面向多方交互场景的MQTT协议模糊测试方法
收稿日期: 2026-04-23
网络出版日期: 2026-08-07
基金资助
智能电网国家科技重大专项(2025ZD0808500)
版权
MQTT Protocol Fuzzing Method for Multi-Party Interaction Scenarios
Received date: 2026-04-23
Online published: 2026-08-07
Copyright
面向物联网场景中广泛采用的轻量级发布/订阅通信协议MQTT,针对MQTT代理在多方交互场景下模糊测试中存在的输入变异语义感知不足、状态表示粒度较粗以及多客户端异步交互覆盖不足等问题,提出了一种面向多方交互场景的MQTT协议模糊测试方法。采用全局时序交互场景建模方法构建初始种子库,结合语法感知变异、多客户端协同执行以及细粒度状态提取与引导调度机制,对MQTT代理的深层协议逻辑进行定向探索,并基于该方法设计并实现了原型系统MQTTFuzzer。在多款主流开源MQTT代理软件上的对比实验与消融分析表明,该方法在代码覆盖、状态空间探索方面均优于对比工具,能够发现已知和未知安全缺陷。研究结果表明,该方法能够为发布/订阅型协议实现的安全测试提供有效的方法支持。
谢华宝 , 周彦融 , 关志涛 . 面向多方交互场景的MQTT协议模糊测试方法[J]. 网络空间安全科学学报, 2026 . DOI: 10.20172/j.issn.2097-3136.260701
MQTT, a lightweight publish/subscribe protocol widely used in Internet of Things scenarios, was studied for fuzzing of MQTT brokers under multi-party interaction scenarios, where input mutation lacked semantic awareness, state representation was coarse grained, and asynchronous interactions among multiple clients were insufficiently covered. A fuzzing method for MQTT under multi-party interaction scenarios was proposed. An initial seed corpus was built through global temporal interaction scenario modeling, and grammar-aware mutation, multi-client coordinated execution, and fine-grained state extraction with guided scheduling were combined to direct exploration of deep protocol logic in MQTT brokers. Based on this method, a prototype system named MQTTFuzzer was designed and implemented. Comparative experiments and ablation analyses on several open-source MQTT brokers showed that the method outperformed baseline tools in code coverage and state-space exploration and discovered both known and previously unknown security flaws. The results show that the method provides effective support for security testing of publish/subscribe protocol implementations.
表 1 测试目标软件基本信息Table 1 Basic information of target software under test |
| 软件名称 | 开发语言 | 测试版本 | 开源社区星标数 |
| Mosquitto | C | 2.0.7 | 10.7k |
| NanoMQ | C | 0.24.6 | 2.4k |
| FlashMQ | C++ | 1.24.0 | 236 |
表 2 状态机模型规模对比Table 2 Comparison of state transition graph size |
| 测试工具 | FlashMQ | Mosquitto | NanoMQ |
| AFLNet | 10/57 | 10/61 | 10/70 |
| ChatAFL | 11/76 | 11/83 | 11/93 |
| 本文方法 | 24/258 | 25/287 | 14/206 |
注:X/X 表示状态节点数/状态转移边数。 |
表 3 核心模块消融实验代码分支覆盖数对比Table 3 Comparison of code branch coverage in ablation experiments on core modules |
| 变体名称 | 缺失核心模块 | FlashMQ | 差值 | Mosquitto | 差值 | NanoMQ | 差值 |
| 完整方法 | 无 | − | − | − | |||
| 无语法变体 | 语法感知变异 | −190 | −158 | −142 | |||
| 无协同变体 | 多客户端协同执行 | −141 | −29 | −159 | |||
| 无状态变体 | 状态引导调度 | −47 | −123 | −111 |
表 4 多客户端协同执行机制平均重放耗时对比Table 4 Comparison of average replay time of multi-client collaborative execution mechanism |
| 测试目标 | 样例数量 | 单客户端平均 耗时/ms | 多客户端平均 耗时/ms |
| Mosquitto | 59.010 | 91.288 | |
| FlashMQ | 32.878 | 83.164 | |
| NanoMQ | 48.033 | 84.124 |
表 5 目标代理软件漏洞挖掘结果汇总Table 5 Summary of vulnerability discovery results for target broker software |
| 测试目标 | 漏洞编号与状态 | 漏洞类型 |
| Mosquitto | CVE-2021- | 拒绝服务 |
| FlashMQ | CVE-2024- | 拒绝服务 |
| NanoMQ | 已报告 | 内存泄漏 |
| 1 |
Gubbi J, Buyya R, Marusic S, et al. Internet of Things (IoT): A vision, architectural elements, and future directions[J]. Future Generation Computer Systems, 2013, 29 (7): 1645- 1660.
|
| 2 |
Choudhary A. Internet of Things: A comprehensive overview, architectures, applications, simulation tools, challenges and future directions[J]. Discover Internet of Things, 2024, 4 (1): 31.
|
| 3 |
Dauda A, Flauzac O, Nolot F. A survey on IoT application architectures[J]. Sensors, 2024, 24 (16): 5320.
|
| 4 |
OASIS. MQTT Version 5.0[EB/OL]. [2019-03-07][2026-04-18]. https://docs.oasis-open.org/mqtt/mqtt/v5.0/mqtt-v5.0.html.
|
| 5 |
BORSATTI D, CERRONI W, TONINI F, et al. From IoT to cloud: Applications and performance of the MQTT protocol[C]//2020 22nd International Conference on Transparent Optical Networks (ICTON). IEEE, 2020: 1-4.
|
| 6 |
Laghari A A, Li H, Khan A A, et al. Internet of Things (IoT) applications security trends and challenges[J]. Discover Internet of Things, 2024, 4 (1): 36.
|
| 7 |
张玉清, 周威, 彭安妮. 物联网安全综述[J]. 计算机研究与发展, 2017, 54 (10): 2130- 2143.
Zhang Y Q, Zhou W, Peng A N. Survey of Internet of Things security[J]. Journal of Computer Research and Development, 2017, 54 (10): 2130- 2143.
|
| 8 |
YUAN B, SONG Z, JIA Y, et al. MQTTactic: Security analysis and verification for logic flaws in MQTT implementations[C]//2024 IEEE Symposium on Security and Privacy (SP). IEEE, 2024: 2385-2403.
|
| 9 |
Manes V J M, Han H S, Han C, et al. The art, science, and engineering of fuzzing: A survey[J]. IEEE Transactions on Software Engineering, 2019, 47 (11): 2312- 2331.
|
| 10 |
任泽众, 郑晗, 张嘉元, 等. 模糊测试技术综述[J]. 计算机研究与发展, 2021, 58 (5): 944- 963.
Ren Z Z, Zheng H, Zhang J Y, et al. A review of fuzzing techniques[J]. Journal of Computer Research and Development, 2021, 58 (5): 944- 963.
|
| 11 |
PHAM V T, BOHME M, ROYCHOUDHURY A. AflNet: A greybox fuzzer for network protocols[C]//2020 IEEE 13th International Conference on Software Testing, Validation and Verification (ICST). IEEE, 2020: 460-465.
|
| 12 |
徐威, 李鹏, 张文镔, 等. 网络协议模糊测试综述[J]. 计算机应用研究, 2023, 40 (8): 2241- 2249.
Xu W, Li P, Zhang W B, et al. Survey of network protocol fuzzing[J]. Application Research of Computers, 2023, 40 (8): 2241- 2249.
|
| 13 |
AMINI P. Sulley[EB/OL]. [2026-04-19]. https://github.com/OpenRCE/sulley.
|
| 14 |
PEREYDA J. Boofuzz: A network protocol fuzzing framework[EB/OL]. (2017-05-16)[2026-04-19]. https://github.com/jtpereyda/boofuzz.
|
| 15 |
Gorbunov S, Rosenbloom A. Autofuzz: Automated network protocol fuzzing framework[J]. IJCSNS, 2010, 10 (8): 239.
|
| 16 |
GASCON H, WRESSNEGGER C, YAMAGUCHI F, et al. Pulsar: Stateful black-box fuzzing of proprietary network protocols[C]//International Conference on Security and Privacy in Communication Systems. Cham: Springer International Publishing, 2015: 330-347.
|
| 17 |
JERO S, PACHECO M L, GOLDWASSER D, et al. Leveraging textual specifications for grammar-based fuzzing of network protocols[C]//Proceedings of the AAAI Conference on Artificial Intelligence, 2019, 33(1): 9478-9483.
|
| 18 |
Natella R. StateAFL: Greybox fuzzing for stateful network servers[J]. Empirical Software Engineering, 2022, 27 (7): 191.
|
| 19 |
Qin S, Hu F, Ma Z, et al. NSFuzz: Towards efficient and state-aware network service fuzzing[J]. ACM Transactions on Software Engineering and Methodology, 2023, 32 (6): 1- 26.
|
| 20 |
Li J, Li S, Sun G, et al. SNPSFuzzer: A fast greybox fuzzer for stateful network protocols using snapshots[J]. IEEE Transactions on Information Forensics and Security, 2022, 17, 2673- 2687.
|
| 21 |
LUO Z, ZUO F, SHEN Y, et al. ICS protocol fuzzing: Coverage guided packet crack and generation[C]//2020 57th ACM/IEEE Design Automation Conference (DAC). IEEE, 2020: 1-6.
|
| 22 |
Pan Z, Zhang L, Hu Z, et al. SATFuzz: A stateful network protocol fuzzing framework from a novel perspective[J]. Applied Sciences, 2022, 12 (15): 7459.
|
| 23 |
LUO Z, YU J, ZUO F, et al. BLEEM: Packet sequence oriented fuzzing for protocol implementations[C]//32nd USENIX Security Symposium (USENIX Security 23). 2023: 4481-4498.
|
| 24 |
WU F, LUO Z, ZHAO Y, et al. Logos: Log guided fuzzing for protocol implementations[C]//Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis. 2024: 1720-1732.
|
| 25 |
MENG R, MIRCHEV M, BOHME M, et al. Large language model guided protocol fuzzing[C]//Proceedings of the 31st Annual Network and Distributed System Security Symposium. Reston: Internet Society, 2024.
|
| 26 |
Cheng M, Zhu K, Chen Y, et al. MSFuzz: Augmenting protocol fuzzing with message syntax comprehension via large language models[J]. Electronics, 2024, 13 (13): 2632.
|
| 27 |
张东, 詹一宸, 白家驹, 等. 大语言模型驱动的网络协议逆向与安全测试方法[J]. 网络空间安全科学学报, 2026, 4 (1): 1- 12.
Zhang Dong, Zhan Yichen, Bai Jiaju, et al. Large language model-driven network protocol reverse engineering and security testing methods[J]. Journal of Cybersecurity, 2026, 4 (1): 1- 12.
|
| 28 |
SUN Y, LUO Q, WANG Y, CHEN Q, LIU B, CHEN R, HUANG Q, LI X, WANG J. SemFuzz: A semantics-aware fuzzing framework for network protocol implementations[C]//Proceedings of the ACM Web Conference 2026. 2026: 3251-3262.
|
| 29 |
Zeng Y, Lin M, Guo S, et al. MultiFuzz: A coverage-based multiparty-protocol fuzzer for IoT publish/subscribe protocols[J]. Sensors, 2020, 20 (18): 5194.
|
| 30 |
PEARSON B, ZHANG Y, ZOU C, et al. FUME: Fuzzing Message Queuing Telemetry Transport brokers[C]//IEEE INFOCOM 2022-IEEE Conference on Computer Communications. IEEE, 2022: 1699-1708.
|
| 31 |
Wei Z, Wei X, Zhao X, et al. SGANFuzz: A deep learning-based MQTT fuzzing method using generative adversarial networks[J]. IEEE Access, 2024, 12, 27210- 27224.
|
| 32 |
LIU X, WANG Q, LIU P, et al. MQueez: Specification-driven fuzzing for MQTT broker (Registered Report) [C]//Proceedings of the 34th ACM SIGSOFT International Symposium on Software Testing and Analysis. 2025: 133-142.
|
| 33 |
SONG X, WU J, ZENG Y, et al. MBFuzzer: A multi-part protocol fuzzer for MQTT brokers[C]//34th USENIX Security Symposium (USENIX Security 25). 2025: 6179-6197.
|
/
| 〈 |
|
〉 |