FFXE: Dynamic Control Flow Graph Recovery for Embedded Firmware Binaries
Ryan Tsang, Asmita, Doreen Joseph, Soheil Salehi, Prasant Mohapatra, Houman Homayoun
摘要
Control Flow Graphs (CFG) play a significant role as an intermediary analysis in many advanced static and dynamic software analysis techniques. As firmware security and validation for embedded systems becomes a greater concern, accurate CFGs for embedded firmware binaries are crucial for adapting many valuable software analysis techniques to firmware, which can enable more thorough functionality and security analysis. In this work, we present a portable new dynamic CFG recovery technique based on dynamic forced execution that allows us to resolve indirect branches to registered callback functions, which are dependent on asynchronous changes to volatile memory. Our implementation, the Forced Firmware Execution Engine (FFXE), written in Python using the Unicorn emulation framework, is able to identify 100% of known callback functions in our test set of 36 firmware images, something none of the other techniques we tested against were able to do reliably. Using our results and observations, we compare our engine to 4 other CFG recovery techniques and provide both our thoughts on how this work might enhance other tools, and how it might be further developed. With our contributions, we hope to help enable the application of traditionally software-focused security analysis techniques to the hardware interactions that are integral to embedded system firmware.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper5
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- FirmXRay: Detecting Bluetooth Link Layer Vulnerabilities From Bare-Metal FirmwareHaohuang Wen, Zhiqiang Lin, Yinqian ZhangCCS 2020 · 被引用 47 次
- PMP: Cost-effective Forced Execution with Probabilistic Memory Pre-planningWei You, Zhuo Zhang, Yonghwi Kwon, Yousra Aafer 等S&P 2020 · 被引用 29 次
- Ground Truth for Binary Disassembly is Not EasyChengbin Pang, Tiantai Zhang, Ruotong Yu, Bing Mao 等USENIX Security 2022
- Refining Indirect Call Targets at the Binary LevelSun Hyoung Kim, Cong Sun, Dongrui Zeng, Gang TanNDSS 2021
相关 Paper
- Semantics-Guided Control-Flow Reconstruction for Firmware Binaries via Static AnalysisFengjuan Gao, Qingjie Zhu, Yi Zhang, Yu Wang 等FSE 2026
- FirmSolo: Enabling dynamic analysis of binary Linux-based IoT kernel modulesIoannis Angelakopoulos, Gianluca Stringhini, Manuel EgeleUSENIX Security 2023
- Inception: System-Wide Security Testing of Real-World Embedded Systems SoftwareNassim Corteggiani, Giovanni Camurati, Aurélien FrancillonUSENIX Security 2018 · 被引用 117 次
- FirmGuide: Boosting the Capability of Rehosting Embedded Linux Kernels through Model-Guided Kernel ExecutionQiang Liu, Cen Zhang, Lin Ma, Muhui Jiang 等ASE 2021 · 被引用 10 次
- CO3: Concolic Co-execution for FirmwareChangming Liu, Alejandro Mera, Engin Kirda, Meng Xu 等USENIX Security 2024 · 被引用 7 次
