首页> 外文会议>IEEE International Conference on Power, Intelligent Computing and Systems >Research on Large-scale Firmware Function Security Detection Method Based on SimHash
【24h】

Research on Large-scale Firmware Function Security Detection Method Based on SimHash

机译:基于SimHash的大型固件功能安全检测方法研究

获取原文

摘要

The rapid development of the Internet of Things technology has made more and more physical devices connected to the Internet. Extensive code reuse and the use of third-party SDK libraries have resulted in a large number of homologous binary files in the firmware, making the correlation between device firmware stronger and stronger. Due to the huge amount of data, there is no fast search technology that enables analysts to compare and use the similarity of the required firmware function information efficiently. Therefore, how to obtain the information resources needed by analysts from massive data in a short time and build an index structure with small spatial complexity has become an urgent problem in the field of security detection. In response to the above problems, we propose a large-scale firmware function security detection method research technology based on SimHash. By analyzing and extracting representative firmware function features, we design and implement a SimHash-based firmware function database, which is used to match the similarity of massive firmware functions, quickly locate suspicious fragile firmware functions, and realize large-scale security detection of device firmware. In order to prove the effectiveness of our method, experiments are carried out on the real device firmware function library, and a similarity analysis of tens of millions of firmware function data can be completed in 5 seconds.
机译:事物互联网技术的快速发展技术使得越来越多的物理设备连接到互联网。广泛的代码重用和第三方SDK库的使用导致固件中的大量同源二进制文件,使设备固件更强更强大之间的相关性。由于数据量大,没有快速搜索技术,使分析师能够有效地比较和使用所需固件功能信息的相似性。因此,如何在短时间内从大规模数据获取分析师所需的信息资源,并在短时间内构建具有小的空间复杂性的索引结构已经成为安全检测领域的紧急问题。为了响应上述问题,我们提出了基于Simhash的大规模固件功能安全检测方法研究技术。通过分析和提取代表性固件功能功能,我们设计和实现基于SimHash的固件功能数据库,用于匹配大规模固件功能的相似性,快速定位可疑易碎固件功能,并实现了设备固件的大规模安全检测。为了证明我们方法的有效性,实验在真实的设备固件功能库上进行,并且可以在5秒内完成数百万个固件功能数据的相似性分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号