跳到主要导航 跳到搜索 跳到主要内容

IoTAEG: Automatic Exploit Generation of IoT Devices

  • Yu Wang
  • , Zhoujun Li
  • , Yipeng Zhang*
  • , You Zhai
  • *此作品的通讯作者
  • Beihang University
  • North China University of Technology

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Automatic exploit generation (AEG) refers to the process of automatically finding the path in the program that can trigger vulnerabilities and generate exploits. Generally speaking, the process of finding vulnerabilities needs to apply fuzzing and symbolic execution techniques. Existing AEG generally targets executables for regular Linux and Windows platforms, but no AEG for vulnerable Internet of Things (IoT) devices. In response to this situation, we propose the exploit generation system IoTAEG, which automatically detects stack overflow vulnerabilities in the firmware of IoT devices, and automatically generates and exploits the generation system based on the stack overflow vulnerabilities. IoTAEG uses the mature fuzzing software AFL++ to detect vulnerabilities in IoT devices, uses the crashed input found by AFL++ to construct a symbolic state through symbolic execution, dynamically analyzes the constructed symbolic state, and detects whether there are exploitable vulnerabilities. If the above vulnerabilities exist, different exploit generation strategies will be adopted for different protection mechanisms, and some protection mechanisms such as Address space layout randomization (ASLR) and Non-eXecute (NX) will be bypassed. For some difficult-to-exploit cases, IoTAEG uses advanced stack overflow exploitation methods to generate exploits. Experiments show that IoTAEG can complete 20 MIPS/ARM binary files and 8 IoT devices' firmware vulnerability detection and exploit generation. IoTAEG is the first publicly available vulnerability mining and exploit generation system for IoT devices.

源语言英语
主期刊名2023 4th International Conference on Computer Engineering and Intelligent Control, ICCEIC 2023
出版商Institute of Electrical and Electronics Engineers Inc.
610-619
页数10
ISBN(电子版)9798350308877
DOI
出版状态已出版 - 2023
活动2023 4th International Conference on Computer Engineering and Intelligent Control, ICCEIC 2023 - Hybrid, Guangzhou, 中国
期限: 20 10月 202322 10月 2023

出版系列

姓名2023 4th International Conference on Computer Engineering and Intelligent Control, ICCEIC 2023

会议

会议2023 4th International Conference on Computer Engineering and Intelligent Control, ICCEIC 2023
国家/地区中国
Hybrid, Guangzhou
时期20/10/2322/10/23

学术指纹

探究 'IoTAEG: Automatic Exploit Generation of IoT Devices' 的科研主题。它们共同构成独一无二的学术指纹。

引用此