Download BSI TR-ESOR-C.1 Conformity Test Specification (Level 1
Transcript
BSI TR-ESOR-C.1: Functional Conformity Test Specification 4.1.5 A-05 – Protection of communication channel and interface is robust against DoS-attacks Identifier A-05 Requirement AS:A6.1-4 Test Purpose The test shall verify that any unauthorised access to authentication or payload data during communication is reliably prevented and that the interface is implemented in such a way that denial of service (DoS) or consequential errors, such as buffer overflow or SQL injections are not possible. Configuration CONFIG_Common Pre-test conditions If required, perform identification and authentication. Step Test sequence Expected Results 1. Start logging the data traffic between the TOT and another component. The data logging process has been started. 2. Establish a valid and mutually authenticated connection between the two components and place a request from source to target module (TOT). A valid connection is established and a valid answer from the TOT is received. 3. Close the connection of the two components. The complete data exchange between the components has been intercepted and logged. 4. Check if the logged traffic data reveals any authorisation or payload data. No authorisation or payload data is revealed. 5. Automatically send a large amount of small requests to The availability is not affected in a negative way. The TOT the TOT interface in a short period of time and check if responses to all the requests or identify the DoS targets and block its availability is affected (DoS). Use several client them. applications on several computers in parallel in order to completely fill the network bandwidth of at least 10 Mbit provided to the TOT. 6. Establish a valid connection between the components - The sent data is properly processed and checked for plausibility. and place requests to the TOT with large amounts of data - Invalid data is rejected to provoke buffer overflows. - No buffer overflow will occur 7. Establish a valid connection between the components and place requests to the TOT with included database command sequences. Observations - The sent data is properly processed and checked for plausibility. - Invalid data is rejected - The included database commands are not executed Verdict Federal Office for Information Security 29