TLS clients testing

Autor: A. V. Nikeshin, N. V. Pakulin, V. Z. Shnitman
Rok vydání: 2015
Předmět:
Zdroj: Труды Института системного программирования РАН, Vol 27, Iss 2, Pp 145-160 (2018)
ISSN: 2220-6426
2079-8156
DOI: 10.15514/ispras-2015-27(2)-9
Popis: The paper presents a model-based approach to conformance testing of TLS implementations. It discusses the formal model of TLS protocol, the structure of the test suite. JavaTesK tool, based on UniTESK technology, was used to develop the test suite. A set of fuzz operators was developed for general data types and included in the test suite. We applied the test suite to a several popular implementations of TLS client, and present brief results. This approach has proved his efficiency, various errors and vulnerabilities had been found in all chosen TLS implementations.
Databáze: OpenAIRE