Test Generation and Fuzz Testing Design

dc.contributorAalto-yliopistofi
dc.contributorAalto Universityen
dc.contributor.advisorTóth, Attila
dc.contributor.authorJuhász, Norbert
dc.contributor.schoolPerustieteiden korkeakoulufi
dc.contributor.supervisorNurminen, Jukka
dc.date.accessioned2015-09-18T08:32:11Z
dc.date.available2015-09-18T08:32:11Z
dc.date.issued2015
dc.description.abstractGlobal System for Mobile Communications (GSM) network is one of the most vulnerable systems and it is a popular target for hackers. Its core communication protocol is based on legacy protocol stack Signaling System No. 7 (SS7), which shows more and more known vulnerabilities. However, securing these issues is quite a complex task. The paper focuses on the SS7 protocol family, especially on the Mobile Application Protocol (MAP), which handles sensitive information about the mobile subscribers’ location and enabled services. Fuzzers are tools that are frequently used by hackers to locate security holes in software, and their popularity has grown among the security testers as well. In my thesis I compared various fuzzers and conducted fuzz testing on a Home Location Register in order to locate vulnerabilities in the communication interface. I configured a generational fuzzer called Sulley to test the Update Location operation of the MAP and analyze its behavior during the process. My results showed that including malicious data in the IMSI, MSC-number and VLR-number parameters did not cause any complication. However, initiating plenty, incomplete transaction in a short time can produce system failure.en
dc.format.extent60
dc.identifier.urihttps://aaltodoc.aalto.fi/handle/123456789/17720
dc.identifier.urnURN:NBN:fi:aalto-201509184335
dc.language.isoenen
dc.programmeMaster's Programme in ICT Innovationfi
dc.programme.majorService Design and Engineeringfi
dc.programme.mcodeSCI3022fi
dc.rights.accesslevelclosedAccess
dc.subject.keywordfuzzingen
dc.subject.keywordsecurity testingen
dc.subject.keywordSS7en
dc.subject.keywordMAP protocolen
dc.titleTest Generation and Fuzz Testing Designen
dc.typeG2 Pro gradu, diplomityöen
dc.type.okmG2 Pro gradu, diplomityö
dc.type.ontasotMaster's thesisen
dc.type.ontasotDiplomityöfi
dc.type.publicationmasterThesis
local.aalto.idinssi52054
local.aalto.openaccessno

Files