Open Access Open Access  Restricted Access Subscription Access

低功耗藍芽協定安全模糊測試框架

Sheng-Xiang Lin,
Hsin-Hung Cho,
Chi-Yuan Chen,
Yu-Chieh Li,

Abstract


低功耗藍芽(Bluetooth Low Energy,BLE)由於其省電的特性,許多行動裝置及穿戴裝置皆支援低功耗藍芽通訊技術,加上近年物聯網相關應用的普及,越來越多個人資料透過低功耗藍芽通訊協定來進行傳輸,然而針對各種藍芽技術的攻擊手法層出不窮,如何檢測低功耗藍芽裝置的安全性成為急需克服的挑戰。本研究採用軟體測試中常見的黑箱測試方法-模糊測試(Fuzz Testing),提出一低功耗藍芽協定安全模糊測試框架,並且採用開源的軟硬體資源實作測試帄台,進一步分析進行低功耗藍芽協定測試所遭遇的困難與解決方案。

Due to the power saving feature of Bluetooth Low Energy (BLE), many mobile devices and wearable devices support BLE communication technology. In recent years, the popularity of IoT related applications, more and more personal data transferred through the BLE protocol. However, there are various attack techniques for Bluetooth technologies. How to test the security of BLE devices has become an urgent challenge to overcome. In this paper, we utilized the black box test method, Fuzz Testing, which is common in software testing. This paper presents a Security Fuzz Testing Framework for BLE Protocols and uses open source hardware/software resources to implement the testing platform. We also analyze the difficulties and solutions encountered in the testing of BLE protocols.


Citation Format:
Sheng-Xiang Lin, Hsin-Hung Cho, Chi-Yuan Chen, Yu-Chieh Li, "低功耗藍芽協定安全模糊測試框架," Communications of the CCISA, vol. 25, no. 1 , pp. 28-38, Feb. 2019.

Full Text:

PDF

Refbacks

  • There are currently no refbacks.





Published by Chinese Cryptology and Information Security Association (CCISA), Taiwan, R.O.C
CCCISA Editorial Office, No.1, Sec. 1, Shennong Rd., Yilan City, Yilan County 260, Taiwan (R.O.C.)
E-mail: ccisa.editor@gmail.com