Skip to main content

Security Assessment for Application Network Services Using Fault Injection

  • Conference paper
Intelligence and Security Informatics (PAISI 2007)

Part of the book series: Lecture Notes in Computer Science ((LNISA,volume 4430))

Included in the following conference series:

Abstract

Vulnerabilities in network protocol software have been problematic since Internet infrastructure was deployed. These vulnerabilities damage the reliability of network software and create security holes in computing environment. Many critical security vulnerabilities exist in application network services of which specification or description has not been published. In this paper, we propose a security assessment methodology based on fault injection techniques to improve reliability of the application network services with no specifications published. We also implement a tool for security testing based on the proposed methodology. Windows RPC network services are chosen as an application network service considering its unknown protocol specification and are validated by the methodology. It turns out that the tool detects unknown vulnerabilities in Windows network module.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 39.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. Microsoft Security Bulletin MS03-026. Microsoft (2003), http://www.microsoft.com/technet/security/bulletin/MS03-026.mspx

  2. Microsoft Security Bulletin MS04-011. Microsoft (2004), http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

  3. Voas, J.M., McGraw, G.: Software Fault Injection: Innoculating Programs Against Errors. Wiley, Chichester (1997)

    Google Scholar 

  4. Fabre, J.C., et al.: Building dependable COTS microkernel-based systems using MAFALDA. In: Pacific Rim International Symposium on Dependable Computing (PRDC’00), pp. 85–92 (2000)

    Google Scholar 

  5. Miller, B.P., Fredriksen, L., So, B.: An Empirical Study of the Reliability of UNIX Utilities. Communications of the ACM 33(12), 32–44 (1990)

    Article  Google Scholar 

  6. Koopman, P., et al.: Comparing operating systems using robustness benchmarks. In: 16th IEEE Symposium on Reliable Distributed Systems, October 1997, pp. 72–79 (1997)

    Google Scholar 

  7. Kropp, N.P., Koopman, P.J., Siewiorek, D.P.: Automated Robustness Testing of Off-the-Shelf Software Components. In: 28th International Symposium on Fault- Tolerant Computing, pp. 464–468 (1998)

    Google Scholar 

  8. Forrester, J.E., Miller, B.P.: An empirical study of the robustness of windows NT applications using random testing, http://www.cs.wisc.edu/_bart/fuzz/fuzz.html

  9. Aitel, D.: The advantages of block-based protocol analysis for security testing (2002), http://www.immunitysec.com/resources-papers.shtml

  10. SPIKE Development Homepage, http://www.immunitysec/spike.html

    Google Scholar 

  11. PROTOS: Security Testing of Protocol Implementation, http://www.ee.oulu.fi/research/ouspg/protos

  12. Handley, M., et al.: SIP: Session Initiation Protocol. RFC 2543

    Google Scholar 

  13. MSDN, http://msdn.microsoft.com/

  14. Leighton, L.K.C.: DCE/RPC over SMB: Samba and Windows NT Domain Internals. Macmillan Technical Publishing, Basingstoke (Dec. 1999)

    Google Scholar 

  15. Ethereal, http://www.ethereal.com/

  16. WinDBG, http://www.microsoft.com/whdc/devtools/debugging/default.mspx

Download references

Author information

Authors and Affiliations

Authors

Editor information

Christopher C. Yang Daniel Zeng Michael Chau Kuiyu Chang Qing Yang Xueqi Cheng Jue Wang Fei-Yue Wang Hsinchun Chen

Rights and permissions

Reprints and permissions

Copyright information

© 2007 Springer Berlin Heidelberg

About this paper

Cite this paper

Kang, H., Lee, D.H. (2007). Security Assessment for Application Network Services Using Fault Injection. In: Yang, C.C., et al. Intelligence and Security Informatics. PAISI 2007. Lecture Notes in Computer Science, vol 4430. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-540-71549-8_15

Download citation

  • DOI: https://doi.org/10.1007/978-3-540-71549-8_15

  • Publisher Name: Springer, Berlin, Heidelberg

  • Print ISBN: 978-3-540-71548-1

  • Online ISBN: 978-3-540-71549-8

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics