196
A. Francillon et al.
and from the device occur via the connected debug or serial interface. On the one
hand, by using this approach it is possible to control exactly what is to be analyzed
because the emulator is under the full supervision of the analysis host. On the other
hand, this approach enables broader and deeper coverage of the execution because
the device can complement the execution of firmware parts that are impossible to
execute within the emulator.
This is the approach followed by Avatar [591] which aims at providing symbolic
execution with S2E [140], while Avatar2 [429] focuses on better interoperability
with more tools. Prospect [312] explores forwarding at the system calls level and
Surrogates [341] provides a very fast debug interface. Inception [125] provides an
analysis environment to use during testing when source code is available.
11.4.3 Device-Less Dynamic Analysis and Emulation
Performing dynamic analysis in a device-interactive manner certainly has its
benefits, however such an approach has a number of limitations and is hard to
fully automate. Firstly, it is not easy to scale the human operator’s interventions
and expertise required for many of the tasks related to the approach of device
interaction with emulation. Secondly, it is challenging to automate and scale the
logistics operations related to acquisition, tear-down, connection, configuration and
reset of a large number of devices. Therefore, dynamic analysis techniques that are
easier and more feasible to scale and automate are required. One such technique is
the device-less analysis based on full or partial emulation.
Davidson et al. [175] presented the FIE tool that detects bugs in firmware of the
MSP430 microcontroller family. FIE leverages KLEE [120] to perform symbolic
execution of firmware in order to detect memory safety violations (e.g., buffer
overflows and out-of-bounds memory accesses), and misuse of peripherals (e.g.,
attempted writes to read-only memory). FIE needs the availability of the source
code, which is uncommon, and is able to handle a variety of the nuances and
challenges faced during automated analysis of firmware, especially when dealing
with firmware for Type-III devices. However, when reading I/O from a device,
the values read are always assumed to return unconstrained (completely symbolic)
values which leads to a state explosion problem. This limits the size of the programs
which can be analyzed.
In [156], the authors perform device-less dynamic security analysis via
automated and large-scale emulation of embedded firmware. Similarly, FIRMADYNE [137] presents an automated and scalable system for performing emulation
and dynamic analysis of Linux-based embedded firmware.
The general idea of both works is to crawl and then unpack firmware packages
into minimal root filesystems (i.e., rootfs) that can subsequently be virtualized
and executed as a whole via “system emulation” (as opposed to “user emulation”)
using for example QEMU [69]. The emulator is first used to start an architecturespecific emulation host OS, such as Debian for ARM or MIPS depending on the
Précédent

- 203/268

Suivant