190
A. Francillon et al.
and maintained by different persons or entities in different shapes and forms, thus
there is no uniform way to modify and repack firmware packages.
11.3 Static Firmware Analysis
Once the code is extracted further analysis can be performed. There are two main
classes of analysis that can be preformed on a generic computing system—static
analysis and dynamic analysis. In principle, the distinction between the two is
easy: in static analysis the code is analyzed without executing it, but instead only
reasoning about it, while in the dynamic setting the analysis is performed on the
code while it is executed. With more advanced analysis techniques, however, this
frontier is slightly blurred. For example, symbolic execution allows one to analyze
software by considering some variables to have an unknown value (i.e., they are
unconstrained). Symbolic execution is sometimes considered static analysis and
at other times dynamic analysis. In this section, we will first describe simple
static analysis which can be efficiently performed on firmware packages, then we
will discuss more advanced static analysis approaches. Finally, we will cover the
limitations of static analysis and in the next section focus on the dynamic analysis
on firmware packages.
11.3.1 Simple Static Analysis on Firmware Packages
11.3.1.1 Configuration Analysis
For a large majority of complex embedded devices (i.e., those of Type-I as described
in Sect. 11.1.5), while service configuration is stored within the file-system of the
device, user-configurable information is often stored elsewhere—within a region of
memory called Non-Volatile Random Access Memory (NVRAM) which retains its
state between power cycles (similar to Flash memory in some ways). Many devices
treat NVRAM as a key-value store and include utilities such as nvram-get and
nvram-set, as well as dedicated libraries to get and set values stored there. On
a router, for example, the current Wi-Fi passphrase and web-based configuration
interface credentials, will often be stored within the NVRAM, which will be queried
by software in order to facilitate the authentication of the device and its services.
All other device configuration, without performing a firmware upgrade, will be
static. As a result of this, any, e.g., hard-coded passwords or certificates (as noted
in [151]), can be leveraged by an adversary to compromise a device. To this end,
Costin et al. [155] show many instances where devices are configured with user
accounts and passwords that are weak, missing entirely, or stored in plain-text.
Therefore, a first step in static analysis of firmware is to examine the configuration
of its services: to check for improperly configured services, e.g., due to use of
A. Francillon et al.
and maintained by different persons or entities in different shapes and forms, thus
there is no uniform way to modify and repack firmware packages.
11.3 Static Firmware Analysis
Once the code is extracted further analysis can be performed. There are two main
classes of analysis that can be preformed on a generic computing system—static
analysis and dynamic analysis. In principle, the distinction between the two is
easy: in static analysis the code is analyzed without executing it, but instead only
reasoning about it, while in the dynamic setting the analysis is performed on the
code while it is executed. With more advanced analysis techniques, however, this
frontier is slightly blurred. For example, symbolic execution allows one to analyze
software by considering some variables to have an unknown value (i.e., they are
unconstrained). Symbolic execution is sometimes considered static analysis and
at other times dynamic analysis. In this section, we will first describe simple
static analysis which can be efficiently performed on firmware packages, then we
will discuss more advanced static analysis approaches. Finally, we will cover the
limitations of static analysis and in the next section focus on the dynamic analysis
on firmware packages.
11.3.1 Simple Static Analysis on Firmware Packages
11.3.1.1 Configuration Analysis
For a large majority of complex embedded devices (i.e., those of Type-I as described
in Sect. 11.1.5), while service configuration is stored within the file-system of the
device, user-configurable information is often stored elsewhere—within a region of
memory called Non-Volatile Random Access Memory (NVRAM) which retains its
state between power cycles (similar to Flash memory in some ways). Many devices
treat NVRAM as a key-value store and include utilities such as nvram-get and
nvram-set, as well as dedicated libraries to get and set values stored there. On
a router, for example, the current Wi-Fi passphrase and web-based configuration
interface credentials, will often be stored within the NVRAM, which will be queried
by software in order to facilitate the authentication of the device and its services.
All other device configuration, without performing a firmware upgrade, will be
static. As a result of this, any, e.g., hard-coded passwords or certificates (as noted
in [151]), can be leveraged by an adversary to compromise a device. To this end,
Costin et al. [155] show many instances where devices are configured with user
accounts and passwords that are weak, missing entirely, or stored in plain-text.
Therefore, a first step in static analysis of firmware is to examine the configuration
of its services: to check for improperly configured services, e.g., due to use of
