Score
Designs and builds formal models of protocols (message flows, transition systems, or trace semantics and corresponding type systems) and constructs mechanized analyses or proofs—using trace-based reasoning, type-driven verification, or similar formalisms—to verify protocol correctness properties such as safety, liveness, authentication, and integrity. Produces machine-checkable assurances or concrete counterexamples that detect and rule out protocol flaws through formal modeling and verification techniques.
Ensuring functional correctness and performance resilience of network protocols under component failures and adversarial attacks remains a significant challenge. Method: This paper proposes a synergistic analysis framework integrating formal verification with attack synthesis. It models protocol behavior using a formal specification language and employs logical predicates, trace analysis, and model checking to achieve closed-loop verification—simultaneously establishing correctness guarantees and automatically generating realistic attack scenarios. Contribution/Results: Diverging from conventional unidirectional verification, our approach innovatively embeds attack-path generation directly into the verification workflow, enabling reproducible and interpretable failure attribution. Experimental evaluation across multiple mainstream network protocols demonstrates substantial improvements in vulnerability detection rates and attack-surface characterization accuracy. The results validate the feasibility and practicality of formal methods for deep, security-critical analysis of complex network protocols.
Verifying protocol conformance in distributed heterogeneous systems—such as cloud–IoT environments—faces fundamental challenges due to cross-language, cross-type (including physical devices) message-passing protocols; conventional approaches rely on assumptions of uniform languages or type systems, limiting applicability. Method: We propose the first language-agnostic formal verification framework, based on labeled transition systems. We mechanize, for the first time in Coq, a logical relation supporting arbitrary labeled transition semantics—enabling unified behavioral modeling of typed/untyped software entities and real-world peripherals. Contribution/Results: The framework supports both instance-level fine-grained verification and type-system-level one-time verification. Experiments demonstrate that our approach eliminates implementation-language dependence, yielding the first provably correct, scalable, and general foundational solution for protocol conformance in heterogeneous systems.
Addressing the “oracle absence” and “error attribution difficulty” challenges in network protocol parser verification, this paper proposes an LLM-driven framework for RFC semantic parsing and feedback-based oracle refinement. First, large language models automatically translate unstructured RFC text into formal message specifications. Second, an iterative, quasi-oracle is constructed to support specification-guided fuzz testing and cross-language (C/Python/Go) protocol implementation verification. Finally, vulnerabilities are precisely traced back to their originating RFC clauses. This work is the first to integrate LLM-based semantic understanding with dynamic oracle refinement. Evaluated on nine mainstream protocols, it discovers 69 vulnerabilities—36 of which have been confirmed—surpassing state-of-the-art approaches in both effectiveness and efficiency. It also demonstrates, for the first time, the feasibility of fully automated derivation of test oracles directly from natural-language protocol specifications.
Protocol designers often face a high barrier to entry in using formal verification tools such as ProVerif and Tamarin due to the lack of systematic guidance on translating security properties into executable models. This work addresses this gap by conducting a systematic review of 53 studies published between 2022 and 2025, resulting in the first comprehensive taxonomy of security properties tailored to mainstream verification tools. The taxonomy integrates informal explanations, first-order logic definitions, and tool-specific modeling exemplars. By bridging the gap between theoretical formulations and practical modeling, this study significantly enhances the accuracy and efficiency of protocol modeling. An accompanying open-source repository of illustrative examples further lowers the practical barrier to adopting formal verification in real-world protocol design.
Current approaches to automated program synthesis lack effective governance mechanisms to ensure the compliance of generated code. This work proposes Protocol-Driven Development (PDD), a model that treats machine-executable protocols as primary artifacts and delineates the space of valid implementations through structural, behavioral, and operational invariants. PDD mandates that every implementation be accompanied by a verifiable chain of compliance evidence. By integrating formal methods, property-based testing, policy-as-code, and software provenance techniques, PDD establishes a unified framework for protocol specification and verification. This framework enables trustworthy admission control over automatically synthesized code, guaranteeing that all adopted implementations strictly adhere to protocol constraints and are backed by complete, auditable proofs of compliance.
This work addresses the state explosion problem inherent in asynchronous, parameterized distributed protocols, which arises from communication asynchrony and unbounded participant counts. The authors propose an automated safety verification method based on backward unreachableness analysis. Their key innovation lies in distinguishing parameterized unboundedness into affine and non-affine categories, focusing specifically on affine protocols. By integrating goal-directed instantiation, causal reasoning, and state summarization, the approach efficiently prunes the state space. The prototype tool DissProve successfully verifies multiple affine protocols featuring infinitely many participants and unbounded execution lengths, achieving—for the first time—scalable, fully automatic safety verification for such asynchronous parameterized systems.
Protocol model checking often suffers from state-space explosion, particularly when channel capacity or window size increases. This work proposes a compositional verification approach based on bidirectional simulation relations, constructing a hierarchy of protocol abstractions—SCP → ABP → SWP—with progressively refined semantics. By reducing the verification of complex protocols to that of the most abstract protocol, SCP, the method circumvents direct model checking of large state machines. Correctness of ABP and SWP is then derived from the invariance properties verified solely on SCP. This abstraction-based reduction significantly lowers computational complexity and enables efficient formal verification of protocols under high parameter settings.
This work addresses behavioral inconsistencies and deadlocks arising from protocol refinement in distributed systems by proposing a novel approach that integrates multiparty session types (MPST) formal specifications with large language models. By deeply embedding behavioral correctness constraints—such as deadlock freedom—into the generation process, the method achieves, for the first time, formal-specification-guided automatic protocol refinement. Evaluated across multiple large language models, the approach demonstrates high effectiveness, yielding valid protocols in 95.6%–99.5% of cases while maintaining strong syntactic correctness. It successfully generates diverse and non-trivial deadlock-free protocol variants, substantially enhancing the safety, compatibility, and scalability of protocol replacement in distributed environments.
This study addresses the limitations of existing SysML verification approaches, which are often tool-dependent and restricted to performance properties, lacking support for automated validation of behavioral and interface requirements. To overcome these shortcomings, this work proposes a tool-agnostic, automated verification workflow driven by SysML test cases, integrating UML Testing Profile and behavioral diagram constructs to enable unified validation of multidimensional attributes—including behavior, timing, and state responses. The methodology was developed through a mixed-methods research strategy combining literature review and stakeholder interviews, and its efficacy was empirically validated across two independent SysML toolchains. The approach not only transcends the constraints of conventional parametric methods but also enables automatic traceability of verification results back to the original model elements.