A novel vulnerability analysis approach to generate fuzzing test case in industrial control systems

Sung-Jin Kim, Wooyeon Jo, Taeshik Shon · 2016 IEEE Information Technology, Networking, Electronic and Automation Control Conference · 2016

A smart grid is nationwide industrial control system that combine IT and traditional electric system. The main hindrance to smart grid is security. To solve this problem we propose a novel approach for vulnerability analysis of smart grid protocols using fuzzing test. The fuzzing test is widely used for vulnerability analysis, however, these studies do not consider the cross-protocol test and are not suitable to smart grid network. Therefore, we propose a novel test case generation method for fuzzing test. Before creating test cases, we classify the protocol fields into three categories by its characteristics. Based on the classification, we can easily create test case based on the categories without considering each fields. So, it helps to generate cross-field and cross-layer test case. To verify our approach, we examine the common used protocol library using the test case generated by proposed method and successfully find unknown abnormality.

Read the paper · More papers on PaperTik