Our pa­per on Ana­ly­sis of DTLS Im­ple­men­ta­ti­ons Using Pro­to­col State Fuz­zing got ac­cep­ted to USE­NIX Se­cu­ri­ty 2020

In our work, we analyze DTLS implementations using state learning methods and uncover several nice bugs in widely used libraries. For example, we found  a client-authentication bypass in JSSE (CVE-2020-2655), the default (D)TLS stack used in Java.

You can read the preliminary paper version here:


Or, you can already watch a talk presented by Robert Merget at RuhrSec 2020:


This was a joint work with Uppsala University, Ruhr University Bochum, and SIDN Labs.