首页> 外文OA文献 >FirmUSB: Vetting USB Device Firmware using Domain Informed Symbolic Execution
【2h】

FirmUSB: Vetting USB Device Firmware using Domain Informed Symbolic Execution

机译:FirmUsB:使用域知情符号审核UsB设备固件   执行

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The USB protocol has become ubiquitous, supporting devices from high-poweredcomputing devices to small embedded devices and control systems. USB's greatestfeature, its openness and expandability, is also its weakness, and attacks suchas BadUSB exploit the unconstrained functionality afforded to these devices asa vector for compromise. Fundamentally, it is virtually impossible to knowwhether a USB device is benign or malicious. This work introduces FirmUSB, aUSB-specific firmware analysis framework that uses domain knowledge of the USBprotocol to examine firmware images and determine the activity that they canproduce. Embedded USB devices use microcontrollers that have not been wellstudied by the binary analysis community, and our work demonstrates how liftersinto popular intermediate representations for analysis can be built, as well asthe challenges of doing so. We develop targeting algorithms and use domainknowledge to speed up these processes by a factor of 7 compared tounconstrained fully symbolic execution. We also successfully find maliciousactivity in embedded 8051 firmwares without the use of source code. Finally, weprovide insights into the challenges of symbolic analysis on embeddedarchitectures and provide guidance on improving tools to better handle thisimportant class of devices.
机译:USB协议已无处不在,支持从高性能计算设备到小型嵌入式设备和控制系统的设备。 USB的最大功能,即开放性和可扩展性,也是它的弱点,诸如BadUSB之类的攻击利用了为这些设备提供的不受限制的功能,作为妥协的载体。从根本上讲,几乎不可能知道USB设备是良性还是恶意的。这项工作介绍了FirmUSB,这是一种USB特定的固件分析框架,该框架使用USB协议的领域知识来检查固件映像并确定它们可以产生的活动。嵌入式USB设备使用的二进制分析社区尚未深入研究微控制器,我们的工作证明了如何将提升器构建为流行的用于分析的中间表示形式以及这样做的挑战。与无约束的完全符号执行相比,我们开发了定位算法,并使用领域知识将这些过程加快了7倍。我们还成功地在嵌入式8051固件中发现了恶意活动,而无需使用源代码。最后,我们提供了有关嵌入式体系结构上符号分析挑战的见解,并提供了改进工具的指南,以更好地处理这类重要的设备。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号