A tool for IoT Firmware Certification


연구 분야: Analysis



학회: ARES '24: Proceedings of the 19th International Conference on Availability, Reliability and Security


초록

The rapid growth of the Internet of Things (IoT) has created a fragmented ecosystem, with no clear rules for security and reliability. This lack of standardization makes IoT devices vulnerable to attacks. IoT firmware certification can address these security concerns. It empowers consumers to make informed choices by readily identifying secure products. Additionally, it incentivizes developers to prioritize secure coding practices, ultimately promoting transparency and trust within the IoT ecosystem. Several existing IoT device certifications (e.g. Cybersecurity Assurance Program, British Standards Institution, ioXt Alliance) prioritise cybersecurity through risk and vulnerability assessments. This paper proposes a complementary approach. Our tool focuses on identifying firmware functionality by analysing system calls through static analysis. This allows to publicly identify APIs to assess the actual behaviour of a firmware. The analysis culminates in the generation of JSON manifests, which encapsulate the relevant information gathered during the case study. In particular, this analysis verifies whether the actual behaviour is in line with the developer’s statements about the device’s functionality, contributing to the security and reliability of a device. To evaluate tool’s performance, we conducted a benchmarking analysis which has demonstrated efficient handling of binaries written in various languages, even those with large file sizes. Future will be based on refining the API search and syscall collection algorithms, other than incorporating vulnerability analysis to further strengthen the security of an IoT device.


Author Profile
Giuseppe Marco Bianco

Department of Control and Computer Engineering Politecnico di Torino Italy

Andorra
Author Profile
Luca Ardito

Department of Control and Computer Engineering Politecnico di Torino Italy

Andorra
Author Profile
Michele Valsesia

Department of Control and Computer Engineering Politecnico di Torino Italy

Andorra

📄 논문 정보

발행 연도 2024년
인용수 2
출판 국가 Andorra
사이트 ACM
좋아요 수 0

연관 논문 목록 (246건)