Vulnerability Detection in IoT Firmware: A Survey

Wei Xie, Yikun Jiang, Yong Tang, Ning Ding, Yuanming Gao

2017 · 44 citations · 16 references

Concepts

TL;DR

IoT devices are increasingly connected, raising security and privacy concerns, and vulnerability detection is essential, yet conventional tools cannot directly analyze IoT firmware. This survey reviews existing vulnerability detection approaches for IoT firmware and proposes a combined fuzzing and static analysis method to uncover authentication bypass flaws. The authors classify prior work into static analysis, symbolic execution, emulator‑based fuzzing, and comprehensive testing, and then apply a hybrid fuzzing–static analysis strategy tailored to MIPS‑based embedded binaries. The hybrid method successfully validated known CVEs and uncovered previously unknown vulnerabilities.

Abstract

With the development of Internet of Things(IoT), more and more smart devices are connected into the Internet. The security and privacy issues of IoT devices have received increasingly academic and industrial attentions. Vulnerability detection is the key technology to protect IoT devices from zero-day attacks. However, traditional methods and tools of vulnerability detection cannot be directly used in analyzing IoT firmware. This paper firstly reviews related works on vulnerability detection in IoT firmware, previous researches are classified into four types i.e. static analysis, symbolic execution, fuzzing on emulators and comprehensive testing. Then, this paper points out that the specificity of vulnerability detection in IoT firmware is to detect logical flaws in embedded binaries which are built on the MIPS architecture. Finally, this paper proposes a method based on fuzzing and static analysis to detect authentication bypass flaws in IoT embedded binary servers. The proposed method is proved to be effective by verifying known CVEs as well as discovering unknown ones.

References

16