FirmWire: Transparent Dynamic Analysis for Cellular Baseband Firmware

FirmWire: Transparent Dynamic Analysis for Cellular Baseband Firmware
复制标题

DOI:
10.14722/ndss.2022.23136
复制
发表时间:
2022
期刊:
Proceedings 2022 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Grant Hernandez;Marius Muench;D. Maier;A. Milburn;Shinjo Park;Tobias Scharnowski;Tyler Tucker;Patrick Traynor;Kevin R. B. Butler
Grant Hernandez;Marius Muench;D. Maier;A. Milburn;Shinjo Park;Tobias Scharnowski;Tyler Tucker;Patrick Traynor;Kevin R. B. Butler
中科院分区:
其他
文献类型:
--
作者:
Grant Hernandez;Marius Muench;D. Maier;A. Milburn;Shinjo Park;Tobias Scharnowski;Tyler Tucker;Patrick Traynor;Kevin R. B. Butler

文献摘要

相似文献

- 如今的智能手机利用基带处理器来实现多种蜂窝协议。基带执行固件,负责解码从三十年的蜂窝标准中开发出来的数百种消息类型。尽管其空中攻击面很大,但基带固件几乎没有得到安全分析。以前的工作主要是分析来自少数设备模型的少数固件图像,但通常严重依赖于耗时的手动静态分析或单功能模糊。为了填补这一空白,我们提出了F W IRE,这是第一个用于基带处理器的全系统仿真平台,可执行未修改的艾德基带二进制固件。FW IRE提供特定于基带的API,可轻松添加对新供应商、固件映像和安全分析的支持。为了展示F IRM W IRE的可扩展性,我们支持2个供应商和9个手机型号的213个软件映像,以便执行和测试它们。通过这些映像,F W IRE自动发现并桥接内部基带API,从而轻松注入协议消息。使用这些入口点,我们选择了LTE和GSM协议进行模糊测试,并发现了7个可能导致远程代码执行的预认证内存损坏-其中4个以前未知。我们在真实的设备上再现了这些崩溃,证明了FW IRE的仿真准确性。F W IRE是一个可扩展的基带平台
—Smartphones today leverage baseband processors to implement the multitude of cellular protocols. Basebands execute firmware, which is responsible for decoding hundreds of message types developed from three decades of cellular standards. Despite its large over-the-air attack surface, baseband firmware has received little security analysis. Previous work mostly analyzed only a handful of firmware images from a few device models, but often relied heavily on time-consuming manual static analysis or single-function fuzzing. To fill this gap, we present F IRM W IRE , the first full-system emulation platform for baseband processors that executes unmod-ified baseband binary firmware. F IRM W IRE provides baseband-specific APIs to easily add support for new vendors, firmware images, and security analyses. To demonstrate F IRM W IRE ’s scalability, we support 213 firmware images across 2 vendors and 9 phone models, allowing them to be executed and tested. With these images, F IRM W IRE automatically discovers and bridges internal baseband APIs, allowing protocol messages to be injected with ease. Using these entry points, we selected the LTE and GSM protocols for fuzzing and discovered 7 pre-authentication memory corruptions that could lead to remote code execution – 4 of which were previously unknown. We reproduced these crashes over-the-air on real devices, proving F IRM W IRE ’s emulation accuracy. F IRM W IRE is a scalable platform for baseband