Literature DB >> 29049409

Protocol vulnerability detection based on network traffic analysis and binary reverse engineering.

Shameng Wen1, Qingkun Meng1, Chao Feng1, Chaojing Tang1.   

Abstract

Network protocol vulnerability detection plays an important role in many domains, including protocol security analysis, application security, and network intrusion detection. In this study, by analyzing the general fuzzing method of network protocols, we propose a novel approach that combines network traffic analysis with the binary reverse engineering method. For network traffic analysis, the block-based protocol description language is introduced to construct test scripts, while the binary reverse engineering method employs the genetic algorithm with a fitness function designed to focus on code coverage. This combination leads to a substantial improvement in fuzz testing for network protocols. We build a prototype system and use it to test several real-world network protocol implementations. The experimental results show that the proposed approach detects vulnerabilities more efficiently and effectively than general fuzzing methods such as SPIKE.

Entities:  

Mesh:

Year:  2017        PMID: 29049409      PMCID: PMC5648143          DOI: 10.1371/journal.pone.0186188

Source DB:  PubMed          Journal:  PLoS One        ISSN: 1932-6203            Impact factor:   3.240


  1 in total

1.  Coverage-guided differential testing of TLS implementations based on syntax mutation.

Authors:  Yan Pan; Wei Lin; Yubo He; Yuefei Zhu
Journal:  PLoS One       Date:  2022-01-24       Impact factor: 3.240

  1 in total

北京卡尤迪生物科技股份有限公司 © 2022-2023.