Bridge: High-Order Taint Vulnerabilities Detection in Linux-Based IoT Firmware
Jiaqian Peng, Puzhuo Liu, Yicheng Zeng, Kai Cheng, Yongji Liu, Yun Yang, Hongsong Zhu
Abstract
The rapid proliferation of IoT devices has led to a surge in security incidents stemming from vulnerabilities in firmware. IoT device security is critical, as failures can result in privacy breaches, system downtime, and life-threatening situations. While taint analysis has been a standard approach for detecting vulnerabilities, the increasing complexity of modern IoT devices has introduced high-order taint vulnerabilities that traditional methods cannot address. These vulnerabilities often require the coordination of multiple requests and components, making detection particularly challenging. This paper presents Bridge, a novel approach to detecting high-order taint vulnerabilities in IoT firmware. Bridge operates in three stages: identifying entry points (i.e., the initial handlers corresponding to different action requests) and taint source functions (i.e., functions for parsing user-controllable data), constructing binary dependency graphs for tainted data propagation, and constructing action dependency graphs to trace taint vulnerability triggering control relationships. Extensive evaluation on 44 real-world firmware samples demonstrates that Bridge outperforms state-of-the-art tools, detecting true positive vulnerabilities including 566 high-order vulnerabilities. Moreover, among the results, 90 vulnerabilities (including 45 high-order vulnerabilities) have been confirmed by vendors (CVE/PSV) and pose a threat to device security, including remote code execution and denial of service.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get afc9da0d-14aa-4f3f-9e29-9f4bd6f498b5Cited by top-tier papers1
Ask how each one uses itRelated papers
- Operation Mango: Scalable Discovery of Taint-Style Vulnerabilities in Binary Firmware ServicesWil Gibbs, Arvind S. Raj, Jayakrishna Menon Vadayath, Hui Jun Tay et al.USENIX Security 2024 · 20 citations
- FITS: Inferring Intermediate Taint Sources for Effective Vulnerability Analysis of IoT Device FirmwarePuzhuo Liu, Yaowen Zheng, Chengnian Sun, Chuan Qin et al.ASPLOS 2023 · 21 citations
- FirmAgent: Leveraging Fuzzing to Assist LLM Agents with IoT Firmware Vulnerability DiscoveryJiangan Ji, Chao Zhang, Shuitao Gan, Lin Jian et al.NDSS 2026 · 12 citations
- FirmCross: Detecting Taint-style Vulnerabilities in Modern C-Lua Hybrid Web Services of Linux-based FirmwareRunhao Liu, Jiarun Dai, Haoyu Xiao, Yuan Zhang et al.NDSS 2026 · 1 citation
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo et al.NDSS 2018 · 311 citations
