引用本文:于颖超,甘水滔,邱俊洋,秦晓军,陈左宁.二进制代码相似度分析及在嵌入式设备固件漏洞搜索中的应用.软件学报,2022,33(11):4137-4172
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 2628次   下载 4754 本文二维码信息
码上扫一扫!
分享到: 微信 更多
二进制代码相似度分析及在嵌入式设备固件漏洞搜索中的应用
于颖超1, 甘水滔1, 邱俊洋1, 秦晓军1, 陈左宁2
1.数学工程与先进计算国家重点实验室, 江苏 无锡 214125;2.中国工程院, 北京 100088
摘要:
在当今“万物互联”的时代,嵌入式系统逐渐成为接入云端的重要组件,常用于安全和隐私敏感的应用或设备中.然而,其底层软件(即固件)也在频繁遭受着安全漏洞的影响.由于嵌入式设备底层硬件平台的复杂异构,软硬件实现差异较大,且其专用性强、源码/文档等往往不会公开,加之其运行环境受限等原因,使得一些在桌面系统上运行良好的动态测试工具很难(或根本不可能)直接适配到嵌入式设备/固件环境中.近年来,研究人员逐渐开始探索基于二进制相似度分析技术来检测嵌入式设备固件中存在的已知漏洞,并且取得了较大的进展.围绕二进制代码相似度分析面临的关键技术挑战,系统研究了现有的二进制代码相似度分析技术,对其通用流程、技术特征、评估标准进行了综合分析和比较;然后分析并总结了现有二进制代码相似度分析技术在嵌入式设备固件漏洞搜索领域的应用;最后,提出了该领域应用仍然存在的一些技术挑战及未来的一些开放性的研究方向.
关键词:  二进制代码相似度分析  嵌入式固件  漏洞搜索  深度学习
DOI:10.13328/j.cnki.jos.006540
分类号:TP311
基金项目:
Binary Code Similarity Analysis and Its Applications on Embedded Device Firmware Vulnerability Search
YU Ying-Chao1, GAN Shui-Tao1, QIU Jun-Yang1, QIN Xiao-Jun1, CHEN Zuo-Ning2
1.State Key Laboratory of Mathematical Engineering and Advanced Computing, Wuxi 214125, China;2.Chinese Academy of Engineering, Beijing 100088, China
Abstract:
In the era of today’s Internet of Things, embedded systems are becoming important components for accessing the cloud, which are used in both secure and privacy-sensitive applications or devices frequently. However, the underlying software (a.k.a. firmware) often suffered from a wide range of security vulnerabilities. The complexity and heterogeneous of the underlying hardware platform, the difference of the hardware and software implementation, the specificity and limited document, together with limited running environment made some of very good dynamic testing tools for desktop systems hard to (even impossible) be adapted to embedded devices/firmware environment directly. In recent years, researchers have made great progress in detecting well-known vulnerabilities in embedded device firmware based on binary code similarity analysis. Focusing on the key technical challenges of binary code similarity analysis, the existing binary code similarity analysis technologies are studied systematically; the general process, technical characteristics, and evaluation criteria of these technologies are analyzed and compared comprehensively. Then, the application of these technologies is analyzed and summarized in the field of embedded device firmware vulnerability search. At last, some technical challenges in this field are presented and some open future research directions are proposed for the related researchers.
Key words:  binary code similarity analysis  embedded firmware  vulnerability search  deep learning

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: