When Firmware Modifications Attack: A Case Study of Embedded Exploitation

When Firmware Modifications Attack: A Case Study of Embedded Exploitation
复制标题

DOI:
10.7916/d8p55nkb
复制
发表时间:
2013
期刊:
--
影响因子:
--
通讯作者:
Ang Cui;Michael Costello;S. Stolfo
Ang Cui;Michael Costello;S. Stolfo
中科院分区:
其他
文献类型:
--
作者:
Ang Cui;Michael Costello;S. Stolfo

文献摘要

被引文献

相似文献

更新固件的能力几乎在所有现代嵌入式系统中都可以找到。我们演示了如何利用此功能允许攻击者将恶意固件修改注入易受攻击的嵌入式设备。我们讨论了利用这种易受攻击的功能的技术,以及能够网络侦察,数据泄露和传播到通用计算机和其他嵌入式设备类型的概念验证打印机恶意软件的实现。我们对HP-RFU(远程固件更新)激光打印机固件修改漏洞进行了案例研究,该漏洞允许通过标准打印文档将恶意软件任意注入打印机固件。我们展示了通过对IPv4空间进行详尽扫描而不断跟踪所有可公开访问的打印机所收集的易受攻击人群数据。为了证明固件更新签名并不是嵌入式防御的灵丹妙药,我们对373个LaserJet固件映像中第三方库中发现的已知漏洞进行了分析。先前的研究表明,本文提出的设计缺陷和漏洞在其他现代嵌入式系统中也存在。因此,本文提出的攻击技术可以推广到其他嵌入式系统。关键词:嵌入式系统开发;固件修改攻击;嵌入式系统rootkit;HP-RFU脆弱性。
The ability to update firmware is a feature that is found in nearly all modern embedded systems. We demonstrate how this feature can be exploited to allow attackers to inject malicious firmware modifications into vulnerable embedded devices. We discuss techniques for exploiting such vulnerable functionality and the implementation of a proof of concept printer malware capable of network reconnaissance, data exfiltration and propagation to general purpose computers and other embedded device types. We present a case study of the HP-RFU (Remote Firmware Update) LaserJet printer firmware modification vulnerability, which allows arbitrary injection of malware into the printer’s firmware via standard printed documents. We show vulnerable population data gathered by continuously tracking all publicly accessible printers discovered through an exhaustive scan of IPv4 space. To show that firmware update signing is not the panacea of embedded defense, we present an analysis of known vulnerabilities found in third-party libraries in 373 LaserJet firmware images. Prior research has shown that the design flaws and vulnerabilities presented in this paper are found in other modern embedded systems. Thus, the exploitation techniques presented in this paper can be generalized to compromise other embedded systems. Keywords-Embedded system exploitation; Firmware modification attack; Embedded system rootkit; HP-RFU vulnerability.