FirmCross: Detecting Taint-style Vulnerabilities in Modern C-Lua Hybrid Web Services of Linux-based Firmware
Runhao Liu, Jiarun Dai, Haoyu Xiao, Yuan Zhang, Yeqi Mou, Lukai Xu, Bo Yu, Baosheng Wang, Min Yang
摘要
proaches [14] , [15] , [16] , [17] work by literally executing the target firmware services either through emulated environments or directly on physical devices. However, these methods face inherent challenges including labor-extensive firmware rehosting [3], [18] and limited code coverage [14] , [19] . In comparison, static approaches [10], [11], [13], [2], [20], which do not require the establishment of a dynamic execution environment, have been embraced as a complementary solution to detect vulnerabilities of IoT web services. Specifically, these works mostly leverage the taint analysis technique to accomplish this task, which involves two key phases: ❶ Source and Sink Identification pinpoints user-controllable inputs (sources) and security-sensitive operations (sinks), and ❷ Taint Propagation verifies whether attacker-controlled data can flow from sources to sinks through execution paths, causing potentially exploitable vulnerabilities. Although these static taint analysis techniques [8], [9], [2], [13], [12] , [20] have helped identify various vulnerabilities in firmware web services, they usually over-simplify the composition of firmware web services, inevitably hurting the completeness of vulnerability detection. To be more specific, existing works merely consider C-binaries (i.e., those extracted from the target firmware) as the scope of vulnerability detection. However, as highlighted in recent studies [21], [22], [23], Lua has emerged as one of the most popular languages for implementing web services [24], [25], [26], [27], [28], due to its high performance and flexibility. As demonstrated in our large-scale empirical study (see §II) on 4012 commercial device firmware, 38% firmware samples typically adopt a hybrid C-Lua framework to implement modern web services. Among these firmware, Lua scripts/bytecode are extensively leveraged to implement a wide array of functions (e.g., URI dispatching and handling). In fact, these long-neglected Luainvolved attack surfaces [29], [30] have become one of the bottlenecks in firmware security. Due to the fundamental differences between C binaries and Lua scripts/bytecode, as well as the complex cross-language interactions in C-Lua hybrid web services, existing static taint analysis approaches [8], [9], [2], [13], [12], [20] are difficult to directly apply to this scenario. Hence, in this work, we are highly motivated to re-design the taint-style Abstract-Static taint analysis has become a fundamental technique to detect vulnerabilities implied in web services of Linuxbased firmware. However, existing works commonly oversimplify the composition of firmware web services. Specifically, only C binaries (i.e., those extracted from the target firmware) are considered within the scope of vulnerability detection. In this work, we observe that modern firmware e xtensively combines Lua scripts/bytecode and C binaries to implement hybrid web services, and obviously, those C-binary-oriented vulnerability detection techniques can hardly achieve satisfactory performance. In light of this, we propose FirmCross, an automated taint-style vulnerability detector dedicated for C-Lua hybrid web services. Compared to existing detectors, FirmCross can automatically deobfuscate the Lua bytecode in target firmware, additionally identify distinctive taint sources in Lua codespace, and systematically capture the C-Lua cross-language taint flow. In the evaluation, FirmCross detects 6.82X ˜ 14.5X more vulnerabilities than SoTA approaches (i.e., MangoDFA and LuaTaint) in a dataset containing 73 firmware images from 11 vendors. Notably, FirmCross helps identify 610 0-day vulnerabilities among target firmware images. After reporting these vulnerabilities to vendors, till now, 31 vulnerability IDs have been assigned.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper24
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 被引用 428 次
- Snipuzz: Black-box Fuzzing of IoT Firmware via Message Snippet InferenceXiaotao Feng, Ruoxi Sun, Xiaogang Zhu, Minhui Xue 等CCS 2021 · 被引用 146 次
- Karonte: Detecting Insecure Multi-binary Interactions in Embedded FirmwareNilo Redini, Aravind Machiry, Ruoyu Wang, Chad Spensky 等S&P 2020 · 被引用 128 次
- Typestate-guided fuzzer for discovering use-after-free vulnerabilitiesHaijun Wang, Xiaofei Xie, Yi Li, Cheng Wen 等ICSE 2020 · 被引用 107 次
- JN-SAF: Precise and Efficient NDK/JNI-aware Inter-language Static Analysis Framework for Security Vetting of Android Applications with Native CodeFengguo Wei, Xingwei Lin, Xinming Ou, Ting Chen 等CCS 2018 · 被引用 93 次
相关 Paper
- FirmAgent: Leveraging Fuzzing to Assist LLM Agents with IoT Firmware Vulnerability DiscoveryJiangan Ji, Chao Zhang, Shuitao Gan, Lin Jian 等NDSS 2026 · 被引用 12 次
- Bridge: High-Order Taint Vulnerabilities Detection in Linux-Based IoT FirmwareJiaqian Peng, Puzhuo Liu, Yicheng Zeng, Kai Cheng 等S&P 2026 · 被引用 1 次
- Accurate and Efficient Recurring Vulnerability Detection for IoT FirmwareHaoyu Xiao, Yuan Zhang, Minghang Shen, Chaoyang Lin 等CCS 2024 · 被引用 5 次
- Operation Mango: Scalable Discovery of Taint-Style Vulnerabilities in Binary Firmware ServicesWil Gibbs, Arvind S. Raj, Jayakrishna Menon Vadayath, Hui Jun Tay 等USENIX Security 2024 · 被引用 20 次
- Sharing More and Checking Less: Leveraging Common Input Keywords to Detect Bugs in Embedded SystemsLibo Chen, Yanhao Wang, Quanpu Cai, Yunfan Zhan 等USENIX Security 2021 · 被引用 71 次
