Vulnerability Detection Framework of Industrial Control Equipment Based on Improved Fuzzing

XIANG Shuang,ZHAO Bo,JI Xiangmin,ZHANG Huanguo
DOI: https://doi.org/10.14188/j.1671-8836.2013.05.014
2013-01-01
Abstract:Vulnerability detection is an effective way to solve security problem of current industrial control system.By analyzing the difficulties of vulnerability detection in the existing industrial control platform,this paper proposes an improved fuzzing framework that introduces the concept of confidence to quantify the test cases as a classifier input,and thus pre-screens potential test cases,so as to reduce input space and enhance hit rate.Based on this architecture design for industrial control systems,the generic framework for vulnerability mining combines with malformed data structure,test target monitoring,and test results management,and supports multi-target,multi-protocol,multiplatform extensions.Finally,experimental results on an industrial controller have shown the feasibility and effectiveness of the method.
What problem does this paper attempt to address?