Skip to main navigation Skip to search Skip to main content

IoTAEG: Automatic Exploit Generation of IoT Devices

  • Yu Wang
  • , Zhoujun Li
  • , Yipeng Zhang*
  • , You Zhai
  • *Corresponding author for this work
  • Beihang University
  • North China University of Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Automatic exploit generation (AEG) refers to the process of automatically finding the path in the program that can trigger vulnerabilities and generate exploits. Generally speaking, the process of finding vulnerabilities needs to apply fuzzing and symbolic execution techniques. Existing AEG generally targets executables for regular Linux and Windows platforms, but no AEG for vulnerable Internet of Things (IoT) devices. In response to this situation, we propose the exploit generation system IoTAEG, which automatically detects stack overflow vulnerabilities in the firmware of IoT devices, and automatically generates and exploits the generation system based on the stack overflow vulnerabilities. IoTAEG uses the mature fuzzing software AFL++ to detect vulnerabilities in IoT devices, uses the crashed input found by AFL++ to construct a symbolic state through symbolic execution, dynamically analyzes the constructed symbolic state, and detects whether there are exploitable vulnerabilities. If the above vulnerabilities exist, different exploit generation strategies will be adopted for different protection mechanisms, and some protection mechanisms such as Address space layout randomization (ASLR) and Non-eXecute (NX) will be bypassed. For some difficult-to-exploit cases, IoTAEG uses advanced stack overflow exploitation methods to generate exploits. Experiments show that IoTAEG can complete 20 MIPS/ARM binary files and 8 IoT devices' firmware vulnerability detection and exploit generation. IoTAEG is the first publicly available vulnerability mining and exploit generation system for IoT devices.

Original languageEnglish
Title of host publication2023 4th International Conference on Computer Engineering and Intelligent Control, ICCEIC 2023
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages610-619
Number of pages10
ISBN (Electronic)9798350308877
DOIs
StatePublished - 2023
Event2023 4th International Conference on Computer Engineering and Intelligent Control, ICCEIC 2023 - Hybrid, Guangzhou, China
Duration: 20 Oct 202322 Oct 2023

Publication series

Name2023 4th International Conference on Computer Engineering and Intelligent Control, ICCEIC 2023

Conference

Conference2023 4th International Conference on Computer Engineering and Intelligent Control, ICCEIC 2023
Country/TerritoryChina
CityHybrid, Guangzhou
Period20/10/2322/10/23

Keywords

  • Internet of Things
  • automatic exploit generation
  • fuzzing
  • stack overflow vulnerability
  • symbolic execution

Fingerprint

Dive into the research topics of 'IoTAEG: Automatic Exploit Generation of IoT Devices'. Together they form a unique fingerprint.

Cite this