I can detect you: Using intrusion checkers to resist malicious firmware attacks
Devu Manikantan Shila, Penghe Geng, T. Lovett · 2016
Recent attacks on embedded devices, ranging from garage door openers, home thermostats, home automation systems to automobiles, have identified remote exploit vulnerabilities as one of the major attack vectors. According to OWASP Internet of Things project, these vulnerabilities are due to insecure web interfaces, insufficient authentication and authorization, insufficient transport layer protection, broken cryptography, insecure software/firmware updates, or poor physical security. This effort considers such a remote exploit attack vector on Internet-connected embedded devices where an adversary utilizes commonly seen remotely exploitable vulnerabilities such as improper input validation or insecure firmware updates to execute malicious code on these devices (called as remote code execution). Due to the lack of efficient and robust approaches for detecting these complex malicious remote code execution attacks, we propose to embed light weight intrusion-defense capability called Intrusion Checkers within the embedded firmware by employing source code instrumentation techniques. Unlike existing approaches that requires an understanding of exploit characteristics, Intrusion Checkers is based on detecting anomalous operations by comparing the current execution behavior of firmware with the past recurrent execution behavior. Any deviation, based on a user-defined threshold, from the past recurrent behavior of the firmware will be flagged by Intrusion Checkers as anomalous. We evaluated the security performance of Intrusion Checkers by executing a complex code reuse attack on vulnerable system library function. Our approach were able to detect the attack with negligible latency. We also evaluated the overhead by applying the Intrusion Checkers on four example firmware/programs and observed that our approach produces unnoticeable overhead when applied to computationally less intensive operations.