11 Finding Software Bugs in Embedded Devices
193
11.3.2.2 Discovering Backdoors with Static Analysis
Aside from vulnerability discovery, a small body of work has attempted to automatically identify backdoor-like constructs in device firmware. Static analysis is
most suited to detecting such constructs due to the fact it can achieve full program
coverage. Dynamic analysis is less adequate in this case, as it relies solely on
execution traces that can be captured and analyzed stemming from triggering
standard program behaviors (which, by definition [551], a backdoor is not).
HumIDIFy 3 [552] uses a combination of Machine Learning (ML) and static
analysis to identify anomalous and unexpected behavior in services commonly
found in Linux-based firmware. ML is used first to identify the type of firmware
binaries, e.g., a web-server, this then drives classification-specific static analysis
on each binary. HumIDIFy attempts to validate that binaries do not perform any
functionality outside of what is expected of the type of software they are identified
as. For example, HumIDIFy is able to detect a backdoor within a web-server taken
from Tenda router firmware 4 that contains an additional UDP listening thread which
executes shell commands provided to it (without authentication) as the root user.
Stringer 5 [550] attempts to locate backdoor-like behavior in Linux-based
firmware. It automatically discovers comparisons with static data that leads to
execution of unique program functionality, which models the situation of a backdoor
providing access to undocumented functionality via a hard-coded credential pair
or undocumented command. Stringer provides an ordering of the functions within
a binary based on how much their control-flow is influenced by static data
comparisons that guard access to functionality not otherwise reachable. The authors
demonstrate Stringer is able to detect both undocumented functionality and hardcoded credential backdoors in devices from a number of manufacturers.
Firmalice [528] is a tool for detecting authentication bypass vulnerabilities and
backdoors within firmware by symbolic execution. It takes a so-called security
policy as input, which specifies a condition a program (or firmware) will exhibit
when it has reached an authenticated state. Using this security policy, it attempts to
prove that it is possible to reach an authenticated state by discovering an input that
when given to the program satisfies the conditions to reach that state. To discover
such an input, Firmalice employs symbolic execution on a program slice taken from
a program point acting as an input source to the point reached that signals the
program is in an authenticated state. If it is able to satisfy all of the constraints such
that a path exists between these two points, and an input variable can be concretised
that satisfies those constraints, then it has discovered an authentication bypass
backdoor (and a triggering input)—such an input will not be discoverable in a nonbackdoored authentication routine. Unfortunately, Firmalice requires a degree of
manual intervention to perform its analysis, such as identifying the security policy,
3 Available as open-source: https://github.com/BaDSeED-SEC/HumIDIFy.
4 http://www.devttys0.com/2013/10/from-china-with-love/.
5 Available as open-source: https://github.com/BaDSeED-SEC/strngr.
Précédent

- 200/268

Suivant