• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Cluster Crash: Learning from Recent Vulnerabilities in Communication Stacks
 
  • Details
  • Full
Options
2022
Conference Paper
Title

Cluster Crash: Learning from Recent Vulnerabilities in Communication Stacks

Abstract
To ensure functionality and security of network stacks in Industrial Devices, thorough testing is necessary. This includes blackbox network fuzzing, where fields in network packets are filled with unexpected values to test the device's behavior in edge cases. Due to resource constraints, the tests need to be efficient and such the input values need to be chosen intelligently. Previous solutions use heuristics based on vague knowledge from previous projects to make these decisions. We aim to structure existing knowledge by defining Vulnerability Anti-Patterns for network communication stacks based on an analysis of the recent vulnerability groups Ripple20, Amnesia:33, and Urgent/11. For our evaluation, we implement fuzzing test scripts based on the Vulnerability Anti-Patterns and run them against 8 Industrial Devices from 5 different device classes. We show (I) that similar vulnerabilities occur in implementations of the same protocol as well as in different protocols, (II) that similar vulnerabilities also spread over different device classes, and (III) that test scripts based on the Vulnerability Anti-Patterns help to identify these vulnerabilities.
Author(s)
Borcherding, Anne  
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Takacs, Philipp
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Beyerer, Jürgen  
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Mainwork
ICISSP 2022, 8th International Conference on Information Systems Security and Privacy. Proceedings  
Project(s)
KASTEL
Funder
Bundesministerium für Bildung und Forschung BMBF (Deutschland)  
Conference
International Conference on Information Systems Security and Privacy (ICISSP) 2022  
Open Access
DOI
10.5220/0010806300003120
Additional full text version
Landing Page
Language
English
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Keyword(s)
  • industrial control system

  • Anti-Patterns

  • Vulnerability Testing

  • Ripple20

  • Amnesia-33

  • Urgent / 11

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024