polito.it
Politecnico di Torino (logo)

OCPPStorm: A Comprehensive Fuzzing Tool for OCPP Implementations

Gaetano Coppoletta

OCPPStorm: A Comprehensive Fuzzing Tool for OCPP Implementations.

Rel. Cataldo Basile. Politecnico di Torino, Corso di laurea magistrale in Ingegneria Informatica (Computer Engineering), 2023

[img]
Preview
PDF (Tesi_di_laurea) - Tesi
Licenza: Creative Commons Attribution Non-commercial No Derivatives.

Download (1MB) | Preview
Abstract:

The modern world of digital communication hinges on the reliability and security of its underlying protocols. Among these, the Open Charge Point Protocol (OCPP) stands out as a cornerstone for electric vehicle charging stations. However, ensuring its robustness requires systematic testing against potential vulnerabilities. Enter OCPPStorm, a sophisticated fuzzer tailored for the OCPP protocol. This research presents a comprehensive dive into OCPPStorm and its triad of fuzzing techniques. First, the Random Fuzzer serves as a foundational mechanism, autonomously selecting OCPP message types, fuzzing, and subsequently dispatching them to a central system for response analysis. The State Machine Fuzzer takes a more structured approach, permitting users to input correct sequences of OCPP messages that emulate a "state machine". This empowers users to define and fuzz common OCPP message sequences, bridging the gap between theoretical testing and real-world communication patterns. Lastly, the Isla Fuzzer, a result of integrating the Isla Message Generator with OCPPStorm, employs the Isla library coupled with meticulously crafted grammars and constraints. Together, these techniques fortify OCPPStorm's ability to identify bugs and security issues in OCPP implementations, shining a light on vulnerabilities while offering avenues for enhancements. In its entirety, this thesis underscores the critical importance of exhaustive protocol testing and sets the benchmark for future endeavors in the realm of OCPP security.

Relators: Cataldo Basile
Academic year: 2023/24
Publication type: Electronic
Number of Pages: 99
Subjects:
Corso di laurea: Corso di laurea magistrale in Ingegneria Informatica (Computer Engineering)
Classe di laurea: New organization > Master science > LM-32 - COMPUTER SYSTEMS ENGINEERING
Ente in cotutela: UNIVERSITY OF ILLINOIS AT CHICAGO (STATI UNITI D'AMERICA)
Aziende collaboratrici: UNSPECIFIED
URI: http://webthesis.biblio.polito.it/id/eprint/29600
Modify record (reserved for operators) Modify record (reserved for operators)