haku: @keyword SS7 / yhteensä: 11
viite: 2 / 11
Tekijä:Juhász, Norbert
Työn nimi:Test Generation and Fuzz Testing Design
Julkaisutyyppi:Diplomityö
Julkaisuvuosi:2015
Sivut:iv + 55      Kieli:   eng
Koulu/Laitos/Osasto:Perustieteiden korkeakoulu
Oppiaine:Service Design and Engineering   (SCI3022)
Valvoja:Nurminen, Jukka ; Pataki, Norbert
Ohjaaja:Tóth, Attila
Elektroninen julkaisu: http://urn.fi/URN:NBN:fi:aalto-201509184335
Sijainti:P1 Ark Aalto  3120   | Arkisto
Avainsanat:fuzzing
security testing
SS7
MAP protocol
Tiivistelmä (eng):Global System for Mobile Communications (GSM) network is one of the most vulnerable systems and it is a popular target for hackers.
Its core communication protocol is based on legacy protocol stack Signaling System No. 7 (SS7), which shows more and more known vulnerabilities.
However, securing these issues is quite a complex task.
The paper focuses on the SS7 protocol family, especially on the Mobile Application Protocol (MAP), which handles sensitive information about the mobile subscribers' location and enabled services.
Fuzzers are tools that are frequently used by hackers to locate security holes in software, and their popularity has grown among the security testers as well.

In my thesis I compared various fuzzers and conducted fuzz testing on a Home Location Register in order to locate vulnerabilities in the communication interface.
I configured a generational fuzzer called Sulley to test the Update Location operation of the MAP and analyze its behavior during the process.
My results showed that including malicious data in the IMSI, MSC-number and VLR-number parameters did not cause any complication.
However, initiating plenty, incomplete transaction in a short time can produce system failure.
ED:2015-09-27
INSSI tietueen numero: 52054
+ lisää koriin
INSSI