...
首页> 外文期刊>International Journal of Distributed Sensor Networks >A Novel Fuzzing Method for Zigbee Based on Finite State Machine
【24h】

A Novel Fuzzing Method for Zigbee Based on Finite State Machine

机译:基于有限状态机的Zigbee模糊测试新方法

获取原文
           

摘要

With the extensive application of Zigbee, some bodies of literature were devoted into finding the vulnerabilities of Zigbee by fuzzing. According to earlier test records, the majority of defects were exposed due to a series of testing cases. However, the context of malformed inputs is not taken account into the previous algorithms. In this paper, we propose a refined structure-based fuzzing algorithm for Zigbee based on FSM, FSM-fuzzing. Any malformed input in FSM-Fuzzing is injected to the tested sensor against a specific initial state. If the sensor transferred to the next state of FMS or crashed, there would be a defect of Zigbee in dealing with the input under the state. The final state of the sensor is verified by an UIO sequence. After a round of tests, the sensor is regressed to the specific state to prepars for receiving the next mutation. All of the states would be traversed in FSM-fuzzing. A fuzzing tool, ZFSM-fuzzer, is designed for evaluating the performance of FSM-fuzzing. Experiment results show that there is a vulnerability of Zigbee in dealing with the frames without destination addresses. Further, the quality of cases of FSM-fuzzing is higher than the previous algorithms. Therefore, FSM-fuzzing is powerful in finding the vulnerabilities of Zigbee.
机译:随着Zigbee的广泛应用,一些文献致力于通过模糊来发现Zigbee的漏洞。根据较早的测试记录,大多数缺陷是由于一系列测试案例而暴露出来的。但是,先前的算法未考虑格式错误的输入的上下文。在本文中,我们提出了一种基于FSM的精巧的基于结构的Zigbee模糊测试算法。 FSM-Fuzzing中任何格式错误的输入都会针对特定的初始状态注入经过测试的传感器。如果传感器转移到FMS的下一个状态或崩溃,则Zigbee在处理该状态下的输入时将存在缺陷。传感器的最终状态由UIO序列验证。经过一轮测试后,传感器将退回到特定状态以准备接收下一个突变。在FSM模糊测试中将遍历所有状态。一种模糊测试工具ZFSM-fuzzer用于评估FSM模糊测试的性能。实验结果表明,Zigbee在处理没有目标地址的帧时存在漏洞。此外,FSM模糊情况的质量比以前的算法更高。因此,FSM模糊检测在发现Zigbee的漏洞方面功能强大。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号