Through the Authentication Maze: Detecting Authentication Bypass Vulnerabilities in Firmware Binaries
Nanyu Zhong, Yuekang Li, Yanyan Zou, Jiaxu Zhao, Jinwei Dong, Yang Xiao, Bingwei Peng, Yeting Li, Wei Wang, Wei Huo
摘要
—Embedded web services are widely integrated into network devices such as routers and gateways. These services are often exposed to public networks, making them attractive targets for authentication bypass attacks. Such vulnerabilities allow at-tackers to gain privileged access without valid credentials, posing serious risks to device integrity and network security. Existing detection techniques rely heavily on manual analysis or rigid heuristics, making them ineffective against diverse and evolving authentication schemes. We present AuthSpark , a novel dynamic analysis framework for detecting authentication bypass vulnerabilities in firmware binaries. AuthSpark leverages execution trace similarity between successful and failed authentication attempts to locate credential checks. It then tracks authentication-related variable propagation to identify authentication success logic. Finally, it employs a customized greybox fuzzer with task-specific power scheduling and mutation strategies to explore bypass paths. We evaluate AuthSpark on firmware from 32 real-world devices containing 14 known vulnerabilities. AuthSpark successfully identifies 42 out of 44 credential checks and detects 14 of the known vulnerabilities. More importantly, when applied to the latest firmware versions, AuthSpark discovers six zero-day authentication bypass vulnerabilities, four of which received official assignments (three CVEs and one PSV). These results highlight AuthSpark ’s effectiveness and its potential to uncover critical security flaws in real-world systems.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper12
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo 等NDSS 2018 · 被引用 311 次
- FIRM-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process EmulationYaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song 等USENIX Security 2019 · 被引用 279 次
- Snipuzz: Black-box Fuzzing of IoT Firmware via Message Snippet InferenceXiaotao Feng, Ruoxi Sun, Xiaogang Zhu, Minhui Xue 等CCS 2021 · 被引用 146 次
- Sharing More and Checking Less: Leveraging Common Input Keywords to Detect Bugs in Embedded SystemsLibo Chen, Yanhao Wang, Quanpu Cai, Yunfan Zhan 等USENIX Security 2021 · 被引用 71 次
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars 等USENIX Security 2024 · 被引用 45 次
相关 Paper
- FirmCred: Detecting Authentication Bypass Vulnerabilities in Firmware from Credential Initialization PerspectiveZiqi Wei, Haoyu Xiao, Yuan Zhang, Chi Chen 等CCS 2026
- HouseFuzz: Service-Aware Grey-Box Fuzzing for Vulnerability Detection in Linux-Based FirmwareHaoyu Xiao, Ziqi Wei, Jiarun Dai, Bowen Li 等S&P 2025
- Your Firmware Has Arrived: A Study of Firmware Update VulnerabilitiesYuhao Wu, Jinwen Wang, Yujie Wang, Shixuan Zhai 等USENIX Security 2024 · 被引用 33 次
- Karonte: Detecting Insecure Multi-binary Interactions in Embedded FirmwareNilo Redini, Aravind Machiry, Ruoyu Wang, Chad Spensky 等S&P 2020 · 被引用 128 次
- Facilitating Non-Intrusive In-Vivo Firmware Testing with Stateless InstrumentationJiameng Shi, Wenqiang Li, Wenwen Wang, Le GuanNDSS 2024
