Off-the-shelf Embedded Devices as Platforms for Security Research
Lucian Cojocar, Kaveh Razavi, Herbert Bos · 2017
With increasing concerns about the security and trustworthiness of embedded devices, the importance of research on their firmware is growing. Unfortunately, researchers with new ideas for improving the security of these devices (e.g., fuzzing) or studying adversarial scenarios (e.g., malware) face massive hurdles when applying them to actual hardware. To conduct realistic experiments, we need real-world hardware that can be easily used for security research. Unfortunately, such devices are scarce and depend entirely on efforts by the hacker community. In this paper, we describe two new devices that we have opened up, a programmable logic controller (PLC) and a solid sate drive (SSD). These two types of devices have not been previously reverse engineered and they are both interesting cases given the recent developments on the security of embedded devices and the rise of Internet of Things. We discuss possible new directions with these two "real-world" research platforms. We further make the results of our efforts available to the security community in order to make it easier to get started in this research area.