MobiDeke Fuzzing the GSM Protocol Stack
MobiDeke: Fuzzing the GSM Protocol Stack
MobiDeke: Fuzzing the GSM Protocol Stack
- No tags were found...
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
Introduction<strong>Fuzzing</strong> over-<strong>the</strong>-airThe <strong>MobiDeke</strong> FrameworkConclusionTestcases generation and mutationMonitoringReportFuture enhancementMethods for data generation and mutationCreating crafted L3 messages• Dumb: using captures (MBUS Nokia, OsmocomBB...) and bit-flipping• Smarter: knowing <strong>the</strong> structure of <strong>the</strong> messages• gsm um for scapy: interesting but not complete• libmich developed by Benoît Michau: we have chosen this solution for <strong>the</strong>most partMutations• ‘libmich’ Mutor• Sulley mutation engineIt is better to combine multiple generation methods to cover as much testcases aspossible.<strong>MobiDeke</strong>: <strong>Fuzzing</strong> <strong>the</strong> <strong>GSM</strong> <strong>Protocol</strong> <strong>Stack</strong> 22/38