Backbone Protocol Fuzzing

No ratings

Presented at ShmooCon 2007 by

While bugs continue to be found in backbone gear on a fairly regular basis, there has been little attention given to protocol fuzzing research on routing and switching infrastructure gear. Given that so many backbone bugs are Denial-of-Service related, this seems a strange omission. Basic errors such as "router catches wrong protocol version number, chokes, dies" are still being found and reported -- these type of errors should be quickly found by an intelligent fuzzer. This talk will present the author's operational framework implementation for backbone protocol fuzzing, discuss successes and failures in developing a workable fuzzing model, and address kinds of gear yet to be tested as well as further research in this direction. All code used and presented will be open source and available with the presentation.