Published September 16, 2024 | Version v1

Aplicação da Técnica Fuzzing em Testes da Implementação de Referência do SPDM

Description

Automated tests performed during software development are capable of finding flaws early, preventing vulnerabilities ranging from denial of service to privilege escalation. In particular, these automated tests can be performed using the fuzzing technique, which coordinates the sending of unexpected inputs to the software under test. This paper presents preliminary results of spdmfuzzer, a fuzzer developed to test the reference implementation of the Security Protocols and Data Models (SPDM), a protocol that enables hardware and firmware attestation. In its current publicly available version, spdmfuzzer has already been able to find unexpected behaviors in the protocol implementation.

Files

SBSeg24_Thiago.pdf

Files (908.7 kB)

Name Size Download all
md5:5709c6668da3bf41937e12b78af113a6
908.7 kB Preview Download

Additional details

Funding

Fundação de Amparo à Pesquisa do Estado de São Paulo
SMART NEtworks and ServiceS for 2030 (SMARTNESS) 2021/00199-8