首页> 外文会议>IEEE International Conference on Software Engineering and Service Science >FIRMNANO: Toward IoT Firmware Fuzzing Through Augmented Virtual Execution
【24h】

FIRMNANO: Toward IoT Firmware Fuzzing Through Augmented Virtual Execution

机译:FIRMNANO:通过增强的虚拟执行实现物联网固件模糊

获取原文

摘要

Considering that the deployment of IoT devices is becoming more and more widespread, the security analysis of the firmware of these devices is extremely important. However, a large number of devices now have vulnerabilities that can be exploited, allowing attackers to remotely control IoT devices. In this article, we show FIRMNANO, a fuzzing framework for the firmware of IoT devices with microcontrollers as the core. Based on augmented virtual execution, FIRMNANO solves three key problems of microcontrollers firmware emulation: (1) MMIO region access (2) interrupt triggering (3) DMA support. On this basis, it conducts code coverage-based fuzzing testing for firmware. Our evaluation results show that FIRMNANO can execute firmware correctly and can be used for real-world firmware vulnerability mining.
机译:考虑到物联网设备的部署越来越广泛,对这些设备的固件进行安全性分析非常重要。但是,大量设备现在具有可以利用的漏洞,从而使攻击者可以远程控制IoT设备。在本文中,我们展示了FIRMNANO,这是一个以微控制器为核心的物联网设备固件的模糊框架。基于增强的虚拟执行,FIRMNANO解决了微控制器固件仿真的三个关键问题:(1)MMIO区域访问(2)中断触发(3)DMA支持。在此基础上,它将对固件进行基于代码覆盖率的模糊测试。我们的评估结果表明,FIRMNANO可以正确执行固件,并且可以用于实际的固件漏洞挖掘。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号