DocumentCode :
3668672
Title :
A vulnerability detecting method for Modbus-TCP based on smart fuzzing mechanism
Author :
Qi Xiong;Hui Liu;Yuan Xu;Huayi Rao;Shengwei Yi;Baofeng Zhang;Wei Jia;Hui Deng
Author_Institution :
China Information Technology Security Evaluation Center, Beijing, China
fYear :
2015
fDate :
5/1/2015 12:00:00 AM
Firstpage :
404
Lastpage :
409
Abstract :
As one of the most popular industrial network protocol used in the energy distribution field, the security, especially vulnerability of Modbus-TCP protocol has attracted great attentions from both academic and industrial field. Due to the Particularity of Modbus-TCP, traditional fuzzing framework for vulnerability detecting cannot work efficiently. To overcome this drawback, a special smart fuzzing technology for Modbus-TCP is proposed, the architecture is described in detail, an adaptive algorithm for test case generating and the workflow of the testing process are presented, which can smartly generate test case according to the feedback from target. The result of the simulation experiment show that the mechanism described can satisfy the requirement of the vulnerability detecting for Modbus-TCP well. What´s more, compared with traditional fuzzing framework, the quality of the test case and the efficiency of the process are apparently improved without losing the coverage.
Keywords :
"Protocols","Testing","Security","Information technology","Monitoring","Servers","Industrial control"
Publisher :
ieee
Conference_Titel :
Electro/Information Technology (EIT), 2015 IEEE International Conference on
Electronic_ISBN :
2154-0373
Type :
conf
DOI :
10.1109/EIT.2015.7293376
Filename :
7293376
Link To Document :
بازگشت