Identifying Channel Related Vulnerabilities in Zephyr Firmware
Identifying Channel Related Vulnerabilities in Zephyr Firmware
复制标题
DOI:
10.1109/ithings-greencom-cpscom-smartdata-cybermatics55523.2022.00055
复制
发表时间:
2022-08
期刊:
影响因子:
--
通讯作者:
Devansh Rajgarhia;Peng Liu;S. Sural
中科院分区:
文献类型:
--
作者:
Devansh Rajgarhia;Peng Liu;S. Sural
In recent years, IoT devices and systems have helped make our lifestyle smarter. Operating systems running on IoT devices form a critical component for connectivity, security, networking, storage, remote device management and other system needs. As a result, applications deployed on top of such an operating system can exploit its vulnerabilities and potentially leak confidential data to the attacker. IoT devices typically have sensors that allow them to measure one or more channel values. They constitute one such example of confidential data for the user which can get leaked or manipulated by a malicious application exploiting the privileges provided by the operating system. In this work, we propose a methodology for finding security vulnerabilities using the concept of taint analysis on the LLVM IR of a part of the kernel of the Zephyr OS, a lightweight real-time operating system for connected, resource-constrained and embedded devices. Several vulnerabilities were detected as reported in the Results section.