A comprehensive survey of vulnerability detection method towards Linux-based IoT devices


연구 분야: Strategies



학회: CNCIT '23: Proceedings of the 2023 2nd International Conference on Networks, Communications and Information Technology


초록

The IoT devices have introduced vulnerabilities and new attack vectors, making many devices a prime target for cybercriminals, while enriching people’s daily lives and industries. Vulnerability detection can effectively address this growing threat. However, due to variability of software and hardware, non-disclosure of source code and documentation, and limited resources of IoT devices, security analysis has never been an easy task. Although researchers have developed many new methods to overcome various challenges in the past decade, key challenges still hinder the practical application of firmware vulnerability mining. Therefore, this paper aims to systematically summarize existing work and analyze the challenges of this field and its solutions. Result: By summarizing the state-of-the-art approaches for static, dynamic, and hybrid analysis of IoT firmware and network service programs, we identify their advantages, disadvantages, and limitations. We found that network service programs are the main attack surface for 0-day vulnerability. Meanwhile, in the short term, static analysis and dynamic analysis are still mainstream techniques for vulnerability detection. Moreover, we point out that unique running workflow and environments are the biggest challenges for vulnerability detection. This survey serves as a reference for researchers and practitioners interested in IoT device security analysis and helps identify promising research directions for the future.


Author Profile
Xixing Li

Information Engineering University China

China
Author Profile
Qiang Wei

Information Engineering University China

China
Author Profile
Zehui Wu

Information Engineering University China

China

📄 논문 정보

발행 연도 2023년
인용수 3
출판 국가 China
사이트 ACM
좋아요 수 0

연관 논문 목록 (267건)