首页> 外文会议>International Conference on Smart Card Research and Advanced Applications >Breaking All the Things - A Systematic Survey of Firmware Extraction Techniques for IoT Devices
【24h】

Breaking All the Things - A Systematic Survey of Firmware Extraction Techniques for IoT Devices

机译:打破所有的东西 - 对物联网设备的固件提取技术进行系统调查

获取原文

摘要

In this paper, we systematically review and categorize different hardware-based firmware extraction techniques, using 24 examples of real, wide-spread products, e.g. smart voice assistants (in particular Amazon Echo devices), alarm and access control systems, as well as home automation devices. We show that in over 45% of the cases, an exposed UART interface is sufficient to obtain a firmware dump, while in other cases, more complicated, yet still low-cost methods (e.g. JTAG or eMMC readout) are needed. In this regard, we perform an in-depth investigation of the security concept of the Amazon Echo Plus, which contains significant protection methods against hardware-level attacks. Based on the results of our study, we give recommendations for countermeasures to mitigate the respective methods.
机译:在本文中,我们系统地审查和分类基于硬件的固件提取技术,使用24个真实宽的产品的示例,例如,如此。智能语音助理(特别是亚马逊回波设备),报警和访问控制系统,以及家庭自动化设备。我们显示,在超过45%的情况下,暴露的UART接口足以获得固件转储,而在其他情况下,需要更复杂,但仍然需要低成本的方法(例如JTAG或EMMC读数)。在这方面,我们对Amazon Echo Plus的安全概念进行了深入调查,其中包含针对硬件级攻击的显着保护方法。根据我们的研究结果,我们提出了对对策的建议,以减轻各自的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号