首页> 外文会议>Network Protocols (ICNP), 2008 IEEE International Conference on >A model-based approach to security flaw detection of network protocol implementations
【24h】

A model-based approach to security flaw detection of network protocol implementations

机译:基于模型的网络协议实现安全漏洞检测方法

获取原文

摘要

A lot of efforts have been devoted to the analysis of network protocol specification for reliability and security properties using formal techniques. However, faults can also be introduced during system implementation; it is indispensable to detect protocol implementation flaws, yet due to the black-box nature of protocol implementation and the unavailability of protocol specification most of the approaches resort to random or manual testing. In this paper we propose a model-based approach for security flaw detection of protocol implementation with a high fault coverage, measurability, and automation. Our approach first synthesizes an abstract behavioral model from a protocol implementation and then uses it to guide the testing process for detecting security and reliability flaws. For protocol specification synthesis we reduce the problem a trace minimization with a Finite State Machine model and an efficient algorithm is presented for state space reduction. Our method is implemented and applied to real network protocols. Guided by the synthesized model our testing tool reveals a number of unknown reliability and security issues by automatically crashing the implementations of the Microsoft MSN instant messaging (MSNIM) protocol. Analytical comparison between our model-based and prevalent syntax-based flaw detection schemes is also provided with the support of experimental results.
机译:使用正式技术对网络协议规范进行了分析,致力于分析网络协议规范。但是,在系统实施期间也可以引入故障;检测协议实现缺陷是必不可少的,但由于协议的黑匣子性质以及协议规范的不可用的大多数方法都采取了随机或手动测试。在本文中,我们提出了一种基于模型的安全漏洞检测方法,具有高故障覆盖,可测量和自动化。我们的方法首先从协议实现中综合抽象行为模型,然后使用它来指导检测安全性和可靠性漏洞的测试过程。对于协议规范合成,我们减少了用有限状态机模型的迹线最小化的问题,并且呈现了用于状态空间的有效算法。我们的方法是实现并应用于真正的网络协议。通过合成模型为指导我们的测试工具通过自动崩溃Microsoft MSN Instant Messaging(MSNIM)协议的实现来显示许多未知的可靠性和安全问题。还提供了基于模型和普遍的语法的缺陷检测方案与实验结果的分析比较。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号