Service-Level Traffic Variations using Protocol Fuzzing Service-level traffic variations use protocol mutations (aka Protocol Fuzzing) designed to undermine the reliability and availability of a application, product or service and to
expose underlying weaknesses. The Mu Test Suite generates millions
of service level traffic variations in a wide range of VoIP, IPTV, IMS and other widely-used application protocols. The variations embody a vast amount
of knowledge gleaned through examining fundamental vulnerability patterns
across protocols, by generalizing publicly known vulnerabilities and using our
internal security expertise.
The dynamic protocol fuzzing generated by the Mu Test Suite allow identification of previously unknown
service weaknesses and vulnerabilities in a target application or device. Mu's customers launch
millions of mutations against a network to proactively expose weaknesses and
take action to remediate them before these issues lead to costly downtime.
What are
Service-level Traffic Variations?
Mu offers a comprehensive suite of dynamically-created variations, along with
intelligent automation for isolating application, service or product weaknesses. Typical variations include:
- Correctly
formatted message received in the wrong state
- Semantically
incorrect messages from a broken implementation
- Messages
that structurally malformed
- Packet
flows that are incorrect due to the actions of intermediate devices (dropped,
corrupted, badly fragmented, truncated, reordered, etc.)
The dynamic mutations deliver a set of variations generated based upon an operator's service, application or product configuration as well as the responses from the
service. Vendors select their variations based upon building the highest quality into their products. This allows the variations to be precisely tailored to the service
being analyzed.
Traffic Variation/Mutation
Explorer
The Mu Test Suite also includes an interactive Explorer that lets the
user direct interactions with the live service interface(s) to hone in on
correct settings while receiving precise feedback and information on where
communication failures occurred and exposing all traffic details for both sent
and received traffic. Once correct configuration options are established, the
user can save them as a reusable template or can immediately create an analysis
using those settings.
Related Collateral
|