OctopusTaint: Advanced Data Flow Analysis for Detecting Taint-Based Vulnerabilities in IoT/IIoT Firmware
Abdullah Qasem, Mourad Debbabi, Andrei Soeanu
摘要
The widespread integration of Internet of Things (IoT) and Industrial IoT (IIoT) devices in respectively home and business environments offers both benefits and perils. While these devices, such as IP cameras and network routers improve operational efficiency with their user-friendly web interfaces, they also broaden the potential for cybersecurity vulnerabilities. Recent studies highlight the vulnerability of these devices to taint-based attacks, demonstrating that even attackers with limited permissions can gain control of a device. Current state-of-the-art solutions for mitigating these risks primarily utilize Dynamic Symbolic Execution (DSE). Although effective, DSE is computationally costly and challenging for large-scale analysis. Besides, during inspection, these approaches typically exhibit over-taint behavior by producing a large number of alerts, many of which are false positives due to ineffective handling of sanitization measures that might be in place. To overcome these limitations, we introduce OctopusTaint, an innovative static-based taint analysis approach that integrates advanced data flow analysis with backtracking techniques. OctopusTaint is distinguished by its integration of a sanitization inspection module and sophisticated post-processing filters. These features are specifically designed to minimize false positives effectively while ensuring the accurate identification of genuine security threats. OctopusTaint also excels in tracking transformed tainted inputs across NVRAM, identifying new user-defined taint source functions while addressing the challenges associated with indirect calls and aliasing. Through comparative performance evaluations, OctopusTaint demonstrates superior performance over the current state-of-the-art solutions, SaTC, EmTaint, and MangoDFA. It reports genuine extra tainted sinks in considerable less time (24% faster). Furthermore, OctopusTaint identifies 82% of tainted sinks within EmTaint 's labeled dataset while exhibiting its advanced capability in sanitization inspection. It correctly flags as sanitized 320 sinks, which were misidentified as genuine alerts by EmTaint. Furthermore, OctopusTaint uncovers additional candidates overlooked by EmTaint, leveraging its enhanced detection mechanisms for new taint sources. OctopusTaint successfully identifies 142 n -day vulnerabilities previously reported by SaTC and EmTaint, in addition to discovering dozens of potential 0-day candidates.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper6
- FirmAgent: Leveraging Fuzzing to Assist LLM Agents with IoT Firmware Vulnerability DiscoveryJiangan Ji, Chao Zhang, Shuitao Gan, Lin Jian 等NDSS 2026 · 被引用 12 次
- User-Space Dependency-Aware Rehosting for Linux-Based Firmware BinariesChuan Qin, Cen Zhang, Yaowen Zheng, Puzhuo Liu 等NDSS 2026 · 被引用 2 次
- FirmCross: Detecting Taint-style Vulnerabilities in Modern C-Lua Hybrid Web Services of Linux-based FirmwareRunhao Liu, Jiarun Dai, Haoyu Xiao, Yuan Zhang 等NDSS 2026 · 被引用 1 次
- Bond: Constraint-Directed Fuzzing for Automated Validation of Taint Analysis Results in Linux-based IoT FirmwareJiaqian Peng, Puzhuo Liu, Kai Cheng, Zhaoteng Yan 等USENIX Security 2026
- Firmenstein: Scaling Dynamic Analysis for Linux-Based Firmware Services via API-Centric Intervention Code SynthesisYanzhong Wang, Wenhui Zhang, Ruigang Liang, Kai Chen 等USENIX Security 2026
相关 Paper
- Detecting Vulnerabilities in Linux-Based Embedded Firmware with SSE-Based On-Demand Alias AnalysisKai Cheng, Yaowen Zheng, Tao Liu, Le Guan 等ISSTA 2023 · 被引用 28 次
- Faster and Better: Detecting Vulnerabilities in Linux-based IoT Firmware with Optimized Reaching Definition AnalysisZicong Gao, Chao Zhang, Hangtian Liu, Wenhou Sun 等NDSS 2024
- Operation Mango: Scalable Discovery of Taint-Style Vulnerabilities in Binary Firmware ServicesWil Gibbs, Arvind S. Raj, Jayakrishna Menon Vadayath, Hui Jun Tay 等USENIX Security 2024 · 被引用 20 次
- Bridge: High-Order Taint Vulnerabilities Detection in Linux-Based IoT FirmwareJiaqian Peng, Puzhuo Liu, Yicheng Zeng, Kai Cheng 等S&P 2026 · 被引用 1 次
- AirTaint: Making Dynamic Taint Analysis Faster and EasierQian Sang, Yanhao Wang, Yuwei Liu, Xiangkun Jia 等S&P 2024 · 被引用 11 次
