2017 · 44 citations · 16 references
EngineeringIot FirmwareInformation SecurityIot SecuritySoftware AnalysisVulnerability Assessment (Computing)Firmware DetectionInternet Of Things SecurityInternet Of ThingsFuzzingStatic AnalysisComputer EngineeringSecurity Testing MethodData SecurityProgram AnalysisSoftware TestingVulnerability DetectionSecurityFirmware SecurityIot Forensics
IoT devices are increasingly connected, raising security and privacy concerns, and vulnerability detection is essential, yet conventional tools cannot directly analyze IoT firmware. This survey reviews existing vulnerability detection approaches for IoT firmware and proposes a combined fuzzing and static analysis method to uncover authentication bypass flaws. The authors classify prior work into static analysis, symbolic execution, emulator‑based fuzzing, and comprehensive testing, and then apply a hybrid fuzzing–static analysis strategy tailored to MIPS‑based embedded binaries. The hybrid method successfully validated known CVEs and uncovered previously unknown vulnerabilities.
With the development of Internet of Things(IoT), more and more smart devices are connected into the Internet. The security and privacy issues of IoT devices have received increasingly academic and industrial attentions. Vulnerability detection is the key technology to protect IoT devices from zero-day attacks. However, traditional methods and tools of vulnerability detection cannot be directly used in analyzing IoT firmware. This paper firstly reviews related works on vulnerability detection in IoT firmware, previous researches are classified into four types i.e. static analysis, symbolic execution, fuzzing on emulators and comprehensive testing. Then, this paper points out that the specificity of vulnerability detection in IoT firmware is to detect logical flaws in embedded binaries which are built on the MIPS architecture. Finally, this paper proposes a method based on fuzzing and static analysis to detect authentication bypass flaws in IoT embedded binary servers. The proposed method is proved to be effective by verifying known CVEs as well as discovering unknown ones.
16
SOK: (State of) The Art of War: Offensive Techniques in Binary Analysis
Yan Shoshitaishvili, Ruoyu Wang, Christopher Salls et al. · 2016 · 883 citations · Full text
Towards Automated Dynamic Analysis for Linux-based Embedded Firmware
Daming D. Chen, Manuel Egele, Maverick Woo et al. · 2016 · 346 citations · Full text
A Large-Scale Analysis of the Security of Embedded Firmwares
Andrei Costin, Jonas Zaddach, Aurélien Francillon et al. · 2014 · 311 citations
Avatar: A Framework to Support Dynamic Security Analysis of Embedded Systems’ Firmwares
Jonas Zaddach, Luca Bruno, Aurélien Francillon et al. · 2014 · 307 citations