Development of a Multi-purpose Fuzzer to Perform Assessment as Input to a Cybersecurity Risk Assessment and Analysis System

06/07/2023
by   Jack Hance, et al.
0

Fuzzing is utilized for testing software and systems for cybersecurity risk via the automated adaptation of inputs. It facilitates the identification of software bugs and misconfigurations that may create vulnerabilities, cause abnormal operations or result in systems' failure. While many fuzzers have been purpose-developed for testing specific systems, this paper proposes a generalized fuzzer that provides a specific capability for testing software and cyber-physical systems which utilize configuration files. While this fuzzer facilitates the detection of system and software defects and vulnerabilities, it also facilitates the determination of the impact of settings on device operations. This later capability facilitates the modeling of the devices in a cybersecurity risk assessment and analysis system. This paper describes and assesses the performance of the proposed fuzzer technology. It also details how the fuzzer operates as part of the broader cybersecurity risk assessment and analysis system.

READ FULL TEXT
research
12/21/2022

A Comparative Risk Analysis on CyberShip System with STPA-Sec, STRIDE and CORAS

The widespread use of software-intensive cyber systems in critical infra...
research
06/22/2020

An In-Depth Security Assessment of Maritime Container Terminal Software Systems

Attacks on software systems occur world-wide on a daily basis targeting ...
research
01/13/2021

Mutation Analysis for Cyber-Physical Systems: Scalable Solutions and Results in the Space Domain

On-board embedded software developed for spaceflight systems (space soft...
research
06/07/2023

Development of a System Vulnerability Analysis Tool for Assessment of Complex Mission Critical Systems

A system vulnerability analysis technique (SVAT) for complex mission cri...
research
04/18/2019

Doping Tests for Cyber-Physical Systems

The software running in embedded or cyber-physical systems (CPS) is typi...
research
01/21/2018

Recent Results on Classifying Risk-Based Testing Approaches

In order to optimize the usage of testing efforts and to assess risks of...

Please sign up or login with your details

Forgot password? Click here to reset