Diplomová práce
Získaná ocenění: Cena děkana FI za vynikající závěrečnou práci

APDUFuzzer: blackbox recovery of smartcard API

Bc. Peter Benčík
Anotace

Špecifikácia aplikačného programového rozhrania čipových kariet často nie je pre nezávislých výskumníkov k dispozícii. Tí sa potom musia spoliehať na vlastné bádanie v oblasti reverzného inžinierstva. Táto práca sa zaoberá možnosťou použitia inštrumentovaného fuzzing testovania na zjednodušenie tohto procesu. Demonštrujeme uskutočniteľnosť tohto návrhu jednoduchou implementáciou používajúcou nástroj …více

Abstract

Specification of API for smart card applets is often not available for independent researches, who must, therefore, rely on their own reverse engineering efforts. In this work, we explore the possibility to use guided fuzzing combined with power consumption analysis to make this task more efficient. We provide a proof-of-concept implementation of this idea using AFL fuzzer and PicoScope digital oscilloscope …více

Zadání práce
The goal of the work is to survey the options for recovery of unknown application programming interface (API) of black box implementation running on a smartcard. The practical part will design and implement analysis setup using a combination of instruction bruteforcing, generic instrumentation-based fuzzer (AFL) and code execution characteristics obtainable from smartcard probing (response time, response data, error code) including usage of power analysis via digital oscilloscope (power profile of the code executed during input command processing). The goal is to recover the supported commands (INS and other related values from APDU header) as well as and the format of APDU data payload.
The efficiency of the designed setup shall be verified on a testing JavaCard applet with a known interface (e.g., OpenPGP applet) and 1-2 smartcards with an unknown interface.
The thesis will cover the following topics:
  • Survey of existing research articles on black-box API discovery methods with a focus on the area of smartcards.
  • Extension of APDUFuzzer project with AFL fuzzer combined with power trace analysis recorded by digital oscilloscope.
  • Analysis of fuzzing performance to discover the expected apdu payload using an applet(s) with a known interface as ground truth (e.g., OpenPGP or SimpleAPDU).
  • Application of fuzzing setup on 1-2 cards with an unknown interface with results interpretation.
  • A suggestion of techniques to cluster the same or very similar fuzzing "hits" together and how to extract apdu payload structure based on the hits obtained.
  • Suggestions for further optimization of the fuzzing setup.
The resulting implementation shall provide quality and well-documented open-source code and repeatable measurement setup construction.

Literature:
APDUFuzzer project: https://github.com/petrs/pyAPDUFuzzer
Smart Card Handbook, W. Rankl, W. Effing, ISBN-10: 0470743670, Wille, 2010
american fuzzy lop (AFL) http://lcamtuf.coredump.cx/afl/
Picoscope https://www.picotech.com/products/oscilloscope

Práce zkontrolována:
23. 5. 2019 13:18, doc. RNDr. Petr Švenda, Ph.D., učo 4085
Jazyk práce
angličtina angličtina
Termín obhajoby
18. 6. 2019
Práce byla úspěšně obhájena

Vedoucí

doc. RNDr. Petr Švenda, Ph.D., učo 4085
KPSK FI MU

Oponent

RNDr. Dušan Klinec, Ph.D., učo 325219
abs FI MU

Masarykova univerzita Fakulta informatiky
Studijní program
Informatika
  • Přidání souboru

    Soubor nebo složku lze nahrát pomocí tlačítka Přidat.
  • Další operace se soubory

    Podrobnosti lze zjistit označením příslušného řádku.
  • Pohled pro experty

    Pro častou práci je možné zvolit režim Více možností.
  • Vyhledávání souborů

    Vyhledávaný výraz můžete zadat přímo do adresního řádku.
  • Rychlý přístup k souborům

    Pomocí funkce Nedávné je možné se rychle vrátit k právě prohlíženým souborům. Oblíbené soubory je také možné označit Hvězdičkou.