IoT Application-Layer Protocol Vulnerability Detection using Reverse Engineering
Autor: | Chun Shan, Jun Cai, Jian-Zhen Luo, Yan Liu |
---|---|
Jazyk: | angličtina |
Rok vydání: | 2018 |
Předmět: |
Physics and Astronomy (miscellaneous)
Network security Computer science General Mathematics IoT security Code coverage 02 engineering and technology Field (computer science) 0202 electrical engineering electronic engineering information engineering Computer Science (miscellaneous) Protocol (object-oriented programming) business.industry lcsh:Mathematics change-point detection Byte 020206 networking & telecommunications Fuzz testing Construct (python library) lcsh:QA1-939 Application layer Chemistry (miscellaneous) vulnerability detection 020201 artificial intelligence & image processing protocol reverse engineering business Computer network |
Zdroj: | Symmetry Volume 10 Issue 11 Pages: 561 Symmetry, Vol 10, Iss 11, p 561 (2018) |
ISSN: | 2073-8994 |
DOI: | 10.3390/sym10110561 |
Popis: | Fuzzing is regarded as the most promising method for protocol vulnerabilities discovering in network security of Internet of Things (IoT). However, one fatal drawback of existing fuzzing methods is that a huge number of test files are required to maintain a high test coverage. In this paper, a novel method based on protocol reverse engineering is proposed to reduce the amount of test files for fuzzing. The proposed method uses techniques in the field of protocol reverse engineering to identify message formats of IoT application-layer protocol and create test files by generating messages with error fields according to message formats. The protocol message treated as a sequence of bytes is assumed to obey a statistic process with change-points indicating the boundaries of message fields. Then, a multi-change-point detection procedure is introduced to identify change-points of byte sequences according to their statistic properties and divide them into segments according to their change-points. The message segments are further processed via a position-based occurrence probability test analysis to identify keyword fields, data fields and uncertain fields. Finally, a message generation procedure with mutation operation on message fields is applied to construct test files for fuzzing test. The results show that the proposed method can effectively find out the message fields and significantly reduce the amount of test files for fuzzing test. |
Databáze: | OpenAIRE |
Externí odkaz: | |
Nepřihlášeným uživatelům se plný text nezobrazuje | K zobrazení výsledku je třeba se přihlásit. |