Fuzzing Technology Based on Information Theory for Industrial Proprietary Protocol
نویسندگان
چکیده
With the rapid development of Industrial Internet Things (IIoT), programmable logic controllers (PLCs) are becoming increasingly intelligent, leading to improved productivity. However, this also brings about a growing number security vulnerabilities. As result, efficiently identifying potential vulnerabilities in PLCs has become crucial research topic for researchers. This article proposes method fuzzing industrial proprietary protocols effectively identify PLCs’ protocols. The aim study is develop protocol approach that can uncover To achieve this, presents structure parsing algorithm specifically designed PLC protocols, utilizing information theory. Additionally, case generation based on genetic algorithms introduced select test cases adhere format specifications while exhibiting high degree mutation. methodology consists several steps. Firstly, proposed used analyze two known namely Modbus TCP and S7Comm. results obtained from then compared with correct validate its effectiveness. Next, applied formats models. Finally, analysis results, subjected fuzzing. Overall, approach, incorporating algorithm, successfully identifies denial-of-service Notably, one these zero-day vulnerability, indicating it was previously unknown undisclosed.
منابع مشابه
Pulsar: Stateful Black-Box Fuzzing of Proprietary Network Protocols
The security of network services and their protocols critically depends on minimizing their attack surface. A single flaw in an implementation can suffice to compromise a service and expose sensitive data to an attacker. The discovery of vulnerabilities in protocol implementations, however, is a challenging task: While for standard protocols this process can be conducted with regular techniques...
متن کاملapplication of upfc based on svpwm for power quality improvement
در سالهای اخیر،اختلالات کیفیت توان مهمترین موضوع می باشد که محققان زیادی را برای پیدا کردن راه حلی برای حل آن علاقه مند ساخته است.امروزه کیفیت توان در سیستم قدرت برای مراکز صنعتی،تجاری وکاربردهای بیمارستانی مسئله مهمی می باشد.مشکل ولتاژمثل شرایط افت ولتاژواضافه جریان ناشی از اتصال کوتاه مدار یا وقوع خطا در سیستم بیشتر مورد توجه می باشد. برای مطالعه افت ولتاژ واضافه جریان،محققان زیادی کار کرده ...
15 صفحه اولInformation Technology in B2B E-procurement: Open vs. Proprietary Systems
This article presents an economic model of a monopoly retailer with supply and demand uncertainties that enables the study of incentives for B2B e-procurement technology investments that permit inventory coordination and operating cost control. In this context, we focus on the information technology (IT) adoption behavior of firms, emphasizing the trade-offs they make between managing supply pr...
متن کاملA multi agent method for cell formation with uncertain situation, based on information theory
This paper assumes the cell formation problem as a distributed decision network. It proposes an approach based on application and extension of information theory concepts, in order to analyze informational complexity in an agent- based system, due to interdependence between agents. Based on this approach, new quantitative concepts and definitions are proposed in order to measure the amount of t...
متن کاملImproving Protocol State Fuzzing of SSH
With the scale and use of the Internet nowadays, it is crucial that we can effectively test the correctness and security of systems that handle our personal data. In this thesis, we improve upon a previous work by Verleg. Verleg used protocol state fuzzing to test several implementations of the SSH protocol. By adapting a more formal methodology, we achieve higher confidence in our results. We ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
ژورنال
عنوان ژورنال: Electronics
سال: 2023
ISSN: ['2079-9292']
DOI: https://doi.org/10.3390/electronics12143041