CASIA OpenIR  > 学术期刊  > IEEE/CAA Journal of Automatica Sinica
Detecting Vulnerability on IoT Device Firmware: A Survey
Xiaotao Feng; Xiaogang Zhu; Qing-Long Han; Wei Zhou; Sheng Wen; Yang Xiang
发表期刊IEEE/CAA Journal of Automatica Sinica
ISSN2329-9266
2023
卷号10期号:1页码:25-41
摘要Internet of things (IoT) devices make up 30% of all network-connected endpoints, introducing vulnerabilities and novel attacks that make many companies as primary targets for cybercriminals. To address this increasing threat surface, every organization deploying IoT devices needs to consider security risks to ensure those devices are secure and trusted. Among all the solutions for security risks, firmware security analysis is essential to fix software bugs, patch vulnerabilities, or add new security features to protect users of those vulnerable devices. However, firmware security analysis has never been an easy job due to the diversity of the execution environment and the close source of firmware. These two distinct features complicate the operations to unpack firmware samples for detailed analysis. They also make it difficult to create visual environments to emulate the running of device firmware. Although researchers have developed many novel methods to overcome various challenges in the past decade, critical barriers impede firmware security analysis in practice. Therefore, this survey is motivated to systematically review and analyze the research challenges and their solutions, considering both breadth and depth. Specifically, based on the analysis perspectives, various methods that perform security analysis on IoT devices are introduced and classified into four categories. The challenges in each category are discussed in detail, and potential solutions are proposed subsequently. We then discuss the flaws of these solutions and provide future directions for this research field. This survey can be utilized by a broad range of readers, including software developers, cyber security researchers, and software security engineers, to better understand firmware security analysis.
关键词Firmware emulation internet of things (IoT) firmware network fuzzing security static analysis
DOI10.1109/JAS.2022.105860
引用统计
被引频次:32[WOS]   [WOS记录]     [WOS相关记录]
文献类型期刊论文
条目标识符http://ir.ia.ac.cn/handle/173211/50725
专题学术期刊_IEEE/CAA Journal of Automatica Sinica
推荐引用方式
GB/T 7714
Xiaotao Feng,Xiaogang Zhu,Qing-Long Han,et al. Detecting Vulnerability on IoT Device Firmware: A Survey[J]. IEEE/CAA Journal of Automatica Sinica,2023,10(1):25-41.
APA Xiaotao Feng,Xiaogang Zhu,Qing-Long Han,Wei Zhou,Sheng Wen,&Yang Xiang.(2023).Detecting Vulnerability on IoT Device Firmware: A Survey.IEEE/CAA Journal of Automatica Sinica,10(1),25-41.
MLA Xiaotao Feng,et al."Detecting Vulnerability on IoT Device Firmware: A Survey".IEEE/CAA Journal of Automatica Sinica 10.1(2023):25-41.
条目包含的文件 下载所有文件
文件名称/大小 文献类型 版本类型 开放类型 使用许可
JAS-2022-0767.pdf(3134KB)期刊论文出版稿开放获取CC BY-NC-SA浏览 下载
个性服务
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Xiaotao Feng]的文章
[Xiaogang Zhu]的文章
[Qing-Long Han]的文章
百度学术
百度学术中相似的文章
[Xiaotao Feng]的文章
[Xiaogang Zhu]的文章
[Qing-Long Han]的文章
必应学术
必应学术中相似的文章
[Xiaotao Feng]的文章
[Xiaogang Zhu]的文章
[Qing-Long Han]的文章
相关权益政策
暂无数据
收藏/分享
文件名: JAS-2022-0767.pdf
格式: Adobe PDF
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。