Loading [a11y]/accessibility-menu.js
A Fuzzing Method for Embedded Bus Based on Dynamic Mutation of Message Sequences | IEEE Conference Publication | IEEE Xplore

A Fuzzing Method for Embedded Bus Based on Dynamic Mutation of Message Sequences


Abstract:

As an important support for the communication link of embedded systems, the bus protocol faces many security threats while meeting diverse business needs, and how to ensu...Show More

Abstract:

As an important support for the communication link of embedded systems, the bus protocol faces many security threats while meeting diverse business needs, and how to ensure the security of the bus link of embedded systems has become an important security issue. In order to meet the requirements of generalized security detection of embedded system bus protocols, this paper proposes a fuzzing method for embedded bus protocol based on dynamic mutation of message sequences. Based on the bus protocol specification, we model the protocol message and interaction process, and realize the fuzzing test of the protocol process in combination with the association of messages in the message sequence. At the same time, we combined the fuzzer with a timer to increase the time perception of the method. In order to verify the effectiveness of our method, this paper applies the proposed method to the CAN bus fuzzing of the Internet of Vehicles simulation platform, and successfully finds a security flaw in the process of motor speed data frame processing of the platform. Moreover, we carry out a comparative experiment with several common fuzzing tools, and the experimental results show that in the defect detection of the CAN bus of the Internet of Vehicles simulation platform, our method can increase the automatic mutation support for the interval_time field, and can discover more security defects.
Date of Conference: 01-05 July 2024
Date Added to IEEE Xplore: 29 October 2024
ISBN Information:

ISSN Information:

Conference Location: Cambridge, United Kingdom

Contact IEEE to Subscribe

References

References is not available for this document.