Responsible Disclosure is a Two-Way Street: Empirically Measuring the Responsible Disclosure Contract in the Firmware Ecosystem
Hui Jun Tay, Souradip Nath, Arvind S. Raj, Abhay Bhat, Ishan Bansal, Audrey Dutcher, Moritz Schloegel, Adam Doupé, Tiffany Bao, Yan Shoshitaishvili, Ruoyu Wang
摘要
Responsible disclosure is the process by which researchers and vendors cooperate to release information on newly discovered vulnerabilities to the public in an ethically responsible manner. Proper vulnerability disclosure is especially important for the security of embedded firmware in Internetof-Things, where a single exploit often impacts thousands of consumer devices.
The current prevalent belief is that disclosing vulnerabilities on some devices is better than not bringing up observed vulnerabilities at all, leaving us with an unknown set of potentially affected devices. Implicitly, this assumes that the potential vulnerability impact of these "invisible" devices is minimal relative to the rest of the publicized set. Should this assumption prove false, a partial reporting of vulnerable devices would conversely pose a greater security risk, as malicious actors can trivially use released exploits to target the invisible devices.
In this paper, we seek to quantify the degree to which such vulnerable devices are overlooked during responsible disclosure. We provide a lower-bound estimate of the security impact these "invisible" yet vulnerable devices have for endusers. To this end, we model the disclosure process and develop an automated pipeline, BucketLeak, to run a collection of 54 vulnerability exploitation scripts from the years 2010-2025 against a large-scale dataset of 3,569 firmware images belonging to 566 router and camera devices. Our pipeline uncovers 467 unique device-exploit pairs (DevExPairs), of which 422 are undisclosed potential N-days that correspond to 290 device models still in circulation. Furthermore, 181 of the models with undisclosed vulnerabilities are still vulnerable even with the latest versions of their firmware installed. By scanning the Internet-of-Things with ZoomEye, we find that these 181 vulnerable yet undisclosed devices have more than 1.04 million real-world device counterparts still active and discoverable over the public Internet.
- Edge cases exist and require careful consideration before action [34]. 2. Also called coordinated disclosure, although the "charged" term responsible has seemingly won out, at least in academic circles.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper12
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard 等USENIX Security 2017 · 被引用 2,003 次
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 被引用 428 次
- Karonte: Detecting Insecure Multi-binary Interactions in Embedded FirmwareNilo Redini, Aravind Machiry, Ruoyu Wang, Chad Spensky 等S&P 2020 · 被引用 128 次
- Automatic Firmware Emulation through Invalidity-guided Knowledge InferenceWei Zhou, Le Guan, Peng Liu, Yuqing ZhangUSENIX Security 2021 · 被引用 76 次
- Efficient greybox fuzzing of applications in Linux-based IoT devices via enhanced user-mode emulationYaowen Zheng, Yuekang Li, Cen Zhang, Hongsong Zhu 等ISSTA 2022 · 被引用 34 次
相关 Paper
- Your Firmware Has Arrived: A Study of Firmware Update VulnerabilitiesYuhao Wu, Jinwen Wang, Yujie Wang, Shixuan Zhai 等USENIX Security 2024 · 被引用 33 次
- Vulnerability, Where Art Thou? An Investigation of Vulnerability Management in Android Smartphone ChipsetsDaniel Klischies, Philipp Mackensen, Veelasha MoonsamyNDSS 2025
- Accurate and Efficient Recurring Vulnerability Detection for IoT FirmwareHaoyu Xiao, Yuan Zhang, Minghang Shen, Chaoyang Lin 等CCS 2024 · 被引用 5 次
- Game of Hide-and-Seek: Exposing Hidden Interfaces in Embedded Web Applications of IoT DevicesWei Xie, Jiongyi Chen, Zhenhua Wang, Chao Feng 等WWW 2022 · 被引用 26 次
- Patchy Performance? Uncovering the Vulnerability Management Practices of IoT-Centric VendorsSandra Rivera Pérez, Michel van Eeten, Carlos Hernandez GañánS&P 2024 · 被引用 3 次
