haku: @keyword SS7 / yhteensä: 11
viite: 2 / 11
Tekijä: | Juhász, Norbert |
Työn nimi: | Test Generation and Fuzz Testing Design |
Julkaisutyyppi: | Diplomityö |
Julkaisuvuosi: | 2015 |
Sivut: | iv + 55 Kieli: eng |
Koulu/Laitos/Osasto: | Perustieteiden korkeakoulu |
Oppiaine: | Service Design and Engineering (SCI3022) |
Valvoja: | Nurminen, Jukka ; Pataki, Norbert |
Ohjaaja: | Tóth, Attila |
Elektroninen julkaisu: | http://urn.fi/URN:NBN:fi:aalto-201509184335 |
Sijainti: | P1 Ark Aalto 3120 | Arkisto |
Avainsanat: | fuzzing security testing SS7 MAP protocol |
Tiivistelmä (eng): | Global System for Mobile Communications (GSM) network is one of the most vulnerable systems and it is a popular target for hackers. Its core communication protocol is based on legacy protocol stack Signaling System No. 7 (SS7), which shows more and more known vulnerabilities. However, securing these issues is quite a complex task. The paper focuses on the SS7 protocol family, especially on the Mobile Application Protocol (MAP), which handles sensitive information about the mobile subscribers' location and enabled services. Fuzzers are tools that are frequently used by hackers to locate security holes in software, and their popularity has grown among the security testers as well. In my thesis I compared various fuzzers and conducted fuzz testing on a Home Location Register in order to locate vulnerabilities in the communication interface. I configured a generational fuzzer called Sulley to test the Update Location operation of the MAP and analyze its behavior during the process. My results showed that including malicious data in the IMSI, MSC-number and VLR-number parameters did not cause any complication. However, initiating plenty, incomplete transaction in a short time can produce system failure. |
ED: | 2015-09-27 |
INSSI tietueen numero: 52054
+ lisää koriin
INSSI