kth.sePublications KTH
Change search
Link to record
Permanent link

Direct link
Karlsson, Gunnar, ProfessorORCID iD iconorcid.org/0000-0002-3704-1338
Alternative names
Publications (10 of 140) Show all publications
Fernandez, L. & Karlsson, G. (2025). Measuring the Impact of Fuzzing Activity in Networking Software. In: 40TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING: . Paper presented at 40th Symposium on Applied Computing-SAC, MAR 31-APR 04, 2025, Catania, ITALY (pp. 1746-1748). Association for Computing Machinery (ACM)
Open this publication in new window or tab >>Measuring the Impact of Fuzzing Activity in Networking Software
2025 (English)In: 40TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, Association for Computing Machinery (ACM) , 2025, p. 1746-1748Conference paper, Published paper (Refereed)
Abstract [en]

Fuzz testing has become the de facto standard for vulnerability discovery. In this paper we study 32 prominent protocol implementations that have been continuously fuzzed by OSS-Fuzz, a widely used fuzzing platform. We define metrics to measure fuzzing activity within a project and correlate our measurements with registered CVEs for discovered vulnerabilities. Our analysis show a strong correlation between fuzzing activity and registered CVEs within a project. However, by using the CWE-1000 analys framework, we find that the correlation is only strong for certain classes of vulnerabilities.

Place, publisher, year, edition, pages
Association for Computing Machinery (ACM), 2025
Keywords
Fuzz Testing, Cyber Security
National Category
Computer Sciences
Identifiers
urn:nbn:se:kth:diva-368397 (URN)10.1145/3672608.3707730 (DOI)001497934400234 ()2-s2.0-105006470321 (Scopus ID)979-8-4007-0629-5 (ISBN)
Conference
40th Symposium on Applied Computing-SAC, MAR 31-APR 04, 2025, Catania, ITALY
Note

QC 20250818

Available from: 2025-08-18 Created: 2025-08-18 Last updated: 2025-08-18Bibliographically approved
Karlsson, G. & Fernandez, L. (2025). Measuring the Impact of Fuzzing Activity in Networking Software - Extended. Stockholm: KTH Royal Institute of Technology
Open this publication in new window or tab >>Measuring the Impact of Fuzzing Activity in Networking Software - Extended
2025 (English)Report (Other academic)
Abstract [en]

Fuzz testing has become the de facto standard for vulnerability discovery. State-of-the-art fuzzers employ a so-called gray-box approach,where coverage information is fed back to the fuzzer after each generated test case, thereby allowing it to effectivize its generationstrategy over time to find bugs deep within the code. Despite research efforts in recent years, networked applications have proven tobe notoriously difficult to fuzz efficiently and thoroughly. Modern fuzzers struggle with the complex environmental interactions andstatefulness associated with networked systems and subsequently, shortcuts are taken to ensure at least some degree of hardening.

In this paper we study 32 prominent protocol implementations that have been continuously fuzzed by OSS-Fuzz. We define metricsto measure fuzzing activity within a project and correlate our measurements with registered CVEs for discovered vulnerabilities. Our analysis show a strong correlation between fuzzing activity and registered CVEs within a project. However, by using the CWE-1000 analys framework, we show that the correlation is only strong for certain classes of vulnerabilities. From those observations, we areable to draw conclusions about what current fuzzing practices are lacking and where fuzzing research efforts need to be spent in thefuture.

This technical report is an extension of doi:10.1145/3672608.3707730, which has been published with ACM in the SAC 2025 conference proceedings.

Place, publisher, year, edition, pages
Stockholm: KTH Royal Institute of Technology, 2025. p. 13
Series
TRITA-EECS-RP ; 2025:3
Keywords
Computer network, protocol, testing, fuzz testing
National Category
Communication Systems Telecommunications Computer Sciences Computer Engineering Security, Privacy and Cryptography
Research subject
Electrical Engineering; Computer Science
Identifiers
urn:nbn:se:kth:diva-372022 (URN)
Note

This technical report is an extension of doi:10.1145/3672608.3707730, which has been published with ACM in the SAC 2025 conference proceedings.

QC 20251029

Available from: 2025-10-23 Created: 2025-10-23 Last updated: 2026-02-18Bibliographically approved
Karlsson, G. (2024). From Campus to Boot Camp-Lessons from Extramural Teaching in Cybersecurity. In: EDUCON 2024 - IEEE Global Engineering Education Conference, Proceedings: . Paper presented at 15th IEEE Global Engineering Education Conference, EDUCON 2024, May 8-11, 2024, Kos Island, Greece. Institute of Electrical and Electronics Engineers (IEEE)
Open this publication in new window or tab >>From Campus to Boot Camp-Lessons from Extramural Teaching in Cybersecurity
2024 (English)In: EDUCON 2024 - IEEE Global Engineering Education Conference, Proceedings, Institute of Electrical and Electronics Engineers (IEEE) , 2024Conference paper, Published paper (Refereed)
Abstract [en]

Work life is rapidly developing owing to digitalization and new work practices. As a consequence, intensive training is needed for working people to acquire new skills and knowledge. Such training might require larger efforts of weeks or months of full time work in order for professionals to get started on new roles at work. For this type of education, the boot camp format may be suitable. It is characterized by a focus on essentials in contents, scheduled work time, and social interaction and support amongst the course participants. This paper presents learning from boot camp training of conscript soldiers and it extends the experiences to training of working professionals. The novelty of the endeavor for the university is that the courses are given on a remote site by instructors without expert knowledge in the field; the university provides curated contents, formal examination and support to the instructors. This setup works well and has been in production for four years with minimal adjustments. It builds on good communication with the instructors, on teaching material structured for independent study, and on peer support among the students. We contrast the format with the popular massive open online courses and discuss how the boot camp format scales in terms of number of courses and course participants with respect to resources, primarily the time of the responsible teachers. The conclusion is that boot camp training should be considered for professional education and that it might not be more demanding for the teachers than any other course format.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2024
Keywords
adult education, boot camp training, Continuous education, cybersecurity education, life-long learning, professional training
National Category
Production Engineering, Human Work Science and Ergonomics Communication Systems
Identifiers
urn:nbn:se:kth:diva-351506 (URN)10.1109/EDUCON60312.2024.10578866 (DOI)001289091100307 ()2-s2.0-85199038515 (Scopus ID)
Conference
15th IEEE Global Engineering Education Conference, EDUCON 2024, May 8-11, 2024, Kos Island, Greece
Note

Part of ISBN 9798350394023

QC 20241023

Available from: 2024-08-20 Created: 2024-08-20 Last updated: 2024-10-23Bibliographically approved
Fernandez, L. & Karlsson, G. (2024). Fuzz Testing for Code Injection Vulnerabilities in Network Management Systems. In: 2024 8th International Conference on System Reliability and Safety, ICSRS 2024: . Paper presented at 8th International Conference on System Reliability and Safety, ICSRS 2024, Sicily, Italy, November 20-22, 2024 (pp. 529-536). Institute of Electrical and Electronics Engineers (IEEE)
Open this publication in new window or tab >>Fuzz Testing for Code Injection Vulnerabilities in Network Management Systems
2024 (English)In: 2024 8th International Conference on System Reliability and Safety, ICSRS 2024, Institute of Electrical and Electronics Engineers (IEEE) , 2024, p. 529-536Conference paper, Published paper (Refereed)
Abstract [en]

To handle the complexity of modern technical systems, the operator often relies on some kind of graphical user interface software. Such software typically provides statistics, visualization and remote management capabilities to the operator. Today, this software is usually implemented using various web technologies. This lets operators monitor and manage the system in question with a tool familiar to most people today, namely their web browser. Unfortunately, web technology comes with plenty of intricate and unexpected caveats and flaws that can lead to unpredictable and sometimes even insecure behavior. In this paper, we focus on how one such obscure flaw, cross-channel scripting, can affect communications and service-provider networks. We provide a testing framework for detecting such flaws and use it to test four different open-source network management systems. Three vulnerabilities were found and acknowledged and fixed by the developers and one CVE was assigned.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2024
Keywords
Code Injection, Cybersecurity, Fuzz Testing, Web Security
National Category
Computer Sciences Computer Systems
Identifiers
urn:nbn:se:kth:diva-367476 (URN)10.1109/ICSRS63046.2024.10927541 (DOI)2-s2.0-105003291353 (Scopus ID)
Conference
8th International Conference on System Reliability and Safety, ICSRS 2024, Sicily, Italy, November 20-22, 2024
Note

Part of ISBN 9798350354508

QC 20250718

Available from: 2025-07-18 Created: 2025-07-18 Last updated: 2026-02-18Bibliographically approved
Karlsson, G. & Lundén, P. (2023). Agile Education Imagined: A report from the Cybercampus workshop onAgile Education.
Open this publication in new window or tab >>Agile Education Imagined: A report from the Cybercampus workshop onAgile Education
2023 (English)Report (Other (popular science, discussion, etc.))
Abstract [en]

Cybercampus Sweden is a national initiative to provide education, research, innovation and advice in cybersecurity and cyber-defense. This brochure addresses needs for cybersecurity training and education. The contents are fictitious courses created from the outcomes of a planning workshop on agile education, conducted by the planning project for Cybercampus Sweden, held on October 17, 2022.

Publisher
p. 16
Series
TRITA-EECS-RP ; 2023:1
Keywords
Cybersecurity, education, information security, life-long learning
National Category
Other Engineering and Technologies Computer Systems Communication Systems
Identifiers
urn:nbn:se:kth:diva-323132 (URN)
Note

Published under license CC BY 4.0

QC 20230118

Available from: 2023-01-17 Created: 2023-01-17 Last updated: 2025-02-18Bibliographically approved
Fernandez, L. & Karlsson, G. (2023). Black-Box Fuzzing for Security in Managed Networks: An Outline. IEEE Networking Letters, 5(4), 241-244
Open this publication in new window or tab >>Black-Box Fuzzing for Security in Managed Networks: An Outline
2023 (English)In: IEEE Networking Letters, E-ISSN 2576-3156, Vol. 5, no 4, p. 241-244Article in journal (Refereed) Published
Abstract [en]

Service providers are adopting open-source technology and open standards in their next-generation networks. This gives them great flexibility and spurs innovation. But it also means that they must ensure proper interoperability between components; otherwise, vulnerabilities might get introduced in their networks. Unfortunately, state-of-the-art vulnerability scanning tools are unable to handle the complexity of service provider networks. In this letter we show how interoperability issues between seemingly reliable components introduce an injection vulnerability that allows us to control a firewall-protected network management system. We also extend the state-of-the-art in black-box fuzzing to give service providers a tool for combating similar issues.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2023
National Category
Computer Sciences
Identifiers
urn:nbn:se:kth:diva-376829 (URN)10.1109/lnet.2023.3286443 (DOI)001556071500023 ()2-s2.0-85183466608 (Scopus ID)
Note

QC 20260218

Available from: 2026-02-18 Created: 2026-02-18 Last updated: 2026-07-01Bibliographically approved
Karlsson, G. (2023). Fortare, vidare och högre: Handledning för fortbildning vid högskolor – behov, förslag och handlingsplan.
Open this publication in new window or tab >>Fortare, vidare och högre: Handledning för fortbildning vid högskolor – behov, förslag och handlingsplan
2023 (Swedish)Report (Other academic)
Abstract [sv]

I denna rapport har jag sammanställt bakgrundsinformation och övergripande förslag för att öka högskolans utbud av fortbildning[1] för yrkesverksamma. Såväl företag och branschorganisationer som fackföreningar uttrycker en efterfråga som inte möts idag. Därför börjar rapporten med behovet av fortbildning och korta genomgångar av möjligheter som redan finns för att etablera en betydande verksamhet.

Sedan diskuteras frågan om anslagsfinansierad kontra uppdragsfinansierad fortbildning samt utformning av fortbildningskurser. Jag skissar sedan på en ändamålsenlig organisation för ett verksamhetsstöd.  Sist i rapport föreslår jag en handlingsplan som bör följas av en genomförandeplan med konkreta, realiserbara erbjudanden och samarbeten.

Jag gör inga anspråk på att handledningen täcker alla väsentliga områden för fortbildning vare sig  i stort eller för enskilda utbildningsområden. Den är ämnad som en utgångspunkt för arbeten med att ta fram ett utbud och en organisation för att erbjuda fortbildning till yrkesverksamma i en större omfattning än vad som sker idag. 

Publisher
p. 17
Series
TRITA-EECS-RP ; 2023:3
Keywords
Fortbildning, vidareutbildning, omskolning, högre utbildning
National Category
Educational Sciences
Identifiers
urn:nbn:se:kth:diva-331268 (URN)
Note

QC 20230707

Available from: 2023-07-06 Created: 2023-07-06 Last updated: 2023-08-09Bibliographically approved
Fernandez, L. & Karlsson, G. (2023). Squashing Resource Exhaustion Bugs with Black-Box Fuzzing and Reinforcement Learning. In: 2023 7th International Conference on System Reliability and Safety, ICSRS 2023: . Paper presented at 7th International Conference on System Reliability and Safety, ICSRS 2023, Bologna, Italy, Nov 22 2023 - Nov 24 2023 (pp. 439-448). Institute of Electrical and Electronics Engineers (IEEE)
Open this publication in new window or tab >>Squashing Resource Exhaustion Bugs with Black-Box Fuzzing and Reinforcement Learning
2023 (English)In: 2023 7th International Conference on System Reliability and Safety, ICSRS 2023, Institute of Electrical and Electronics Engineers (IEEE) , 2023, p. 439-448Conference paper, Published paper (Refereed)
Abstract [en]

For a software system to be reliable, it must manage its resources properly. Failure to do so will result in unreliable behaviour: an application that leaks memory will eventually crash, a packet source that overloads a queue may cause other systems to fail, a process that consumes too many CPU cycles will degrade the performance of other processes and so on. Resource leaks or resource exhaustion are difficult to discover during testing as it may happen slowly over a long time. One approach for discovering issues with reliability, security and robustness is fuzzing (short for fuzz testing). Fuzzing can take many forms, depending on what type of system is to be tested and what kinds of bugs one is after. Black-box fuzzing is arguably the most flexible approach to fuzzing. Unfortunately, it suffers from a low efficiency that makes it slow at finding bugs such as resource leaks. In this paper we explore the topic of black-box fuzzing by modeling it as a multi-armed bandit problem, an important subclass of the general reinforcement learning problem. We believe that by utilizing a reinforcement learning framework, black-box fuzzing can be better understood and attention can be drawn to the field, which deserves to be studied more. We also implement a fuzzer according to our model and evaluate it against a toy implementation of a simple protocol with a known resource leak. Lastly, we apply our fuzzer in a real-world case study against two widely distributed implementations of the Link Layer Discovery Protocol (LLDP), a key component in critical infrastructure applications such as network management and network automation. Our results show that our fuzzer gradually learns how to effectively trigger the resource leak in the toy implementation, thereby speeding up the bug discovery process. In the case study, the fuzzer struggles to learn from the observations it makes about the test target. We believe this to be because of excessive delays between the actions the fuzzer takes during testing and their corresponding effects. Despite this, our fuzzer still manages to find one resource leak in each of the two LLDP implementations, one of which was previously unknown. With this paper, we have taken the first steps towards a better understanding of black-box fuzzing and that a new generation of smart and highly efficient black-box fuzzers is within reach.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2023
Keywords
Cybersecurity, Fuzz Testing, Reinforcement Learning, Resource Exhaustion
National Category
Computer Sciences Software Engineering
Identifiers
urn:nbn:se:kth:diva-343177 (URN)10.1109/ICSRS59833.2023.10381445 (DOI)2-s2.0-85183463254 (Scopus ID)
Conference
7th International Conference on System Reliability and Safety, ICSRS 2023, Bologna, Italy, Nov 22 2023 - Nov 24 2023
Note

QC 20240208

Part of ISBN 979-8-3503-0605-7

Available from: 2024-02-08 Created: 2024-02-08 Last updated: 2026-02-18Bibliographically approved
Fernandez, L., Karlsson, G. & Hübinette, D. (2022). A Framework for Feedback-Enabled Blackbox Fuzzing Using Context-Free Grammars.
Open this publication in new window or tab >>A Framework for Feedback-Enabled Blackbox Fuzzing Using Context-Free Grammars
2022 (English)Report (Other academic)
Abstract [en]

For some 30 years, fuzzing has been a favored methodology for vulnerability discovery and robustness testing by researchers anddevelopers alike. Following the popularity of American Fuzzy Lop and the rise of coverage-guided fuzzing, many state-of-the-art fuzzersemploy heavy instrumentation, work best on small components and often require source code access. For networking equipmentsuch as switches and routers, this may not be feasible. If the software needs to run on or interact with specialized hardware, fuzzingthe equipment on a component level becomes very difficult. Heavy instrumentation may also degrade the performance of the SUTtoo much, thus invalidating the testing. Furthermore, the customers who buy the networking equipment often want to do their ownsecurity or robustness testing, but lack access to the source code.This paper details the design and usage of a grammar-based fuzzing framework and applies it to the Link Layer Discovery Protocol(LLDP), which is commonly used by industrial networking equipment. By modeling the fuzzing campaign as a multi-armed banditproblem, the grammar used to generate frames is able to adapt to observations made by lightweight probes, a novel concept accordingto the author’s knowledge.

Publisher
p. 19
Series
TRITA-EECS-RP ; 2023:2
National Category
Software Engineering
Identifiers
urn:nbn:se:kth:diva-323237 (URN)
Note

QC 20230123

Available from: 2023-01-23 Created: 2023-01-23 Last updated: 2023-01-23Bibliographically approved
Karlsson, G. (2022). Snabbt om fortbildning: En lathund. Stockholm: KTH Royal Institute of Technology
Open this publication in new window or tab >>Snabbt om fortbildning: En lathund
2022 (Swedish)Report (Other (popular science, discussion, etc.))
Abstract [sv]

Högskoleutbildning för yrkesverksamma kan vara svår att överblicka och förstå. Denna kortfattade text är ämnad att förklara hur högskolor kan hjälpa organisationer med kompetensförsörjning genom att utbilda anställda.

Place, publisher, year, edition, pages
Stockholm: KTH Royal Institute of Technology, 2022
Series
TRITA-EECS-RP ; 2022:4
Keywords
Fortbildning, uppdragsutbildning, livslångt lärande, kompetensförsörjning
National Category
Educational Sciences Other Electrical Engineering, Electronic Engineering, Information Engineering
Identifiers
urn:nbn:se:kth:diva-313721 (URN)
Note

QC 20220628

Available from: 2022-06-17 Created: 2022-06-17 Last updated: 2024-03-18Bibliographically approved
Organisations
Identifiers
ORCID iD: ORCID iD iconorcid.org/0000-0002-3704-1338

Search in DiVA

Show all publications