透過您的圖書館登入
IP:3.144.27.148
  • 期刊

低功耗藍芽協定安全模糊測試框架

Security Fuzz Testing Framework for Bluetooth Low Energy Protocols

摘要


低功耗藍芽(Bluetooth Low Energy,BLE)由於其省電的特性,許多行動裝置及穿戴裝置皆支援低功耗藍芽通訊技術,加上近年物聯網相關應用的普及,越來越多個人資料透過低功耗藍芽通訊協定來進行傳輸,然而針對各種藍芽技術的攻擊手法層出不窮,如何檢測低功耗藍芽裝置的安全性成為急需克服的挑戰。本研究採用軟體測試中常見的黑箱測試方法-模糊測試(Fuzz Testing),提出一低功耗藍芽協定安全模糊測試框架,並且採用開源的軟硬體資源實作測試平台,進一步分析進行低功耗藍芽協定測試所遭遇的困難與解決方案。

並列摘要


Due to the power saving feature of Bluetooth Low Energy (BLE), many mobile devices and wearable devices support BLE communication technology. In recent years, the popularity of IoT related applications, more and more personal data transferred through the BLE protocol. However, there are various attack techniques for Bluetooth technologies. How to test the security of BLE devices has become an urgent challenge to overcome. In this paper, we utilized the black box test method, Fuzz Testing, which is common in software testing. This paper presents a Security Fuzz Testing Framework for BLE Protocols and uses open source hardware/software resources to implement the testing platform. We also analyze the difficulties and solutions encountered in the testing of BLE protocols.

參考文獻


“Bluetooth Core Version 4.0 specification,” 2010.
H. Robin, “Bluetooth Low Energy: The Developer's Handbook,” Prentice Hall, 2012.
L. Matteo, R. Setola, and J. Lopez, “Cybersecurity of wearable devices: an experimental analysis and a vulnerability assessment method,” Annual Computer Software and Applications Conference (COMPSAC), 2017.
Sławomir Jasek, “Gattacking Bluetooth smart devices”, BlackHat USA, 2016.
https://github.com/noble/bleno

延伸閱讀