期刊文献+

基于协议分析与模糊测试的SIP漏洞挖掘研究 被引量:5

Research on Vulnerability Discovery for SIP Based on Protocol Analysis and Fuzz Test
下载PDF
导出
摘要 针对会话初始协议(SIP)可能存在的安全漏洞以及对SIP漏洞挖掘研究工作不足的问题,基于协议分析与模糊测试,提出一种SIP协议漏洞挖掘方案。该方案在分析SIP协议语法、格式和会话流程的基础上,对可能出现漏洞的SIP消息生成对应的畸形数据包作为模糊测试的测试用例,并在会话建立的过程中随机发送畸形数据触发测试目标,在监视到SIP客户端发生异常时记录异常信息,并分析导致异常的错误是否能被利用。实验结果表明,该方案能更全面地挖掘出由协议分析结果和模糊测试发现的SIP漏洞,提高挖掘数量和效率。 Aiming at the potential security vulnerabilities of Session Initiation Protocol(SIP) and the lack of research work for exploiting SIP vulnerabilities, an exploiting solution of SIP vulnerabilities is proposed based on protocol analysis and fuzz test. On the basis of analyzing SIP protocol grammar, format and session interaction process, this method generates abnormal SIP data packets as the test case of fuzz test for the SIP messages with potential vulnerabilities,sends abnormal data randomly to trigger the test object in the process of building conversation, records abnormal information when monitoring the exception of SIP clients, and analyzes whether the exception information can be utilized. Experimental results show that this scheme can exploit more SIP vulnerabilities based on protocol analysis results and fuzz test, improving mining quantity and efficiency.
出处 《计算机工程》 CAS CSCD 北大核心 2016年第8期117-122,共6页 Computer Engineering
基金 国家自然科学基金资助项目"分组密码代数旁路攻击技术研究"(61173191)
关键词 会话初始协议 协议分析 漏洞挖掘 模糊测试 测试用例 Session Initiation Protocol(SIP) protocol analysis vulnerability discovery fuzz test test case
  • 相关文献

参考文献8

二级参考文献54

  • 1司端锋,潘爱民.IP电话(VoIP)中的安全性问题[J].计算机工程,2004,30(18):105-107. 被引量:25
  • 2徐明,陈纯,应晶.一个两层马尔可夫链异常入侵检测模型(英文)[J].软件学报,2005,16(2):276-285. 被引量:7
  • 3王乐春,朱培栋,龚正虎.基于RFSM的健壮性测试技术研究[J].通信学报,2005,26(9):21-29. 被引量:2
  • 4Boris Beizer. Black-Box Testing [M]. New York: Wiley,1995.
  • 5IEEE Std. IEEE Std610. 12-1990 IEEE Standard Glossary of Software Engineering Terminology[S]. IEEE Computer Soc. , 1990.
  • 6Miller B P,Koski D, Lee C P, et al. Fuzz Re-visited: A Reexamination of the Reliability of Unix Utilities and Services [R]. Carnegie-Mellon University,1995.
  • 7DeVale J, Koopman P, Guttendorf D. The Ballista Software Robustness Testing Service [C]///Proc of the 16th Int'l Conf on Testing Computer Software, 1999.
  • 8Kropp N P,Koopman Jr P J,Siewiorek D P. Automated Robustness Testing of Off-the Shelf Software Components[C]//Proc of the 28th Fault Tolerant Computing Symp, 1998 : 230-239.
  • 9Saad-Khorchef F, Roller A, Castanet R. A Framework and a Tool for Robustness Testing of Communicating Software[C]//Proc of SAC'07, 2007 : 1461-1466.
  • 10Lai R. A Survey of Communication Protocol Testing[J]. Journal of Systems and Software, 2002,62 (1) :21-46.

共引文献27

同被引文献33

引证文献5

二级引证文献6

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部