A Tool for IoT Firmware Certification

被引:0
|
作者
Bianco, Giuseppe Marco [1 ]
Ardito, Luca [1 ]
Valsesia, Michele [1 ]
机构
[1] Politecn Torino, Dept Control & Comp Engn, Turin, Italy
来源
19TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY, ARES 2024 | 2024年
关键词
Certification; IoT; IoT Firmware; Behaviour; Static analysis; Binary analysis; ELF file; IoT devices; Rust; Detection;
D O I
10.1145/3664476.3670469
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The rapid growth of the Internet of Things (IoT) has created a fragmented ecosystem, with no clear rules for security and reliability. This lack of standardization makes IoT devices vulnerable to attacks. IoT firmware certification can address these security concerns. It empowers consumers to make informed choices by readily identifying secure products. Additionally, it incentivizes developers to prioritize secure coding practices, ultimately promoting transparency and trust within the IoT ecosystem. Several existing IoT device certifications (e.g. Cybersecurity Assurance Program, British Standards Institution, ioXt Alliance) prioritise cybersecurity through risk and vulnerability assessments. This paper proposes a complementary approach. Our tool focuses on identifying firmware functionality by analysing system calls through static analysis. This allows to publicly identify APIs to assess the actual behaviour of a firmware. The analysis culminates in the generation of JSON manifests, which encapsulate the relevant information gathered during the case study. In particular, this analysis verifies whether the actual behaviour is in line with the developer's statements about the device's functionality, contributing to the security and reliability of a device. To evaluate tool's performance, we conducted a benchmarking analysis which has demonstrated efficient handling of binaries written in various languages, even those with large file sizes. Future will be based on refining the API search and syscall collection algorithms, other than incorporating vulnerability analysis to further strengthen the security of an IoT device.
引用
收藏
页数:7
相关论文
共 50 条
  • [41] A Points-to-Sensitive Model Checker for C Programs in IoT Firmware
    Yu, Yinbo
    Liu, Jiajia
    Mu, Dejun
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (19): : 18998 - 19011
  • [42] Toward Hybrid Static-Dynamic Detection of Vulnerabilities in IoT Firmware
    He, Daojing
    Gu, Hongjie
    Li, Tinghui
    Du, Yongliang
    Wang, Xiaolei
    Zhu, Sencun
    Guizani, Nadra
    IEEE NETWORK, 2021, 35 (02): : 202 - 207
  • [43] IoT-DeepSense: Behavioral Security Detection of IoT Devices Based on Firmware Virtualization and Deep Learning
    Wang, Jin
    Liu, Chang
    Xu, Jiangpei
    Wang, Juan
    Hao, Shirong
    Yi, Wenzhe
    Zhong, Jing
    SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [44] Toward a generic and secure bootloader for IoT device firmware OTA update
    El Jaouhari, Saad
    Bouvet, Eric
    36TH INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN 2022), 2022, : 90 - 95
  • [45] A Secure IoT Firmware Update Scheme Against SCPA and DoS Attacks
    Yan-Hong Fan
    Mei-Qin Wang
    Yan-Bin Li
    Kai Hu
    Mu-Zhou Li
    Journal of Computer Science and Technology, 2021, 36 : 419 - 433
  • [46] ChainVeri: Blockchain-based Firmware Verification System for IoT environment
    Lim, Jea-Min
    Kim, Youngpil
    Yoo, Chuck
    IEEE 2018 INTERNATIONAL CONGRESS ON CYBERMATICS / 2018 IEEE CONFERENCES ON INTERNET OF THINGS, GREEN COMPUTING AND COMMUNICATIONS, CYBER, PHYSICAL AND SOCIAL COMPUTING, SMART DATA, BLOCKCHAIN, COMPUTER AND INFORMATION TECHNOLOGY, 2018, : 1050 - 1056
  • [47] Proving IoT Devices Firmware Integrity With Bijective MAC Time Stamped
    Urien, Pascal
    2020 IEEE 6TH WORLD FORUM ON INTERNET OF THINGS (WF-IOT), 2020,
  • [48] Securing Over-The-Air IoT Firmware Updates using Blockchain
    He, Xinchi
    Alqahtani, Sarra
    Gamble, Rose
    Papa, Mauricio
    INTERNATIONAL CONFERENCE ON OMNI-LAYER INTELLIGENT SYSTEMS (COINS), 2019, : 164 - 171
  • [49] Blockchain-Based Distributed Firmware Update Architecture for IoT Devices
    Choi, Seoyun
    Lee, Jong-Hyouk
    IEEE ACCESS, 2020, 8 : 37518 - 37525
  • [50] Universal Firmware Upgrade Over-The-Air for IoT Devices with Security
    Thakur, Poonam
    Bodade, Varsha
    Achary, Angitha
    Addagatla, Madhuri
    Malviya, Neeraj Kumar
    Pingle, Yogesh
    PROCEEDINGS OF THE 2019 6TH INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT (INDIACOM), 2019, : 27 - 30