No More Companion Apps Hacking but One Dongle: Hub-Based Blackbox Fuzzing of IoT Firmware

No More Companion Apps Hacking but One Dongle: Hub-Based Blackbox Fuzzing of IoT Firmware
复制标题

DOI:
10.1145/3581791.3596857
复制
发表时间:
2023-06
期刊:
Proceedings of the 21st Annual International Conference on Mobile Systems, Applications and Services
影响因子:
--
通讯作者:
Xiaoyue Ma;Qiang Zeng;Haotian Chi;Lannan Luo
Xiaoyue Ma;Qiang Zeng;Haotian Chi;Lannan Luo
中科院分区:
其他
文献类型:
--
作者:
Xiaoyue Ma;Qiang Zeng;Haotian Chi;Lannan Luo

文献摘要

相似文献

考虑到仿真物联网固件的巨大困难,对物联网设备进行黑盒融合以发现漏洞已成为一个有吸引力的选择。然而,现有的黑盒物联网模糊器需要大量时间和繁琐的工作来对每个物联网设备的物联网同伴应用程序进行反向工程(或手动收集测试脚本),这在分析许多设备时是不可扩展的。此外,通过配套应用程序进行模糊处理会受到应用程序内部输入清理的阻碍,并且仅限于手动显示的功能。我们注意到,物联网设备通常能够使用标准无线协议(如ZigBee、Z-Wave和WiFi)连接集线器。因此,我们提出了一个统一的基于集线器的架构,用于模糊化各种物联网设备,而不需要对任何配套应用程序进行反向工程。它利用集线器和物联网设备之间交换的消息来自动发现所有功能,然后启动系统的面向功能的消息语义引导的模糊。它避免了配套应用程序强加的杀毒。此外,它还进行设备状态敏感的模糊处理,我们发现这在查找物联网漏洞方面非常有效。我们实现了一个名为HubFuzzer的系统。评估表明,HubFuzzer的覆盖率比现有技术高得多。我们测试了21个物联网设备,发现了23个零日漏洞。已经分配了四名CVE。
Given the massive difficulty in emulating IoT firmware, blackbox fuzzing of IoT devices for vulnerability discovery has become an attractive option. However, existing blackbox IoT fuzzers need much time and tedious effort to reverse engineer the IoT companion app (or manually collect test scripts) of each IoT device, which is unscalable when analyzing many devices. Moreover, fuzzing through a companion app is impeded by the input sanitization inside the app and limited to the manually revealed functions. We notice that IoT devices are typically able to connect a hub using standard wireless protocols (such as ZigBee, Z-Wave, and WiFi). We thus propose a uniform hub-based architecture for fuzzing various IoT devices, without reverse engineering any companion apps. It exploits the messages exchanged between a hub and an IoT device to automatically discover all the functions, and then launches systematic function-oriented message-semantics-guided fuzzing. It avoids sanitization imposed by a companion app. In addition, it conducts device state-sensitive fuzzing, which we find very effective in finding IoT bugs. We implement the system named HubFuzzer. The evaluation shows that HubFuzzer leads to much higher coverage than prior state of the art. We test 21 IoT devices and find 23 zero-day vulnerabilities. Four CVEs have been assigned.