Journal of Information Security and Applications· 2026Q1
Using fuzzing for automated probe message generation in remote black-box TLS fingerprinting
- 0citations
- Q1SCImago
- 2026year
Short summary
An evolutionary fuzzing approach automatically generates TLS probes that identify 3.5x more behavioral differences than manual methods, clustering 323 TLS servers into 155 groups for complete brand identification.
AI-generated from the title and abstract; the full text is not read.
Key points
- Developed an evolutionary fuzzing algorithm for automated black-box TLS fingerprinting.
- Utilized Generic Message Tree (GMT) representation for generating diverse TLS messages.
- Tested on 323 TLS server implementations from six major brands.
- Fuzzing generated probes identified 3.5x more behavioral clusters than existing methods.
- A set of 35 probes created 155 clusters, enabling complete brand identification and version narrowing.
AI-generated from the title and abstract; the full text is not read.
Abstract
Secure network communication is critical across various domains for both functional safety and user acceptance, particularly in IoT environments where Cyber-Physical Systems bridge the physical world and cyberspace. Remote software implementation and version identification (fingerprinting) provide valuable intelligence for security operations specialists and penetration testers. Existing fingerprinting tools, however, rely on manually crafted probe sets that demand deep protocol expertise and may miss subtle behavioral differences. This paper presents an automated approach for black-box remote TLS implementation fingerprinting using differential testing combined with evolutionary fuzzing techniques. Our evolutionary fuzzing algorithm effectively discovers numerous behavioral discrepancies across different TLS implementations. The methodology leverages the Generic Message Tree (GMT) representation, enabling the production of diverse and mostly valid protocol messages. Our experimental study covers 323 TLS server implementations from six major brands. We apply a clustering approach to measure the efficiency of different fingerprinting configurations. Probes generated by our fuzzing approach distinguish about 3.5 times as many behavioral clusters as existing comparable software: a minimal set of just 35 automatically generated probes separates the 323 implementations into 155 clusters. On our reference set these clusters yield complete brand identification and narrow a target to a small range of same-brand versions.
The authors' abstract, as published at the source. Journal of Information Security and Applications, 2026 · DOI ↗
The rest is in the Pofolia app
Takeaways and questions to the paper; new summaries every day for your field. Free.
Sign in on the web to openField: Software
SoftwareComputer Science