Bringing Software Defined Radio to the Penetration Testing Community

Bringing Software Defined Radio to the Penetration Testing Community
复制标题

将软件定义无线电引入渗透测试社区

DOI:
--
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
Jonathan
Jonathan
中科院分区:
--
文献类型:
--
作者:
J. Picod;A. Lebrun;Jonathan

文献摘要

被引文献

相似文献

无线设备的广泛采用比WiFi网络更进一步:智能电表,可穿戴设备等,这些新型设备背后的工程师可能没有深厚的安全背景,当特定技术受到压力时,可能会导致安全和隐私问题。然而,为了评估这些设备的安全性,目前唯一的解决方案是一个专用硬件组件,该组件具有针对每种可用技术的适当无线电接口。这样的组件不容易设计,这就是为什么我们开发了Scapy-radio,一个通用的无线监控器/注入器工具,基于软件定义无线电,使用GNU Radio和著名的Scapy框架。在本文中,我们提出了这个工具,我们开发了广泛的无线安全评估。我们的工具的主要目标是为几乎不了解无线电通信系统的安全审计人员提供有效的渗透测试功能。关键词-渗透测试,软件无线电,智能电网,无线。
The large adoption of wireless devices goes further than WiFi networks: smartmeters, wearable devices, etc. The engineers behind these new types of devices may not have a deep security background and it can lead to security and privacy issues when a particular technology is stressed. However, to assess the security of these devices, the only current solution would be a dedicated hardware component with an appropriate radio interface for each available technology. Such components are not easy to engineer and this is why we developed Scapy-radio, a generic wireless monitor/injector tool based on Software Defined Radio using GNU Radio and the well-known Scapy framework. In this paper, we present this tool we developed for a wide range of wireless security assessments. The main goal of our tool is to provide effective penetration testing capabilities to security auditors with little to no knowledge of radio communication systems. Keywords—Penetration Testing, Software Defined Radio, Smart Grid, Wireless.