A large-scale empirical analysis of the vulnerabilities introduced by third-party components in IoT firmware
Binbin Zhao, Shouling Ji, Jiacheng Xu, Yuan Tian, Qiuyang Wei, Qinying Wang, Chenyang Lyu, Xuhong Zhang, Changting Lin, Jingzheng Wu, Raheem Beyah
Abstract
As the core of IoT devices, firmware is undoubtedly vital. Currently, the development of IoT firmware heavily depends on third-party components (TPCs), which significantly improves the development efficiency and reduces the cost. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will turn back influence the security of IoT firmware. Currently, existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement FirmSec, which leverages syntactical features and control-flow graph features to detect the TPCs at version-level in firmware, and then recognizes the corresponding vulnerabilities. Based on FirmSec, we present the first large-scale analysis of the usage of TPCs and the corresponding vulnerabilities in firmware. More specifically, we perform an analysis on 34,136 firmware images, including 11,086 publicly accessible firmware images, and 23,050 private firmware images from TSmart. We successfully detect 584 TPCs and identify 128,757 vulnerabilities caused by 429 CVEs. Our in-depth analysis reveals the diversity of security issues for different kinds of firmware from various vendors, and discovers some well-known vulnerabilities are still deeply rooted in many firmware images. We also find that the TPCs used in firmware have fallen behind by five years on average. Besides, we explore the geographical distribution of vulnerable devices, and confirm the security situation of devices in several regions, e.g., South Korea and China, is more severe than in other regions. Further analysis shows 2,478 commercial firmware images have potentially violated GPL/AGPL licensing terms.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5d21722a-d5b4-44bd-b033-2a5cf4a01644Cited by top-tier papers17
- Your Firmware Has Arrived: A Study of Firmware Update VulnerabilitiesYuhao Wu, Jinwen Wang, Yujie Wang, Shixuan Zhai et al.USENIX Security 2024 · 33 citations
- LibvDiff: Library Version Difference Guided OSS Version Identification in BinariesChaopeng Dong, Siyuan Li, Shouguo Yang, Yang Xiao et al.ICSE 2024 · 9 citations
- Accurate and Efficient Recurring Vulnerability Detection for IoT FirmwareHaoyu Xiao, Yuan Zhang, Minghang Shen, Chaoyang Lin et al.CCS 2024 · 5 citations
- Samba: Detecting SSL/TLS API Misuses in IoT Binary ApplicationsKaizheng Liu, Ming Yang, Zhen Ling, Yuan Zhang et al.INFOCOM 2024 · 3 citations
- IoTBec: An Accurate and Efficient Recurring Vulnerability Detection Framework for Black Box IoT devicesHaoran Yang, Jiaming Guo, Shuangning Yang, Guoli Zhao et al.NDSS 2026 · 3 citations
Builds on15
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard et al.USENIX Security 2017 · 2,003 citations
- Neural Network-based Graph Embedding for Cross-Platform Binary Code Similarity DetectionXiaojun Xu, Chang Liu, Qian Feng, Heng Yin et al.CCS 2017 · 682 citations
- Scalable Graph-based Bug Search for Firmware ImagesQian Feng, Rundong Zhou, Chengcheng Xu, Yao Cheng et al.CCS 2016 · 456 citations
- Asm2Vec: Boosting Static Representation Robustness for Binary Clone Search against Code Obfuscation and Compiler OptimizationSteven H. H. Ding, Benjamin C. M. Fung, Philippe CharlandS&P 2019 · 447 citations
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 428 citations
Related papers
- UVSCAN: Detecting Third-Party Component Usage Violations in IoT FirmwareBinbin Zhao, Shouling Ji, Xuhong Zhang, Yuan Tian et al.USENIX Security 2023
- Understanding Binary Code Similarity for Real-World Vulnerability Detection: A Large-Scale Empirical StudyJingdong Guo, Chaopeng Dong, Yimo Ren, Siyuan Li et al.FSE 2026
- FirmProj: Detecting Firmware Leakage in IoT Update Processes via Companion App AnalysisWenzhi Li, Jialong Guo, Jiongyi Chen, Fan Li et al.ASE 2025
- Unveiling IoT Security in Reality: A Firmware-Centric JourneyNicolas Nino, Ruibo Lu, Wei Zhou, Kyu Hyung Lee et al.USENIX Security 2024 · 12 citations
- Large-scale Security Measurements on the Android Firmware EcosystemQinsheng Hou, Wenrui Diao, Yanhao Wang, Xiaofeng Liu et al.ICSE 2022 · 21 citations
