Aplicação da Técnica Fuzzing em Testes da Implementação de Referência do SPDM
Authors/Creators
Description
Automated tests performed during software development are capable of finding flaws early, preventing vulnerabilities ranging from denial of service to privilege escalation. In particular, these automated tests can be performed using the fuzzing technique, which coordinates the sending of unexpected inputs to the software under test. This paper presents preliminary results of spdmfuzzer, a fuzzer developed to test the reference implementation of the Security Protocols and Data Models (SPDM), a protocol that enables hardware and firmware attestation. In its current publicly available version, spdmfuzzer has already been able to find unexpected behaviors in the protocol implementation.
Files
SBSeg24_Thiago.pdf
Files
(908.7 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:5709c6668da3bf41937e12b78af113a6
|
908.7 kB | Preview Download |
Additional details
Funding
- Fundação de Amparo à Pesquisa do Estado de São Paulo
- SMART NEtworks and ServiceS for 2030 (SMARTNESS) 2021/00199-8