skip to main content
10.1145/3058060.3058070acmotherconferencesArticle/Chapter ViewAbstractPublication PagesiccspConference Proceedingsconference-collections
research-article

Development of Intelligent Digital Certificate Fuzzer Tool

Authors Info & Claims
Published:17 March 2017Publication History

ABSTRACT

Present day software testing demands effective ways to find software vulnerabilities through testing. This is especially true in case of network security that employ digital certificates for authentication. Digital certificates are the de-facto standard for verification of users and an integral part of public key infrastructure used to secure channels of communication within networks. An effective approach to testing digital certificates is to implement protocol based fuzzing. Fuzzing in general terms is the process of inserting high volume of invalid or random inputs into a program with the aim of obtaining unexpected results, thus identifying errors and potential vulnerabilities. This paper aims to introduce a protocol aware, user friendly graphical user interface (GUI) based digital certificate fuzzing tool. The tool aims to provide an effective means of black box testing through the use of mutation based fuzzing and OpenSSL to create digital certificates with user provided test-case specific fields. The fuzzed certificates are used as inputs in order to expose defects in digital certificate validation systems.

References

  1. Sutton, M., Greene, A., and Amini, P. Fuzzing: Brute Force Vulnerability Discovery, Addison--Wesley Professional, United States, 2007. Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. Schwartz, E.J., Avgerinos, T., and Brumley, D. "All you ever wanted to know about dynamic taint analysis and forward symbolic execution", In IEEE Symposium on Security and Privacy, IEEE Computer Society, 2010, pp. 317--331. Google ScholarGoogle ScholarDigital LibraryDigital Library
  3. RFC 5280- Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) ProfileGoogle ScholarGoogle Scholar
  4. RFC 5246- Transport Layer Security Protocol Version 1.2Google ScholarGoogle Scholar
  5. Citrix NetScaler- https://www.citrix.com/content/dam/citrix/en_us/documents/products-solutions/citrix-netscaler-application-delivery-controller-at-a-glance.pdf as accessed in June 2016.Google ScholarGoogle Scholar
  6. Fuzzing: The State of the Art by Richard McNally, Ken Yiu, Duncan Grove and Damien Gerhardy - Command, Control, Communications and Intelligence Division of Defence Science and Technology Organization of Australia, DSTO-TN-1043.Google ScholarGoogle Scholar
  7. A Comparative Study of White Box, Black Box and Grey Box Testing Techniques(IJACSA) International Journal of Advanced Computer Science and Applications, Vol. 3, No.6, 2012.Google ScholarGoogle Scholar
  8. Miller, C., and Peterson, Z. N.J. Whitepaper on "Analysis of mutation and generation based fuzzing", Independent Security Evaluators March 2007.Google ScholarGoogle Scholar
  9. Revolutionizing the field of grey-box attack surface testing with evolutionary fuzzing, by Jared DeMott, Dr. Richard Enbody, Dr. William Punch, Black Hat, DEF CON 2007.Google ScholarGoogle Scholar
  10. Finding Software Vulnerabilities by Smart Fuzzing, by Sofia Bekrar,Chaouki Bekrar, Roland Groz, Laurent Mounier,2011 Fourth IEEE International Conference on Software Testing, Verification and Validation. Google ScholarGoogle ScholarDigital LibraryDigital Library
  11. Protocol Fuzzing past present and future by Luiz Eduardo Hack in the box 2007.Google ScholarGoogle Scholar
  12. "Minimum Edit Distance" by Dan Jurafsky, Stanford University Natural Language Processing.Google ScholarGoogle Scholar

Recommendations

Comments

Login options

Check if you have access through your login credentials or your institution to get full access on this article.

Sign in
  • Published in

    cover image ACM Other conferences
    ICCSP '17: Proceedings of the 2017 International Conference on Cryptography, Security and Privacy
    March 2017
    153 pages
    ISBN:9781450348676
    DOI:10.1145/3058060

    Copyright © 2017 ACM

    Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

    Publisher

    Association for Computing Machinery

    New York, NY, United States

    Publication History

    • Published: 17 March 2017

    Permissions

    Request permissions about this article.

    Request Permissions

    Check for updates

    Qualifiers

    • research-article
    • Research
    • Refereed limited

PDF Format

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader