Microcontroller Based IoT System Firmware Security: Case Studies
Microcontroller Based IoT System Firmware Security: Case Studies
复制标题
DOI:
10.1109/icii.2019.00045
复制
发表时间:
2019-11
期刊:
影响因子:
--
通讯作者:
Chao Gao;Lan Luo;Yue Zhang;Bryan Pearson;Xinwen Fu
中科院分区:
文献类型:
--
作者:
Chao Gao;Lan Luo;Yue Zhang;Bryan Pearson;Xinwen Fu
The Internet of Things (IoT) has attracted much interest recently from the industry given its flexibility, convenience and smartness. However, security issues and exploits have become amongst the most colossal concerns for IoT. This paper studies the security of Microcontroller (MCU) based IoT firmware. Given the varieties of MCUs and their running environments, we perform case studies to exploit the flaws behind contemporary firmware upgrade models. Specifically, we validate our attacks on a popular air quality sensor from PurpleAir. We also investigate a prototype of a secure firmware upgrade system on an ATmega1284P chip. To demonstrate the attack surface of the implemented countermeasure, we discuss the potential pitfalls identified through our own practice, since these pitfalls may occur during the implementation by other manufacturers.