Security Analysis of Industrial Control Network Protocols Based on Peach

YI Shengwei,ZHANG Chongbin,XIE Feng,XIONG Qi,XIANG Chong,LIANG Lulu
DOI: https://doi.org/10.16511/j.cnki.qhdxxb.2017.21.010
2017-01-01
Abstract:Fuzzing tests are important for discovery of unknown vulnerabilities and risks. A security analysis method was developed for industrial control networks using the Peach fuzzing framework. The system uses the mutation strategy by fabricating abnormal network packets, sending these packets to the target and then executing tests. The tests monitor the status of the industrial control network protocols. The system then identifies exceptions in the industrial control network protocols. Modbus TCP, a widely used industrial control network protocol is analyzed as an example using a fuzzy Modbus TCP protocol. The results show that this method can effectively identify vulnerabilities in industrial control network protocols.
What problem does this paper attempt to address?