FirmXRay: Detecting Bluetooth Link Layer Vulnerabilities From Bare-Metal Firmware

FirmXRay: Detecting Bluetooth Link Layer Vulnerabilities From Bare-Metal Firmware
复制标题

DOI:
10.1145/3372297.3423344
复制
发表时间:
2020-10
期刊:
Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Haohuang Wen;Zhiqiang Lin;Yinqian Zhang
Haohuang Wen;Zhiqiang Lin;Yinqian Zhang
中科院分区:
其他
文献类型:
--
作者:
Haohuang Wen;Zhiqiang Lin;Yinqian Zhang

文献摘要

被引文献

相似文献

如今,蓝牙4.0,也被称为蓝牙低功耗(BLE),已被广泛用于许多物联网设备(例如,智能锁、智能传感器和可穿戴设备)。然而,BLE设备在广播、配对和消息传输期间可能在BLE链路层包含许多漏洞。为了直接从裸金属固件中检测这些漏洞,我们提出了FirmXRay,第一个静态二进制分析工具,它具有一组使能技术,包括用于强大固件反汇编的新型基址识别算法,精确的数据结构识别和配置值解析。作为概念验证,我们专注于来自两个领先SoC供应商的BLE固件(即,Nordic和Texas Instruments),并在Ghidra上实现FirmXRay原型。我们使用基于移动的应用程序的方法收集了793个独特的固件(对应于538个独特的设备)来评估FirmXRay,我们的实验结果显示,98.1%的设备配置了随机静态MAC地址,71.5%的Just Works配对,以及98.5%的不安全密钥交换。利用这些漏洞,我们展示了对现实世界BLE设备的身份跟踪,欺骗和窃听攻击。
Today, Bluetooth 4.0, also known as Bluetooth Low Energy (BLE), has been widely used in many IoT devices (e.g., smart locks, smart sensors, and wearables). However, BLE devices could contain a number of vulnerabilities at the BLE link layer during broadcasting, pairing, and message transmission. To detect these vulnerabilities directly from the bare-metal firmware, we present FirmXRay, the first static binary analysis tool with a set of enabling techniques including a novel base address identification algorithm for robust firmware disassembling, precise data structure recognition, and configuration value resolution. As a proof-of-concept, we focus on the BLE firmware from two leading SoC vendors (i.e., Nordic and Texas Instruments), and implement a prototype of FirmXRay atop Ghidra. We have evaluated FirmXRay with 793 unique firmware (corresponding to 538 unique devices) collected using a mobile app based approach, and our experiment results show that 98.1% of the devices have configured random static MAC addresses, 71.5% Just Works pairing, and 98.5% insecure key exchanges. With these vulnerabilities, we demonstrate identity tracking, spoofing, and eavesdropping attacks on real-world BLE devices.