Chapter 11
Finding Software Bugs in Embedded
Devices
Aurélien Francillon, Sam L. Thomas, and Andrei Costin
Abstract The goal of this chapter is to introduce the reader to the domain of bug
discovery in embedded systems which are at the core of the Internet of Things.
Embedded software has a number of particularities which makes it slightly different
to general purpose software. In particular, embedded devices are more exposed to
software attacks but have lower defense levels and are often left unattended. At the
same time, analyzing their security is more difficult because they are very “opaque”,
while the execution of custom and embedded software is often entangled with the
hardware and peripherals. These differences have an impact on our ability to find
software bugs in such systems. This chapter discusses how software vulnerabilities
can be identified, at different stages of the software life-cycle, for example during
development, during integration of the different components, during testing, during
the deployment of the device, or in the field by third parties.
11.1 The Challenges of Embedded Devices and Software
We argue that the problem of embedded software security is due to multiple factors,
including a systematic lack of transparency, control, and resistance to attacks. A
particular way to improve this is to analyze the software of these devices, with the
particular goal of identifying software vulnerabilities in order to correct them as
early as possible.
A. Francillon ()
EURECOM, Sophia Antipolis, France
e-mail: aurelien.francillon@eurecom.fr
S. L. Thomas
University of Birmingham, Birmingham, United Kingdom
A. Costin
Faculty of Information Technology, University of Jyväskylä, Jyväskylä, Finland
© The Author(s) 2021
G. Avoine, J. Hernandez-Castro (eds.), Security of Ubiquitous Computing Systems,
https://doi.org/10.1007/978-3-030-10591-4_11
183
Précédent

- 190/268

Suivant