09.08.2015 Views

MobiDeke Fuzzing the GSM Protocol Stack

MobiDeke: Fuzzing the GSM Protocol Stack

MobiDeke: Fuzzing the GSM Protocol Stack

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Introduction<strong>Fuzzing</strong> over-<strong>the</strong>-airThe <strong>MobiDeke</strong> FrameworkConclusionTestcases generation and mutationMonitoringReportFuture enhancementMethods for data generation and mutationCreating crafted L3 messages• Dumb: using captures (MBUS Nokia, OsmocomBB...) and bit-flipping• Smarter: knowing <strong>the</strong> structure of <strong>the</strong> messages• gsm um for scapy: interesting but not complete• libmich developed by Benoît Michau: we have chosen this solution for <strong>the</strong>most partMutations• ‘libmich’ Mutor• Sulley mutation engineIt is better to combine multiple generation methods to cover as much testcases aspossible.<strong>MobiDeke</strong>: <strong>Fuzzing</strong> <strong>the</strong> <strong>GSM</strong> <strong>Protocol</strong> <strong>Stack</strong> 22/38

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!