Device-agnostic Firmware Execution is Possible: A Concolic Execution Approach for Peripheral Emulation

Device-agnostic Firmware Execution is Possible: A Concolic Execution Approach for Peripheral Emulation
复制标题

DOI:
10.1145/3427228.3427280
复制
发表时间:
2020-12
期刊:
Proceedings of the 36th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Chen Cao;Le Guan;Jiang Ming;Peng Liu
Chen Cao;Le Guan;Jiang Ming;Peng Liu
中科院分区:
其他
文献类型:
--
作者:
Chen Cao;Le Guan;Jiang Ming;Peng Liu

文献摘要

被引文献

相似文献

随着物联网设备的迅速普及,我们的网络空间如今被数十亿个低成本计算节点所主导,这些节点彼此之间非常异构。动态分析是发现软件错误的最有效方法之一,由于缺乏能够运行各种以前看不见的固件的通用模拟器,动态分析已经瘫痪。近年来,我们目睹了针对低端基于微处理器的物联网设备的毁灭性安全漏洞。这些安全问题严重阻碍了物联网技术的进一步发展。在这项工作中,我们提出了Laelaps,一个专门设计用于运行微控制器设备的各种软件的设备仿真器。我们不会将任何关于设备的特定信息编码到模拟器中。相反,Laelaps通过符号执行辅助外设仿真推断固件的预期行为,并生成适当的输入以实时引导具体执行。这种独特的设计功能使Laelaps能够运行不同的固件,而不需要关于目标设备的先验知识。为了演示Laelaps的功能,我们在仿真器上应用了动态分析技术。我们成功地识别了自我注入和现实世界的漏洞。
With the rapid proliferation of IoT devices, our cyberspace is nowadays dominated by billions of low-cost computing nodes, which are very heterogeneous to each other. Dynamic analysis, one of the most effective approaches to finding software bugs, has become paralyzed due to the lack of a generic emulator capable of running diverse previously-unseen firmware. In recent years, we have witnessed devastating security breaches targeting low-end microcontroller-based IoT devices. These security concerns have significantly hamstrung further evolution of the IoT technology. In this work, we present Laelaps, a device emulator specifically designed to run diverse software of microcontroller devices. We do not encode into our emulator any specific information about a device. Instead, Laelaps infers the expected behavior of firmware via symbolic-execution-assisted peripheral emulation and generates proper inputs to steer concrete execution on the fly. This unique design feature makes Laelaps capable of running diverse firmware with no a priori knowledge about the target device. To demonstrate the capabilities of Laelaps, we applied dynamic analysis techniques on top of our emulator. We successfully identified both self-injected and real-world vulnerabilities.