192
A. Francillon et al.
versions of software (both programs and libraries) it contains, and correlate those
versions with known vulnerabilities (e.g., CVE database).
There are several possible approaches to perform this. For example, [155] use
fuzzy hashing [340, 507] as a method to correlate files in firmware images. The
effectiveness of the approach was demonstrated in several examples, in particular
uncovering many IoT and embedded devices being so-called “white label” products. 2 Finally, machine learning can be used to identify firmware images [157] or
to search for known vulnerabilities [585].
11.3.2 Static Code Analysis of Firmware Packages
Developing tools for performing automated static code analysis on embedded device
firmware presents a number of complexities compared to performing analyses on
software for commodity PC systems (i.e., Type-0 devices). The first challenge is the
diversity of CPU architectures. This alone restricts the amount of existing tooling
that can be used, and when attempting large scale analysis tools will inevitably
have to deal with firmware from a number of distinct architectures. To facilitate
the analysis in this case, the algorithms will either have to be reimplemented for
each architecture being analyzed, or the architecture-specific disassembled firmware
instructions will have to be lifted to a common, so-called Intermediate Language
(IL) or Intermediate Representation (IR). A further difficulty for more simple
devices (e.g., those of Type-III) is the often non-standard means by which different
device firmware executes (e.g., it could be interrupt driven) and interacts with the
memory and external peripherals. More complex firmware (e.g., that of Type-I
devices) tends to more closely follow the execution behavior of more conventional
devices (those of Type-0).
11.3.2.1 Code Analysis of Embedded Firmware
Despite the increased complexity of performing automated analysis of embedded
device firmware, a number of techniques have been proposed for both targeted and
large-scale static analysis. Eschweiler et al. [202] and Feng et al. [212] use numeric
feature vectors to perform graph-based program comparisons [191] efficiently.
They encode control-flow and instruction information in these feature vectors to
identify known vulnerabilities in device firmware. Both methods provide a means
of querying a data-set of binaries using a reference vulnerability as input and
identifying the subset of binaries that contain constructs that are similar (but not
necessarily the same) to those of the input vulnerability. The work in [585] improves
the performance of these approaches by relying on Neural Networks.
2 Generic products which are sold under a known brand.
A. Francillon et al.
versions of software (both programs and libraries) it contains, and correlate those
versions with known vulnerabilities (e.g., CVE database).
There are several possible approaches to perform this. For example, [155] use
fuzzy hashing [340, 507] as a method to correlate files in firmware images. The
effectiveness of the approach was demonstrated in several examples, in particular
uncovering many IoT and embedded devices being so-called “white label” products. 2 Finally, machine learning can be used to identify firmware images [157] or
to search for known vulnerabilities [585].
11.3.2 Static Code Analysis of Firmware Packages
Developing tools for performing automated static code analysis on embedded device
firmware presents a number of complexities compared to performing analyses on
software for commodity PC systems (i.e., Type-0 devices). The first challenge is the
diversity of CPU architectures. This alone restricts the amount of existing tooling
that can be used, and when attempting large scale analysis tools will inevitably
have to deal with firmware from a number of distinct architectures. To facilitate
the analysis in this case, the algorithms will either have to be reimplemented for
each architecture being analyzed, or the architecture-specific disassembled firmware
instructions will have to be lifted to a common, so-called Intermediate Language
(IL) or Intermediate Representation (IR). A further difficulty for more simple
devices (e.g., those of Type-III) is the often non-standard means by which different
device firmware executes (e.g., it could be interrupt driven) and interacts with the
memory and external peripherals. More complex firmware (e.g., that of Type-I
devices) tends to more closely follow the execution behavior of more conventional
devices (those of Type-0).
11.3.2.1 Code Analysis of Embedded Firmware
Despite the increased complexity of performing automated analysis of embedded
device firmware, a number of techniques have been proposed for both targeted and
large-scale static analysis. Eschweiler et al. [202] and Feng et al. [212] use numeric
feature vectors to perform graph-based program comparisons [191] efficiently.
They encode control-flow and instruction information in these feature vectors to
identify known vulnerabilities in device firmware. Both methods provide a means
of querying a data-set of binaries using a reference vulnerability as input and
identifying the subset of binaries that contain constructs that are similar (but not
necessarily the same) to those of the input vulnerability. The work in [585] improves
the performance of these approaches by relying on Neural Networks.
2 Generic products which are sold under a known brand.
