Greenhouse: Single-Service Rehosting of Linux-Based Firmware Binaries in User-Space Emulation

Greenhouse: Single-Service Rehosting of Linux-Based Firmware Binaries in User-Space Emulation
复制标题

DOI:
--
复制
发表时间:
2023
期刊:
--
影响因子:
--
通讯作者:
Hui Jun Tay;Kyle Zeng;J. Vadayath;A. S. Raj;A. Dutcher;T. Reddy;Wil Gibbs;Zion Leonahenahe Basque;Fangzhou Dong;Zack Smith;Adam Doupé;Tiffany Bao;Yan Shoshitaishvili;Ruoyu Wang
Hui Jun Tay;Kyle Zeng;J. Vadayath;A. S. Raj;A. Dutcher;T. Reddy;Wil Gibbs;Zion Leonahenahe Basque;Fangzhou Dong;Zack Smith;Adam Doupé;Tiffany Bao;Yan Shoshitaishvili;Ruoyu Wang
中科院分区:
其他
文献类型:
--
作者:
Hui Jun Tay;Kyle Zeng;J. Vadayath;A. S. Raj;A. Dutcher;T. Reddy;Wil Gibbs;Zion Leonahenahe Basque;Fangzhou Dong;Zack Smith;Adam Doupé;Tiffany Bao;Yan Shoshitaishvili;Ruoyu Wang

文献摘要

相似文献

随着物联网设备变得越来越普遍,扩展当前的分析技术以匹配变得越来越重要。这一挑战的一部分不仅涉及在模拟环境中重新托管这些嵌入式设备的固件,而且还涉及这样做并发现真正的漏洞。当前最先进的重新托管方法必须考虑模拟设备和物理设备之间的差异,因此通常侧重于提高模拟保真度。然而,这种对保真度的追求忽略了其他潜在的解决方案。在本文中,我们提出了一种新颖的重新托管技术,即用户空间单服务重新托管,它模拟用户空间中的单个固件服务。我们研究了数百个固件样本中涉及的重新托管过程,以归纳出一系列阻碍仿真的障碍,并制定干预措施来解决这些障碍。我们的原型 Greenhouse 自动重新托管了来自 9 个不同供应商的 7,140 个固件映像中的 2,841 个(39.7%)。我们的方法回避了以前的重新托管技术遇到的许多挑战,并使我们能够将常见的漏洞发现技术应用于重新托管的图像,例如用户空间覆盖引导的模糊测试。使用这些技术,我们在重新托管的固件服务的子集中发现了 717 个 N 天漏洞和 26 个零日漏洞。
As IoT devices grow more widespread, scaling current analysis techniques to match becomes an increasingly critical task. Part of this challenge involves not only rehosting the firmware of these embedded devices in an emulated environment, but to do so and discover real vulnerabilities. Current state-of-the-art approaches for rehosting must account for the discrepancies between emulated and physical devices, and thus generally focus on improving the emulation fidelity . However, this pursuit of fidelity ignores other potential solutions. In this paper, we propose a novel rehosting technique, user-space single-service rehosting , which emulates a single firmware service in user space. We study the rehosting process involved in hundreds of firmware samples to generalize a set of roadblocks that prevent emulation and create interventions to resolve them. Our prototype Greenhouse automatically rehosts 2,841 (39.7%) of our collected 7,140 firmware images from nine different vendors. Our approach sidesteps many of the challenges encountered by previous rehosting techniques and enables us to apply common vulnerability discovery techniques to our rehosted images such as user-space coverage-guided fuzzing. Using these techniques, we find 717 N-day vulnerabilities and 26 zero-day vulnerabilities on a subset of our rehosted firmware services.