Download BSI TR-ESOR-C.1 Conformity Test Specification (Level 1

Transcript
BSI TR-ESOR-C.1: Functional Conformity Test Specification
4.1.5
A-05 – Protection of communication channel and interface is robust against DoS-attacks
Identifier
A-05
Requirement
AS:A6.1-4
Test Purpose
The test shall verify that any unauthorised access to authentication or payload data during communication is reliably prevented and that the interface is
implemented in such a way that denial of service (DoS) or consequential errors, such as buffer overflow or SQL injections are not possible.
Configuration
CONFIG_Common
Pre-test conditions
If required, perform identification and authentication.
Step
Test sequence
Expected Results
1.
Start logging the data traffic between the TOT and
another component.
The data logging process has been started.
2.
Establish a valid and mutually authenticated connection
between the two components and place a request from
source to target module (TOT).
A valid connection is established and a valid answer from the TOT
is received.
3.
Close the connection of the two components.
The complete data exchange between the components has been
intercepted and logged.
4.
Check if the logged traffic data reveals any authorisation
or payload data.
No authorisation or payload data is revealed.
5.
Automatically send a large amount of small requests to
The availability is not affected in a negative way. The TOT
the TOT interface in a short period of time and check if
responses to all the requests or identify the DoS targets and block
its availability is affected (DoS). Use several client
them.
applications on several computers in parallel in order to
completely fill the network bandwidth of at least 10 Mbit
provided to the TOT.
6.
Establish a valid connection between the components
- The sent data is properly processed and checked for plausibility.
and place requests to the TOT with large amounts of data - Invalid data is rejected
to provoke buffer overflows.
- No buffer overflow will occur
7.
Establish a valid connection between the components
and place requests to the TOT with included database
command sequences.
Observations
- The sent data is properly processed and checked for plausibility.
- Invalid data is rejected
- The included database commands are not executed
Verdict
Federal Office for Information Security
29