首页> 外国专利> APPARATUS AND METHOD FOR DETECTING FIRMWARE VULNERABILIRY BASED ON HYBRID FUZZING

APPARATUS AND METHOD FOR DETECTING FIRMWARE VULNERABILIRY BASED ON HYBRID FUZZING

机译:基于混合模糊检测固件漏洞的装置和方法

摘要

A hybrid fuzzing-based firmware vulnerability detection apparatus and method are disclosed. According to an embodiment, a hybrid fuzzing-based firmware vulnerability detection device includes: a system mode emulator that provides a system mode emulation environment to firmware of any Internet of Things (IoT) device; a user mode emulator that provides a user mode emulation environment to a target process among one or more processes of the firmware running in the system mode emulation environment; a first testing unit that performs mutation-based fuzzing on the target process in the user mode emulation environment; and a second testing unit that, when a preset event occurs during the execution of the fuzzing, performs an operation for resolving the event generated based on the state of the target process at the time of occurrence of the event in the system mode emulation environment However, when the predetermined event occurs, the first testing unit stops the execution of the fuzzing and resumes the execution of the fuzzing based on the result of the operation to detect the vulnerability of the firmware.
机译:公开了一种混合模糊的固件漏洞检测装置和方法。根据一个实施例,基于混合模糊的固件漏洞检测装置包括:系统模式仿真器,为系统模式仿真环境提供给任何内容(物联网)设备的固件;用户模式仿真器,为用户模式仿真环境提供给系统模式仿真环境中的固件的一个或多个进程之间的目标过程;在用户模式仿真环境中对目标过程执行基于突变的模糊的第一测试单元;和第二测试单元,当在执行模糊期间发生预设事件时,执行用于在系统模式仿真环境中发生事件时基于目标过程的状态来解析生成的事件的操作当发生预定事件时,第一测试单元停止执行模糊,并基于操作的结果来恢复模糊的执行,以检测固件的漏洞。

著录项

  • 公开/公告号KR102304861B1

    专利类型

  • 公开/公告日2021-09-23

    原文格式PDF

  • 申请/专利权人 세종대학교산학협력단;

    申请/专利号KR20210040963

  • 发明设计人 윤주범;김현욱;김주환;

    申请日2021-03-30

  • 分类号G06F11/36;G06F9/455;

  • 国家 KR

  • 入库时间 2022-08-24 21:13:50

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号