09.08.2015 Views

MobiDeke Fuzzing the GSM Protocol Stack

MobiDeke: Fuzzing the GSM Protocol Stack

MobiDeke: Fuzzing the GSM Protocol Stack

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Introduction<strong>Fuzzing</strong> over-<strong>the</strong>-airThe <strong>MobiDeke</strong> FrameworkConclusionTestcases generation and mutationMonitoringReportFuture enhancementCheck ‘AT’ responses with <strong>the</strong> ’injecATor’ locally• We checked for phone responsiveness on <strong>the</strong> radio side• What about on <strong>the</strong> local interface?We modified Collin Mulliner’s ‘injector’ to forward ‘AT’ responses over <strong>the</strong> openedsocket.• Lack of AT response can indicate a baseband crash/reboot• Can also be used to simulate user interactions (e.g. accept a phone call)<strong>MobiDeke</strong>: <strong>Fuzzing</strong> <strong>the</strong> <strong>GSM</strong> <strong>Protocol</strong> <strong>Stack</strong> 26/38

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!