Microcontroller Based IoT System Firmware Security: Case Studies

Microcontroller Based IoT System Firmware Security: Case Studies
复制标题

DOI:
10.1109/icii.2019.00045
复制
发表时间:
2019-11
期刊:
2019 IEEE International Conference on Industrial Internet (ICII)
影响因子:
--
通讯作者:
Chao Gao;Lan Luo;Yue Zhang;Bryan Pearson;Xinwen Fu
Chao Gao;Lan Luo;Yue Zhang;Bryan Pearson;Xinwen Fu
中科院分区:
其他
文献类型:
--
作者:
Chao Gao;Lan Luo;Yue Zhang;Bryan Pearson;Xinwen Fu

文献摘要

被引文献

相似文献

物联网(IoT)最近因其灵活性,方便性和智能性而引起了业界的极大兴趣。然而,安全问题和漏洞利用已成为物联网最大的担忧之一。本文研究了基于微控制器(MCU)的物联网固件的安全性。鉴于MCU及其运行环境的多样性,我们进行案例研究,以利用当代固件升级模型背后的缺陷。具体来说,我们验证了我们对PurpleAir流行的空气质量传感器的攻击。我们还研究了一个原型的安全固件升级系统的ATmega1284P芯片。为了证明实施对策的攻击面,我们讨论了通过我们自己的实践确定的潜在陷阱,因为这些陷阱可能会发生在其他制造商的实施过程中。
The Internet of Things (IoT) has attracted much interest recently from the industry given its flexibility, convenience and smartness. However, security issues and exploits have become amongst the most colossal concerns for IoT. This paper studies the security of Microcontroller (MCU) based IoT firmware. Given the varieties of MCUs and their running environments, we perform case studies to exploit the flaws behind contemporary firmware upgrade models. Specifically, we validate our attacks on a popular air quality sensor from PurpleAir. We also investigate a prototype of a secure firmware upgrade system on an ATmega1284P chip. To demonstrate the attack surface of the implemented countermeasure, we discuss the potential pitfalls identified through our own practice, since these pitfalls may occur during the implementation by other manufacturers.