Defensics Fuzz Testing
Defensics Fuzz Testing
Defensics is a powerful testing platform that enables developers and asset owners to
®
KEY FEATURES
Supported Protocols
(Not All Protocols Listed)
(MEF-16) H.248 NFS v4.0 / v4.1 SNMPv3
BACNET H.264 NHRP SOCKS
BFD H.264 RTP NTP SSH1
BFD H.323 OAM (802.3ah) SSH2
BGP4+ HTTP OCSP STP
The Stakes are Higher: Today, organizations depend on technology to process DVMRPv3
E-LMI
LDAPv3
LDP
S1AP
SCEP
WebSocket
Wi-Fi AP
sensitive information and perform essential functions. Unknown vulnerabilities in EAPoL/802.1x
ESTP
LLDP (802.1AB)
MAP
SCTP
SIP
Wi-Fi AP WPA
Wi-Fi Client
business-critical software and devices pose a significant threat because they cannot Ethernet MIME SIP-I Wi-Fi Client WPA
FCoE + FIP ModBus SMBv2 WMV
be addressed by traditional forms of security such as firewalls, IDP/IPS, etc. FIX MP4 SMBv3 WPA Enterprise
FTP MPLS SMPP SMS X.509v3
GARP 802.1D MQTT SMS PDU/File XML File
exponentially as you move further down the development lifecycle and supply chain. GTPv1
GTPv2-control
NetBIOS
NFS v2/v3
SNMP Trap
SNMPv2c
© 2016
2015 Synopsys
DEFENSICS® DATASHEET
• Advanced test suites available for 290+ network protocols, file formats, and other Remote Access: EAPOL Server, PPPoE, Diameter Server, Diameter
Client, LDAPv3 Server, TACACS+ Server, TACACS+ NAS, RADIUS
interfaces. Test suites are continuously added, improved, and supported by a (Server, Client), Kerberos Server
dedicated team of test developers. VPN: IPsec, SSH1 Server, SSH2 Server, TLS/SSL, TLS 1.2, ISAKMP/
IKEv1 (Client, Server), IKEv2, OCSP (Client, Server), L2TPv2, X.509
• Thorough documentation and reporting features allow Defensics to identify the root
VoIP/IMS: SCTP, H.248, H.323, RTSP (Client, Server), TLS/SSL, TLS
cause of critical failures in such a way that they are repeatable, easy to understand, 1.2, SIP UAS, SIP UAC, SigComp, RTP/RTCP/SRTP, MGCP, UPnP
and can be shared with the stakeholders involved in the remediation process. Server, X.509, BICC, SIP TT
WiFi: AP Test Suite, AP WPA Test Suite, Client Test Suite, Client WPA
The technology at the core of Defensics is fuzz testing. This is an automated Test Suite
methodology that tests for unknown vulnerabilities by systematically sending invalid or Link Management: LACP, STP, MSTP, RSTP, ESTP
the same time). A Metro Ethernet: BFD, CFM, E-LMI, Ethernet, GARP, LLDP, OAM,
PBT/PBB-TE, L2TP
security researcher at General Purpose: XML SOAP, Traffic Capture Fuzzer, Universal
Codenomicon (now Fuzzer
Finance: FIX
Synopsys) had been
Web Applications: FIX, JSON, OAuth, SOCKS Client, SOCKS Server,
running a routine test of the Defensics feature, SafeGuard, when he identified a flaw in Traffic Capture Fuzzer, Universal Fuzzer, Web Applications Fuzzer,
Web Sockets, XML file format, XML SOAP Server, XML SOAP Client
OpenSSL. It had gone unidentified for over two years. Ultimately Heartbleed impacted
Web: HTTP, XML, Web Applications, Digital Media, Universal Fuzzer
over 500,000 websites.
Automotive: Bluetooth, WiFi, Digital Media, SMS, General purpose
fuzzers
© 2016 Synopsys, Inc. All rights reserved. The registered trademarks of Synopsys used herein are registered in the U.S. and other countries. All other
company and product names are the property of their respective owners.