| SNMP Vulnerability Test Suite |
|
The SilverCreek Vulnerability Test Suite tests the robustness of an SNMP agent in the face of a Denial-of-Service attack. These attacks can disable computer systems and networks and ultimately the operation of your organization. Denial-of-service attacks come in a variety of forms and aim at a variety of services. Attackers exploit vulnerabilities in SNMP agents in order to disrupt network connectivity by preventing network devices with SNMP agents from operating. Click here to read the Network Computing article:"InterWorking Labs Protects Your Enterprise From SNMP Vulnerabilities" Some DoS attacks focus on finding vulnerabilities in the encapsulation of SNMP packets. If the agent has any weaknesses at all in the algorithms it uses to decode an SNMP packet, then it is likely to crash, hang, reboot, or exhibit other undesirable behavior. SNMP packets are encapsulated according to ASN.1 which describes the grammar, and BER which describes the translation mechanism, for SNMP packets. The SilverCreek SNMP Vulnerability Test Suite introduces abnormalities into the grammar and the encapsulation of the SNMP packet to make it malformed. The parameters that can be changed for encapsulation are type, length, and payload. By changing the tag (what ASN.1 type is it?), length (how long is the payload?), and value (the payload) to wrong or unexpected values, a normal, valid packet becomes a pathological packet. Key Features:
The SilverCreek Vulnerability Test Suite addresses the issues cited in the CERT Advisories concerning SNMP. The Test Suite has more than 700,000 test cases arranged in approximately 450 test groups. Each group focuses on a specific concept:
Here are a few examples of the test
types: (1) Test Scope and Methodology
For SNMPv1 vulnerabilities:
For SNMPv2c vulnerabilities:
For SNMPv3 vulnerabilities: As a side note, it is a good idea, for more extensive testing to use: * the v3 and v2c vulnerability tests
against a v1 agent In this way, you can determine that the agent behaves properly by discarding the test packets that are not appropriate for the version of the agent. Reports from the field confirm that even after vendor patches were installed, the SilverCreek SNMP Vulnerability Test Suite found additional vulnerabilities on many network devices. This means those devices were still vulnerable to new network attacks. It is important to be pro-active and take all measures to secure a network. TSNMP Vulnerability Test Suite, is an essential tool in the arsenal of network security protection solutions. In summary, the SilverCreek Vulnerability Test Suite tests the robustness of an SNMP agent in the face of a Denial-of-Service attack. Some DoS attacks focus on finding vulnerabilities in the encapsulation of SNMP packets. If the agent has any weaknesses at all in the algorithms it uses to decode an SNMP packet, then it is likely to crash, hang, reboot, or exhibit other undesirable behavior. SNMP packets are encapsulated according to ASN.1 which describes the grammar, and BER which describes the translation mechanism, for SNMP packets. |