SoK: Enabling Security Analyses of Embedded Systems via Rehosting

SoK: Enabling Security Analyses of Embedded Systems via Rehosting
复制标题

DOI:
10.1145/3433210.3453093
复制
发表时间:
2021-05
期刊:
Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Andrew Fasano;Tiemoko Ballo;Marius Muench;T. Leek;Alexander Bulekov;Brendan Dolan-Gavitt;Manuel Egele-Manue
Andrew Fasano;Tiemoko Ballo;Marius Muench;T. Leek;Alexander Bulekov;Brendan Dolan-Gavitt;Manuel Egele-Manue
中科院分区:
其他
文献类型:
--
作者:
Andrew Fasano;Tiemoko Ballo;Marius Muench;T. Leek;Alexander Bulekov;Brendan Dolan-Gavitt;Manuel Egele-Manue

文献摘要

相似文献

密切监视软件系统在执行过程中的行为,使开发人员和分析人员能够观察并最终理解它是如何工作的。这种动态分析有助于逆向工程、漏洞发现、利用开发和调试。虽然这些分析通常在同构桌面平台(例如,x86桌面pc)中得到很好的支持,但它们很少应用于嵌入式系统的异构世界。实现嵌入式系统动态分析的一种方法是将软件栈从物理系统移到能够充分模拟硬件行为的虚拟环境中。这个我们称之为“重新托管”的过程对安全分析提出了重大的研究挑战。虽然重新安置传统上是一项不科学的、由领域专家在不同的时间和资源下进行的临时努力,但研究人员开始系统地、认真地解决重新安置的挑战。在本文中,我们确定仿真不足以对现实世界的硬件系统进行大规模动态分析,并将重新托管作为以固件为中心的替代方案。此外,我们对初步的重寄存工作进行了分类,确定了重寄存过程的基本组成部分,并提出了未来的研究方向。
Closely monitoring the behavior of a software system during its execution enables developers and analysts to observe, and ultimately understand, how it works. This kind of dynamic analysis can be instrumental to reverse engineering, vulnerability discovery, exploit development, and debugging. While these analyses are typically well-supported for homogeneous desktop platforms (e.g., x86 desktop PCs), they can rarely be applied in the heterogeneous world of embedded systems. One approach to enable dynamic analyses of embedded systems is to move software stacks from physical systems into virtual environments that sufficiently model hardware behavior. This process which we call "rehosting" poses a significant research challenge with major implications for security analyses. Although rehosting has traditionally been an unscientific and ad-hoc endeavor undertaken by domain experts with varying time and resources at their disposal, researchers are beginning to address rehosting challenges systematically and in earnest. In this paper, we establish that emulation is insufficient to conduct large-scale dynamic analysis of real-world hardware systems and present rehosting as a firmware-centric alternative. Furthermore, we taxonomize preliminary rehosting efforts, identify the fundamental components of the rehosting process, and propose directions for future research.