Linux-based IoT Benchmark Generator For Firmware Security Analysis Tools

18TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY & SECURITY, ARES 2023(2023)

引用 0|浏览2
暂无评分
摘要
There is a growing interest of IoT manufacturers to incorporate firmware analysis tools in their development pipeline to evaluate the security of new embedded devices. This has the advantage of discovering security issues before the device is marketed. However, each device has its own design, including different architectures, services and communication protocols, programmed and configured in different programming languages. This diversity results in potentially complete categories of vulnerabilities discarded by the firmware security analysis tools. Hence, a positive outcome of such tools may result in incorrect conclusions. To address this challenge, we propose B4IoT, a platform that generates customized Linux-based firmware benchmarks, that are representative of the manufacturers' devices. It enables those organizations to evaluate both static and dynamic firmware security analysis tools, to gain insight into what categories of vulnerabilities are found, and which aren't. This allows either to discard tools completely or complement them with additional tools that focus on the missing categories. The platform will be made available online and is evaluated using five state-of-the-art open-source firmware analysis tools.
更多
查看译文
关键词
IoT,Firmware Analysis,Benchmark
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要