首页> 外文会议>IFIP WG 11.9 International Conference on Digital Forensics >AUTOMATED VULNERABILITY DETECTION IN EMBEDDED DEVICES
【24h】

AUTOMATED VULNERABILITY DETECTION IN EMBEDDED DEVICES

机译:嵌入式设备中的漏洞自动检测

获取原文

摘要

Embedded devices are widely used today and are rapidly being incorporated in the Internet of Things that will permeate every aspect of society. However, embedded devices have vulnerabilities such as buffer overflows, command injections and backdoors that are often undocumented. Malicious entities who discover these vulnerabilities could exploit them to gain control of embedded devices and conduct a variety of criminal activities. Due to the large number of embedded devices, non-standard code-bases and complex control flows, it is extremely difficult to discover vulnerabilities using manual techniques. Current automated vulnerability detection tools typically use static analysis, but the detection accuracy is not high. Some tools employ code execution; however, this approach is inefficient, detects limited types of vulnerabilities and is restricted to specific architectures. Other tools use symbolic execution, but the level of automation is not high and the types of vulnerabilities they uncover are limited. This chapter evaluates several advanced vulnerability detection techniques used by current tools, especially those involving automated program analysis. These techniques are leveraged in a new automated vulnerability detection methodology for embedded devices.
机译:嵌入式设备在当今得到了广泛的使用,并且正在迅速融入到将渗透到社会各个方面的物联网中。但是,嵌入式设备具有许多漏洞,例如缓冲区溢出,命令注入和后门程序,这些漏洞通常是未记录的。发现这些漏洞的恶意实体可以利用它们来控制嵌入式设备并进行各种犯罪活动。由于嵌入式设备数量众多,非标准代码库和复杂的控制流程,使用手动技术发现漏洞非常困难。当前的自动化漏洞检测工具通常使用静态分析,但是检测精度不高。一些工具使用代码执行;但是,这种方法效率低下,检测到的漏洞类型有限,并且仅限于特定的体系结构。其他工具使用符号执行,但是自动化程度不高,并且发现的漏洞类型也受到限制。本章评估了当前工具使用的几种高级漏洞检测技术,尤其是那些涉及自动程序分析的技术。这些技术在嵌入式设备的新型自动漏洞检测方法中得到了利用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号