A vulnerability detecting method for Modbus-TCP based on smart fuzzing mechanism

Qi Xiong, Hui Liu, Yuan Xu, Huayi Rao, Shengwei Yi, Baofeng Zhang, Wei Jia, Hui Deng
{"title":"A vulnerability detecting method for Modbus-TCP based on smart fuzzing mechanism","authors":"Qi Xiong, Hui Liu, Yuan Xu, Huayi Rao, Shengwei Yi, Baofeng Zhang, Wei Jia, Hui Deng","doi":"10.1109/EIT.2015.7293376","DOIUrl":null,"url":null,"abstract":"As one of the most popular industrial network protocol used in the energy distribution field, the security, especially vulnerability of Modbus-TCP protocol has attracted great attentions from both academic and industrial field. Due to the Particularity of Modbus-TCP, traditional fuzzing framework for vulnerability detecting cannot work efficiently. To overcome this drawback, a special smart fuzzing technology for Modbus-TCP is proposed, the architecture is described in detail, an adaptive algorithm for test case generating and the workflow of the testing process are presented, which can smartly generate test case according to the feedback from target. The result of the simulation experiment show that the mechanism described can satisfy the requirement of the vulnerability detecting for Modbus-TCP well. What's more, compared with traditional fuzzing framework, the quality of the test case and the efficiency of the process are apparently improved without losing the coverage.","PeriodicalId":415614,"journal":{"name":"2015 IEEE International Conference on Electro/Information Technology (EIT)","volume":"42 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-05-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"15","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 IEEE International Conference on Electro/Information Technology (EIT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/EIT.2015.7293376","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 15

Abstract

As one of the most popular industrial network protocol used in the energy distribution field, the security, especially vulnerability of Modbus-TCP protocol has attracted great attentions from both academic and industrial field. Due to the Particularity of Modbus-TCP, traditional fuzzing framework for vulnerability detecting cannot work efficiently. To overcome this drawback, a special smart fuzzing technology for Modbus-TCP is proposed, the architecture is described in detail, an adaptive algorithm for test case generating and the workflow of the testing process are presented, which can smartly generate test case according to the feedback from target. The result of the simulation experiment show that the mechanism described can satisfy the requirement of the vulnerability detecting for Modbus-TCP well. What's more, compared with traditional fuzzing framework, the quality of the test case and the efficiency of the process are apparently improved without losing the coverage.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
基于智能模糊机制的Modbus-TCP漏洞检测方法
Modbus-TCP协议作为能源分配领域中应用最广泛的工业网络协议之一,其安全性,尤其是其存在的漏洞受到了学术界和工业界的高度关注。由于Modbus-TCP协议的特殊性,传统的漏洞检测模糊框架无法有效地进行漏洞检测。针对这一缺点,提出了一种针对Modbus-TCP的专用智能模糊测试技术,详细描述了该技术的体系结构,给出了一种自适应的测试用例生成算法和测试过程的工作流程,能够根据目标的反馈智能地生成测试用例。仿真实验结果表明,所描述的机制能够很好地满足Modbus-TCP漏洞检测的要求。并且,与传统的模糊测试框架相比,测试用例的质量和过程的效率得到了明显的提高,同时又不损失测试的覆盖率。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Space time block code for four time slots and two transmit antennas Social routing: A novel routing protocol for delay tolerant network based on dynamic connectivity Radiation performance and Specific Absorption Rate (SAR) analysis of a compact dual band balanced antenna Design of half bridge LLC resonant converter using synchronous rectifier Frame distance array algorithm parameter tune-up for TIMIT corpus automatic speech segmentation
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1