Improve feedback over encrypted database connections

Develop a TraceLib-compatible method that recovers useful database feedback when application-to-database connections are protected by Transport Layer Security and SQL statements are encrypted before reaching the system-call interface.

Background

TraceLib obtains database-related feedback by observing SQL statements at the system-call boundary. When the database connection uses TLS, the network data is encrypted before it reaches that boundary, preventing TraceLib from recovering SQL text and substantially reducing the available feedback. Although disabling TLS in a controlled fuzzing environment can mitigate the limitation, the general problem of effective feedback for encrypted connections remains unresolved.

References

Open problems include the restriction to one active request at a time, dependence on application externalization, and reduced effectiveness on encrypted database connections.

— TraceLib: System-Call Bitmap Feedback Mechanism for Language-Agnostic Web Fuzzing  (2609.34778 - Dharmaadi et al., 28 Sep 2026) in Abstract; Section ‘Limitations’, subsection ‘Reduced Effectiveness on Encrypted Connections’