DocumentCode :
3674022
Title :
A Modbus/TCP Fuzzer for testing internetworked industrial systems
Author :
Artemios G. Voyiatzis;Konstantinos Katsigiannis;Stavros Koubias
Author_Institution :
SBA Research, Vienna, Austria
fYear :
2015
Firstpage :
1
Lastpage :
6
Abstract :
Modbus/TCP is a network protocol for industrial communications encapsulated in TCP/IP network packets. There is an increasing need to test existing Modbus protocol implementations for security vulnerabilities, as devices become accessible even from the Internet. Fuzz testing can be used to discover implementation bugs in a fast and economical way. We present the design and implementation of MTF, a Modbus/TCP Fuzzer. The MTF incorporates a reconnaissance phase in the testing procedure so as to assist mapping the capabilities of the tested device and to adjust the attack vectors towards a more guided and informed testing rather than plain random testing. The MTF was used to test eight implementations of the Modbus protocol and revealed bugs and vulnerabilities that crash the execution, effectively resulting in denial of service attacks using only a few network packets.
Keywords :
"Protocols","Testing","Software","Reconnaissance","Sockets","Computer crime","Computer crashes"
Publisher :
ieee
Conference_Titel :
Emerging Technologies & Factory Automation (ETFA), 2015 IEEE 20th Conference on
Type :
conf
DOI :
10.1109/ETFA.2015.7301400
Filename :
7301400
Link To Document :
بازگشت