Journals
  Publication Years
  Keywords
Search within results Open Search
Please wait a minute...
For Selected: Toggle Thumbnails
DCSFFuzzer: dual-channel semantic feature fusion-based fuzz testing method for industrial control protocols
Kan HE, Hongfeng MA, Xuejun ZONG, Hongyan SHI, Lian LIAN, Bowei NING
Journal of Computer Applications    2026, 46 (9): 2877-2888.   DOI: 10.11772/j.issn.1001-9081.2025081026
Abstract79)   HTML0)    PDF (1285KB)(141)       Save

To address the limits of the existing fuzz testing techniques in deep semantic modeling and feature representation of Industrial Control Protocols (ICPs), leading to high test case redundancy and low acceptance rates, an ICP fuzz testing method based on dual-channel semantic feature fusion, DCSFFuzzer, was proposed. In the method, dual-channel parallel architecture was adopted to perform multi-level semantic modeling for ICPs, and a Generative Adversarial Network (GAN) was used to generate diverse test cases. First, global semantic features were extracted by capturing global dependencies in protocol sequences with a Transformer encoder, and local field features were extracted by capturing relationships among adjacent bytes or fields with a multi-scale one-dimensional Convolutional Neural Network (CNN) encoder. Second, the extracted multi-level semantic features were fused by a Gated Recurrent Unit (GRU) adaptively to enhance key semantic feature representation, thereby increasing the acceptance rate of test cases. Finally, a “relativistic discriminator” training strategy was introduced in the GAN to enhance diversity of test cases by comparing relative authenticity of real and generated samples to alleviate mode collapse. Based on the above methods, the fuzz testing framework DCSFFuzzer was designed, and experiments were conducted on three ICPs: Modbus/TCP, S7comm, and Ethernet/IP. Experimental results show that compared with five models: TDRFuzzer, MLFRFuzzer, WGANFuzzer, GANFuzzer, and PeachFuzzer, DCSFFuzzer has the Test Case Acceptance Rate (TCAR) and Diversity of Generated Data (DGD) improved, and the Test Target Anomaly Rate (TTAR) increased by 0.016, 0.024, 0.069, 0.130, and 0.172 percentage points, respectively, validating the method’s effectiveness. It can be seen that by fusing multi-level semantic features, DCSFFuzzer covers more ICP vulnerabilities, improving the security detection capability of industrial control systems.

Table and Figures | Reference | Related Articles | Metrics