IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based Fuzzing
Jiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo, Zhiqiang Lin, XiaoFeng Wang, Wing Cheong Lau, Menghan Sun, Ronghai Yang, Kehuan Zhang
Abstract
With more IoT devices entering the consumer market, it becomes imperative to detect their security vulnerabilities before an attacker does. Existing binary analysis based approaches only work on firmware, which is less accessible except for those equipped with special tools for extracting the code from the device. To address this challenge in IoT security analysis, we present in this paper a novel automatic fuzzing framework, called IOTFUZZER, which aims at finding memory corruption vulnerabilities in IoT devices without access to their firmware images. The key idea is based upon the observation that most IoT devices are controlled through their official mobile apps, and such an app often contains rich information about the protocol it uses to communicate with its device. Therefore, by identifying and reusing program-specific logic (e.g., encryption) to mutate the test case (particularly message fields), we are able to effectively probe IoT targets without relying on any knowledge about its protocol specifications. In our research, we implemented IOTFUZZER and evaluated 17 real-world IoT devices running on different protocols, and our approach successfully identified 15 memory corruption vulnerabilities (including 8 previously unknown ones).
Responsible Disclosure: All vulnerabilities described in this paper have been reported to the corresponding vendors.
reported [48], with devastating consequences in some of them.
A prominent example is the Mirai attack [32], which turns a large number of online IoT devices (e.g., IP cameras and home routers) into bots for launching DDoS attacks against online services. Given the pervasiveness of vulnerable devices, we strongly believe that these known attacks are nothing but a tip of the iceberg.
An important target of IoT attacks is implementation flaws (or security vulnerabilities) within a device's firmware. Systematic detection of these flaws needs to address a few challenges. The primary one is the difficulty in firmware acquisition because many vendors do not make their firmware images publicly available. Alternatively, we can dump images from the motherboard, which, however, needs the support from enabled debugging ports, which may not exist for many IoT devices, due to their simplicity. In addition, given the diversity of compression (even encryption) formats, how to unpack the obtained firmware is nontrivial as well.
When it comes to the security analysis of the files extracted from firmware, the main challenge comes from diverse underlying architectures (memory layout, instruction set, and so forth). Existing techniques mainly rely on emulation for certain architectures [23], [17], [13]. However, the programs running in the emulator will frequently crash due to unavailable NVRAM parameters. Some other related studies utilize symbolic execution to analyze firmware. This attempt is also impeded by the architecture issue. For example, FIE [21] only supports the security analysis of firmware images built on the TI MSP430 microcontroller family, and FirmUSB [31] only supports 8051 architecture.
Our Approach. Unlike traditional embedded devices, most IoT devices are controlled by users through mobile applications (IoT app for short). Such an IoT app is designed to act as its device's phone-side control panel, and therefore carries rich information about the device, particularly the way to talk to its firmware. Examples of such information include command (seed) messages, URLs, and encryption/decryption schemes that embedded in the app. Based on this observation, in this paper, we present IOTFUZZER, an automatic, blackbox fuzzing framework designed specifically for detecting memory-corruption flaws in IoT firmware. A unique property of IOTFUZZER is that it runs a protocol-guided fuzz and utilizes the information carried by the IoT app without reverse-
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4b7a4250-ca67-4089-819b-e3326212dcd9Cited by top-tier papers82
- SoK: Security Evaluation of Home-Based IoT DeploymentsOmar Alrawi, Chaz Lever, Manos Antonakakis, Fabian MonroseS&P 2019 · 411 citations
- FIRM-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process EmulationYaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song et al.USENIX Security 2019 · 279 citations
- All Things Considered: An Analysis of IoT Devices on Home NetworksDeepak Kumar, Kelly Shen, Benton Case, Deepali Garg et al.USENIX Security 2019 · 189 citations
- On the Safety of IoT Device Physical Interaction ControlWenbo Ding, Hongxin HuCCS 2018 · 169 citations
- Snipuzz: Black-box Fuzzing of IoT Firmware via Message Snippet InferenceXiaotao Feng, Ruoxi Sun, Xiaogang Zhu, Minhui Xue et al.CCS 2021 · 146 citations
Builds on7
- Scalable Graph-based Bug Search for Firmware ImagesQian Feng, Rundong Zhou, Chengcheng Xu, Yao Cheng et al.CCS 2016 · 456 citations
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 428 citations
- discovRE: Efficient Cross-Architecture Identification of Bugs in Binary CodeSebastian Eschweiler, Khaled Yakdan, Elmar Gerhards-PadillaNDSS 2016 · 342 citations
- FirmUSB: Vetting USB Device Firmware using Domain Informed Symbolic ExecutionGrant Hernandez, Farhaan Fowze, Dave (Jing) Tian, Tuba Yavuz et al.CCS 2017 · 98 citations
- AUTHSCOPE: Towards Automatic Discovery of Vulnerable Authorizations in Online ServicesChaoshun Zuo, Qingchuan Zhao, Zhiqiang LinCCS 2017 · 59 citations
Related papers
- What You Corrupt Is Not What You Crash: Challenges in Fuzzing Embedded DevicesMarius Muench, Jan Stijohann, Frank Kargl, Aurélien Francillon et al.NDSS 2018 · 202 citations
- P2IM: Scalable and Hardware-independent Firmware Testing via Automatic Peripheral Interface ModelingBo Feng, Alejandro Mera, Long LuUSENIX Security 2020
- Game of Hide-and-Seek: Exposing Hidden Interfaces in Embedded Web Applications of IoT DevicesWei Xie, Jiongyi Chen, Zhenhua Wang, Chao Feng et al.WWW 2022 · 26 citations
- SmuFuzz: Enable Deep System Management Mode Fuzzing in Fully Featured UEFI Runtime EnvironmentJianqiang Wang, Yi Xiang, Meng Wang, Qinying Wang et al.S&P 2026
- Android SmartTVs Vulnerability Discovery via Log-Guided FuzzingYousra Aafer, Wei You, Yi Sun, Yu Shi et al.USENIX Security 2021 · 35 citations
