A framework for intelligent IoT firmware compliance testing

Mohan Krishna Kagita , Giridhar Reddy Bojja , Mohammed Kaosar
{"title":"A framework for intelligent IoT firmware compliance testing","authors":"Mohan Krishna Kagita ,&nbsp;Giridhar Reddy Bojja ,&nbsp;Mohammed Kaosar","doi":"10.1016/j.iotcps.2021.07.001","DOIUrl":null,"url":null,"abstract":"<div><p>The recent mass production and usage of the Internet of Things (IoT) have posed serious concerns due to the unavoidable security complications. The firmware of IoT systems is a critical component of IoT security. Although multiple organizations have released security guidelines, few IoT vendors are following these guidelines properly, either due to a lack of accountability or the availability of appropriate resources. Some tools for this purpose can use static, dynamic, or fuzzing techniques to test the security of IoT firmware, which may result in false positives or failure to discover vulnerabilities. Furthermore, the vast majority of resources are devoted to a single subject, such as networking protocols, web interfaces, or Internet of Things computer applications. This paper aims to present a novel method for conducting compliance testing and vulnerability evaluation on IoT system firmware, communication interfaces, and networking services using static and dynamic analysis. The proposed system detects a broad range of security bugs across a wide range of platforms and hardware architectures. To test and validate our prototype, we ran tests on 4300 firmware images and discovered 13,000+ compliance issues. This work, we believe, will be the first step toward developing a reliable automated compliance testing framework for the IoT manufacturing industry and other stakeholders.</p></div>","PeriodicalId":100724,"journal":{"name":"Internet of Things and Cyber-Physical Systems","volume":"1 ","pages":"Pages 1-7"},"PeriodicalIF":0.0000,"publicationDate":"2021-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://sci-hub-pdf.com/10.1016/j.iotcps.2021.07.001","citationCount":"8","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Internet of Things and Cyber-Physical Systems","FirstCategoryId":"1085","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2667345221000018","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 8

Abstract

The recent mass production and usage of the Internet of Things (IoT) have posed serious concerns due to the unavoidable security complications. The firmware of IoT systems is a critical component of IoT security. Although multiple organizations have released security guidelines, few IoT vendors are following these guidelines properly, either due to a lack of accountability or the availability of appropriate resources. Some tools for this purpose can use static, dynamic, or fuzzing techniques to test the security of IoT firmware, which may result in false positives or failure to discover vulnerabilities. Furthermore, the vast majority of resources are devoted to a single subject, such as networking protocols, web interfaces, or Internet of Things computer applications. This paper aims to present a novel method for conducting compliance testing and vulnerability evaluation on IoT system firmware, communication interfaces, and networking services using static and dynamic analysis. The proposed system detects a broad range of security bugs across a wide range of platforms and hardware architectures. To test and validate our prototype, we ran tests on 4300 firmware images and discovered 13,000+ compliance issues. This work, we believe, will be the first step toward developing a reliable automated compliance testing framework for the IoT manufacturing industry and other stakeholders.

查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
智能物联网固件合规性测试框架
最近,物联网(IoT)的大量生产和使用,由于不可避免的安全问题,引起了严重的担忧。物联网系统的固件是物联网安全的关键组成部分。尽管多个组织已经发布了安全指南,但由于缺乏问责制或适当资源的可用性,很少有物联网供应商正确地遵循这些指南。为此目的的一些工具可以使用静态、动态或模糊测试技术来测试物联网固件的安全性,这可能导致误报或无法发现漏洞。此外,绝大多数资源都用于单一主题,例如网络协议,web接口或物联网计算机应用程序。本文旨在提出一种利用静态和动态分析对物联网系统固件、通信接口和网络服务进行符合性测试和漏洞评估的新方法。该系统可以在各种平台和硬件架构中检测广泛的安全漏洞。为了测试和验证我们的原型,我们对4300个固件映像进行了测试,发现了13000多个遵从性问题。我们相信,这项工作将是为物联网制造业和其他利益相关者开发可靠的自动化合规测试框架的第一步。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
CiteScore
13.80
自引率
0.00%
发文量
0
期刊最新文献
Non-work conserving dynamic scheduling of moldable gang tasks on multicore systems Multi-objective optimization algorithms for intrusion detection in IoT networks: A systematic review Constructing immersive toy trial experience in mobile augmented reality Machine learning techniques for IoT security: Current research and future vision with generative AI and large language models Ransomware on cyber-physical systems: Taxonomies, case studies, security gaps, and open challenges
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1