Feedback-based Greybox Fuzzing of EtherCAT Industrial Protocol
Iskander Zulkarneev, Vladimir Nestor · 2021 Ural Symposium on Biomedical Engineering, Radioelectronics and Information Technology (USBEREIT) · 2021
Industrial protocols are used to control medical destrinuted and virtual systems, to control refining and other processes in critical infrastructure. Such infrastacture must be protected and any vulnurabilities must be found and fixed. The fuzzing of industrial control protocols is the most efficient way to discover their most common vulnerabilities. We have chosen the widely used EtherCAT industrial protocol for fuzzing. Its structure has been analyzed and specificity for testing purpose has been determined. We have chosen fields that may effect the tested program. This fields have helped us to create initial test-cases by modifying them. In this paper, we have proposed to use feedback-based greybox fuzzing due to its high efficiency. The virtual stand has been designed and realized by authors to emulate EtherCAT Master using opensource library SOEM. A coverage guided fuzzer AFL has been adapted by authors for EtherCAT protocol testings. Three different experiments have been conducted. The modification within experiments differs to gain maximum efficiency from the used fuzzer. The data obtained as a result of the selected fuzzing method has been processed in order to determine the reasons for the program's crash and interpret them. In conclusion, the future work for EtherCAT fuzzing are proposed.