Score
Designs, implements, and analyzes secure communication and cryptographic protocols—including authentication, transport, heartbeat, industrial, and hardware-interface protocols—as well as protocol adapters and language-server/networking protocol integrations. Produces protocol specifications and implementations, adapts and optimizes protocols for new environments, and evaluates correctness, security, and performance using formal analysis, testing, and experimental development.
Protocol designers often face a high barrier to entry in using formal verification tools such as ProVerif and Tamarin due to the lack of systematic guidance on translating security properties into executable models. This work addresses this gap by conducting a systematic review of 53 studies published between 2022 and 2025, resulting in the first comprehensive taxonomy of security properties tailored to mainstream verification tools. The taxonomy integrates informal explanations, first-order logic definitions, and tool-specific modeling exemplars. By bridging the gap between theoretical formulations and practical modeling, this study significantly enhances the accuracy and efficiency of protocol modeling. An accompanying open-source repository of illustrative examples further lowers the practical barrier to adopting formal verification in real-world protocol design.
Ensuring functional correctness and performance resilience of network protocols under component failures and adversarial attacks remains a significant challenge. Method: This paper proposes a synergistic analysis framework integrating formal verification with attack synthesis. It models protocol behavior using a formal specification language and employs logical predicates, trace analysis, and model checking to achieve closed-loop verification—simultaneously establishing correctness guarantees and automatically generating realistic attack scenarios. Contribution/Results: Diverging from conventional unidirectional verification, our approach innovatively embeds attack-path generation directly into the verification workflow, enabling reproducible and interpretable failure attribution. Experimental evaluation across multiple mainstream network protocols demonstrates substantial improvements in vulnerability detection rates and attack-surface characterization accuracy. The results validate the feasibility and practicality of formal methods for deep, security-critical analysis of complex network protocols.
This work addresses the semantic gap between informal protocol specifications—such as IETF RFCs—and formal specifications. It introduces a cognitive discrepancy analysis framework that identifies fundamental limitations in RFCs, including semantic ambiguity, unstated assumptions, and logical inconsistency. Methodologically, the approach integrates formal specification languages (e.g., TLA⁺), state-machine modeling, and protocol conformance testing to perform semantic parsing and cross-version consistency checking on real-world RFC texts and reference implementations. A key contribution is the establishment of a collaborative paradigm bridging industry practitioners and formal methods researchers, facilitating the evolution of RFCs into verifiable, executable formal specifications. Empirical evaluation demonstrates that this methodology significantly improves defect detection rates, interoperability assurance, and depth of security verification. The proposed framework provides a reusable, scalable foundation for formalizing next-generation Internet protocol standards.
Addressing the “oracle absence” and “error attribution difficulty” challenges in network protocol parser verification, this paper proposes an LLM-driven framework for RFC semantic parsing and feedback-based oracle refinement. First, large language models automatically translate unstructured RFC text into formal message specifications. Second, an iterative, quasi-oracle is constructed to support specification-guided fuzz testing and cross-language (C/Python/Go) protocol implementation verification. Finally, vulnerabilities are precisely traced back to their originating RFC clauses. This work is the first to integrate LLM-based semantic understanding with dynamic oracle refinement. Evaluated on nine mainstream protocols, it discovers 69 vulnerabilities—36 of which have been confirmed—surpassing state-of-the-art approaches in both effectiveness and efficiency. It also demonstrates, for the first time, the feasibility of fully automated derivation of test oracles directly from natural-language protocol specifications.
Existing formal verification approaches for Mobile Ad-hoc Network (MANET) routing protocols lack a unified framework integrating functional correctness, real-time guarantees, and security. Method: This work introduces the first systematic integration of multi-dimensional formal methods: temporal logic and process algebra for specification; model checking and performance modeling for analysis; and a mobility model tailored to MANETs’ dynamic topology. A taxonomy classifying functional, timing, and security properties is proposed, alongside a consolidated survey of modeling paradigms and verification tools, establishing explicit mappings among protocols, formal methods, and property classes. Contribution: The study delivers a reusable theoretical framework and methodological pipeline for formal verification of MANET routing protocols. It bridges a critical gap by providing the first comprehensive, structured survey and foundational framework for this fragmented domain—enabling rigorous, holistic protocol assurance across functional, temporal, and security dimensions.
Ambiguities in the IETF QUIC specification (draft-29) hinder precise implementation and complicate compliance verification. Method: This work presents the first comprehensive formal model of draft-29, built within the Ivy framework and integrating state-machine modeling, SMT-based constraint solving, and differential testing to automate compliance validation across seven mainstream QUIC client/server implementations. Contribution/Results: Leveraging formal reverse analysis, we systematically uncover specification ambiguities and propose actionable remediation paths. Our approach identifies multiple critical compliance violations across implementations and pinpoints several interoperability-affecting specification ambiguities—directly informing ongoing IETF standard revisions. The methodology establishes a scalable, end-to-end framework for protocol formal verification, bridging high-level specifications with executable conformance checks while supporting both automated bug detection and specification refinement.
This study addresses the lack of systematic empirical analysis of the “Security Considerations” sections in Internet standards documents (RFCs). It presents the first large-scale mixed-methods investigation, combining quantitative and qualitative approaches with textual and network analysis to systematically examine the content characteristics, citation structures, and thematic evolution of these sections. The findings reveal that over 90% of RFCs explicitly discuss security issues, yet very few impose mandatory requirements. Security discussions are highly protocol-specific and exhibit citation concentration around a small set of core RFCs. By uncovering the protocol-specific nature, sparse citation patterns, and historical development of security discourse in RFCs, this work fills a critical gap in empirical research on security governance within Internet standardization.
This work addresses the absence of a systematic security framework in existing AI agent protocols—such as MCP and A2A—which undermines secure interactions across trust boundaries. We propose a six-layer protocol stack model tailored for AI agent communication and an implementation-agnostic Agent-Centric Security Model (AASM). To enforce and validate this model, we develop AgentConform, a two-stage conformance checking tool that integrates TLA+ formal modeling, a typed Protocol Intermediate Representation (IR), model checking, and runtime replay verification. For the first time, we formally define eleven security principles and introduce a mechanism for composition safety. Applying our approach to mainstream protocols reveals systemic flaws concerning credential lifecycle management, authorization enforcement, audit integrity, and compositional security; several identified vulnerabilities are already undergoing coordinated disclosure.
This work addresses the inefficiencies and semantic inconsistencies arising from separately implementing driver and monitor programs in traditional hardware module testing. To overcome this, the authors propose a domain-specific language (DSL) tailored to hardware communication protocols, which enables the unified specification of both driver and monitor logic through an imperative syntax, thereby ensuring their semantic consistency for the first time. Building upon this DSL, they develop a prototype tool that leverages waveform parsing and transaction-level trace inference techniques to accurately reconstruct protocol-compliant transaction sequences from raw signal waveforms. Experimental results demonstrate that the approach significantly improves development efficiency, with further validation planned on real-world interconnect protocols such as Wishbone and AXI-Stream.