search query: @keyword fuzzing / total: 2
reference: 2 / 2
« previous | next »
Author:Juhász, Norbert
Title:Test Generation and Fuzz Testing Design
Publication type:Master's thesis
Publication year:2015
Pages:iv + 55      Language:   eng
Department/School:Perustieteiden korkeakoulu
Main subject:Service Design and Engineering   (SCI3022)
Supervisor:Nurminen, Jukka ; Pataki, Norbert
Instructor:Tóth, Attila
Electronic version URL: http://urn.fi/URN:NBN:fi:aalto-201509184335
Location:P1 Ark Aalto  3120   | Archive
Keywords:fuzzing
security testing
SS7
MAP protocol
Abstract (eng):Global System for Mobile Communications (GSM) network is one of the most vulnerable systems and it is a popular target for hackers.
Its core communication protocol is based on legacy protocol stack Signaling System No. 7 (SS7), which shows more and more known vulnerabilities.
However, securing these issues is quite a complex task.
The paper focuses on the SS7 protocol family, especially on the Mobile Application Protocol (MAP), which handles sensitive information about the mobile subscribers' location and enabled services.
Fuzzers are tools that are frequently used by hackers to locate security holes in software, and their popularity has grown among the security testers as well.

In my thesis I compared various fuzzers and conducted fuzz testing on a Home Location Register in order to locate vulnerabilities in the communication interface.
I configured a generational fuzzer called Sulley to test the Update Location operation of the MAP and analyze its behavior during the process.
My results showed that including malicious data in the IMSI, MSC-number and VLR-number parameters did not cause any complication.
However, initiating plenty, incomplete transaction in a short time can produce system failure.
ED:2015-09-27
INSSI record number: 52054
+ add basket
« previous | next »
INSSI