeng
Du, Zhengjie
Wu, Yuhan
Huang, Haohui
Liu, Yue
Cheng, Guang
Xu, Fengyuan
Wang, Linzhang
Mao, Bing
Cryptography and Security
State machines are essential for enhancing protocol analysis to identify vulnerabilities. However, inferring state machines from network protocol implementations is challenging due to complex code syntax and semantics. Traditional dynamic analysis methods often miss critical state transitions due to limited coverage, while static analysis faces path explosion issues. To overcome these challenges, we introduce a novel state machine inference approach utilizing Large Language Models (LLMs), named ProtocolGPT. This method employs retrieval augmented generation technology to enhance a pre-trained model with specific knowledge from protocol implementations. Through effective prompt engineering, we accurately identify and infer state machines. To the best of our knowledge, our approach represents the first state machine inference that leverages the source code of protocol implementations. Our evaluation of six protocol implementations shows that our method achieves a precision of over 90%, outperforming the baselines by more than 30%. Furthermore, integrating our approach with protocol fuzzing improves coverage by more than 20% and uncovers two 0-day vulnerabilities compared to baseline methods.
title Unleashing the Power of LLM to Infer State Machine from the Protocol Implementation
topic Cryptography and Security
url https://arxiv.org/abs/2405.00393