摘要
为挖掘IP多媒体子系统网络异常场景下Diameter协议流程中潜在的脆弱点,提出一种基于遗传算法的Diameter协议流程漏洞挖掘方法。通过变异网络配置、用户注册状态和服务器工作状态等,制造特定的应用场景,采用遗传算法对正常消息进行变异,生成针对该场景的多维模糊测试消息,通过监测网络对测试消息的响应判断是否存在相关脆弱性。仿真实验结果表明,该生成方法能保证测试消息的随机性,并有效挖掘Diameter协议流程相关的漏洞。
In order to mine the potential vulnerabilities in Diameter protocol dialog flow of IP Multimedia Subsystem(IMS) abnormal scenarios, this paper proposes a leak mining method of Diameter protocol flow based on the Genetic Algorithra(GA). The method makes a given scenario by mutating network configuration, user state, and servers' state. And generates multi-dimension fuzziness test data for the scenario using GA. This paper makes decisions that whether there are related vulnerabilities by watching the network's response to the test messages. Simulation experimental result shows that the test messages' generating method both ensures the messages' randomness and improves the effectiveness, it can mine the vulnerabilities of Diameter protocol flow effectively.
出处
《计算机工程》
CAS
CSCD
2013年第9期6-11,共6页
Computer Engineering
基金
国家"863"计划基金资助项目(2011AA010605)