194
A. Francillon et al.
input points and privileged program locations. It is therefore not easily adaptable for
large-scale analysis.
11.3.2.3 Example Static Analysis to Discover Code Parsers
In order to interact with remote servers or connecting clients (e.g., for remote configuration), most firmware for networked embedded devices will contain client/server
components, e.g., a web-server, or proprietary, domain-specific client/server software. In all cases, the firmware itself or software contained within it (for more
complex devices) will implement parsers for handling the messages of the protocols
required to communicate with corresponding client/server entities. Such parsers are
a common source of bugs, whether their implementation incorrectly handles input
in a way that causes a memory corruption, or permits an invalid state transition
in a protocol’s state machine logic. Thus, identifying these constructs in binary
software is useful as a premise to performing targeted analyses. To this end,
Cojocar et al. [150], propose PIE, a tool to automatically detect parsing routines
in firmware binaries. PIE utilizes a supervised learning classifier trained on a
number of simple features of the LLVM IL representation of firmware components
known to contain parsing logic. Such features include: basic block count, number
of incoming edges to blocks, and number of callers (for functions). PIE provides
a means to identify specific functions responsible for performing parsing within
an input firmware package, or software component. Stringer [550], described
in Sect. 11.3.2.2, similarly provides a means of automatically identifying parser
routines (for text-based input); in addition to identifying routines, it is also able
to identify the individual (text-based) commands, processed by the parser.
11.4 Dynamic Firmware Analysis
Static analysis is indeed a robust technique that can help discover a wide range
of vulnerability classes, such as misconfigurations or backdoors. However, it is
not necessarily best suited for other types of vulnerabilities, especially when they
depend on the complex runtime state of the program.
Similar to static analysis, powerful dynamic analysis techniques and tools have
been developed for traditional systems and general purpose computers. However,
the unique characteristics and challenges of the embedded systems make it difficult,
if not impossible, to directly apply those proven methods. To this end, there are
several distinct directions for dynamic analysis of embedded systems and we briefly
discuss them below.
Précédent

- 201/268

Suivant