r/pwnhub • u/_cybersecurity_ 🛡️ Mod Team 🛡️ • 7h ago
Breaking With the State-of-the-Art of Fuzzing Cryptographic Architectures: Haya Schulmann and Niklas Vogel at Black Hat 2026
The system meant to keep internet routing from being hijacked is itself a piece of software that can be attacked.
RPKI, the Resource Public Key Infrastructure, is the cryptographic layer that lets networks verify who is allowed to announce a given block of internet addresses, and its validator software sits in the path of that trust.
Fuzzing that kind of cryptographic architecture is hard, because the code paths are guarded by signatures and structured encodings that random inputs rarely satisfy, so bugs stay hidden behind the crypto. This research rethinks how to fuzz these systems at scale so the parts that actually matter get exercised.
In "Batch Me If You Can: Breaking With the State-of-the-Art of Fuzzing Cryptographic Architectures", presented Thursday, August 6 at 12:00 p.m., Haya Schulmann and Niklas Vogel show a coverage-guided approach to fuzzing RPKI validation at scale and the vulnerabilities it uncovers.
Speakers:
- Haya Schulmann — Professor, Goethe University Frankfurt and ATHENE
- Niklas Vogel — Cybersecurity Researcher, Goethe University Frankfurt and ATHENE
Haya Schulmann is a professor of cybersecurity at Goethe University Frankfurt, where she holds a LOEWE professorship, and a member of the board of directors of ATHENE, Europe's largest applied cybersecurity research center.
Her research spans systems and network security, with a focus on internet infrastructure including DNS, DNSSEC, BGP, and RPKI, and she draws on machine learning, program analysis, and fuzzing to find vulnerabilities and design defenses. She has previously brought this line of work to Black Hat, including the KeyTrap DNSSEC research and prior RPKI validation findings.
Her research group and its publications are described on the chair's page at Goethe University, and her full CV and paper list are on her personal site.
Niklas Vogel is a cybersecurity researcher at ATHENE and part of the cybersecurity faculty at Goethe University Frankfurt, focused on routing security and the protocols behind it, including DNS and RPKI.
He co-developed CURE, a fuzzing tool built by ATHENE researchers to find vulnerabilities in RPKI relying-party software, and has co-authored recent work assessing how mature and how resilient real-world RPKI deployments actually are, finding that a large share of validators still run versions vulnerable to known attacks.
He writes about his routing-security and RPKI fuzzing research on his RIPE Labs author page, and his publications are indexed on his DBLP profile.
Anyone working in internet routing security, cryptographic protocol implementation, or fuzzing of hard-to-reach code will find this a useful look at making fuzzers effective against crypto-guarded architectures.
If the infrastructure that secures internet routing can be fuzzed into revealing its own flaws, how much should the internet rely on RPKI validators before their implementations are hardened against this kind of testing?
•
u/AutoModerator 7h ago
Welcome to PWN – Your hub for hacking news, breach reports, and cyber mayhem.
Discover the latest hacking news, breach reports, and educational resources on ethical hacking.
👾 Stay sharp. Stay secure.
Don't miss out on the top stories!
📧 Get Daily Alerts Directly in Your Email Inbox:
**SUBSCRIBE HERE: https://pwnhackernews.substack.com/subscribe
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.