Identifying Channel Related Vulnerabilities in Zephyr Firmware

Identifying Channel Related Vulnerabilities in Zephyr Firmware
复制标题

DOI:
10.1109/ithings-greencom-cpscom-smartdata-cybermatics55523.2022.00055
复制
发表时间:
2022-08
期刊:
2022 IEEE International Conferences on Internet of Things (iThings) and IEEE Green Computing & Communications (GreenCom) and IEEE Cyber, Physical & Social Computing (CPSCom) and IEEE Smart Data (SmartData) and IEEE Congress on Cybermatics (Cybermatics)
影响因子:
--
通讯作者:
Devansh Rajgarhia;Peng Liu;S. Sural
Devansh Rajgarhia;Peng Liu;S. Sural
中科院分区:
其他
文献类型:
--
作者:
Devansh Rajgarhia;Peng Liu;S. Sural

文献摘要

相似文献

近年来,物联网设备和系统帮助我们的生活方式变得更加智能。运行在物联网设备上的操作系统构成了连接、安全、网络、存储、远程设备管理和其他系统需求的关键组件。因此,部署在此类操作系统之上的应用程序可以利用其漏洞,并可能将机密数据泄露给攻击者。物联网设备通常具有传感器,允许它们测量一个或多个通道值。它们构成了用户的机密数据的一个这样的例子,可以被利用操作系统提供的特权的恶意应用程序泄露或操纵。在这项工作中,我们提出了一种使用污点分析的概念来发现安全漏洞的方法,该方法对Zephr OS的部分内核的LLVM IR进行污点分析。ZePhyr OS是一个用于连接、资源受限和嵌入式设备的轻量级实时操作系统。如结果部分所述,检测到几个漏洞。
In recent years, IoT devices and systems have helped make our lifestyle smarter. Operating systems running on IoT devices form a critical component for connectivity, security, networking, storage, remote device management and other system needs. As a result, applications deployed on top of such an operating system can exploit its vulnerabilities and potentially leak confidential data to the attacker. IoT devices typically have sensors that allow them to measure one or more channel values. They constitute one such example of confidential data for the user which can get leaked or manipulated by a malicious application exploiting the privileges provided by the operating system. In this work, we propose a methodology for finding security vulnerabilities using the concept of taint analysis on the LLVM IR of a part of the kernel of the Zephyr OS, a lightweight real-time operating system for connected, resource-constrained and embedded devices. Several vulnerabilities were detected as reported in the Results section.