IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based Fuzzing
Jiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo, Zhiqiang Lin, Xiaofeng Wang, Wing Cheong Lau, Menghan Sun, Ronghai Yang, Kehuan Zhang · 2018
With more IoT devices entering the consumer market, it becomes imperative to detect their security vulnerabilities before an attacker does.Existing binary analysis based approaches only work on firmware, which is less accessible except for those equipped with special tools for extracting the code from the device.To address this challenge in IoT security analysis, we present in this paper a novel automatic fuzzing framework, called IOTFUZZER, which aims at finding memory corruption vulnerabilities in IoT devices without access to their firmware images.The key idea is based upon the observation that most IoT devices are controlled through their official mobile apps, and such an app often contains rich information about the protocol it uses to communicate with its device.Therefore, by identifying and reusing program-specific logic (e.g., encryption) to mutate the test case (particularly message fields), we are able to effectively probe IoT targets without relying on any knowledge about its protocol specifications.In our research, we implemented IOTFUZZER and evaluated 17 real-world IoT devices running on different protocols, and our approach successfully identified 15 memory corruption vulnerabilities (including 8 previously unknown ones).Responsible Disclosure: All vulnerabilities described in this paper have been reported to the corresponding vendors.reported [48], with devastating consequences in some of them.A prominent example is the Mirai attack [32], which turns a large number of online IoT devices (e.g., IP cameras and home routers) into bots for launching DDoS attacks against online services.Given the pervasiveness of vulnerable devices, we strongly believe that these known attacks are nothing but a tip of the iceberg.An important target of IoT attacks is implementation flaws (or security vulnerabilities) within a device's firmware.Systematic detection of these flaws needs to address a few challenges.The primary one is the difficulty in firmware acquisition because many vendors do not make their firmware images publicly available.Alternatively, we can dump images from the motherboard, which, however, needs the support from enabled debugging ports, which may not exist for many IoT devices, due to their simplicity.In addition, given the diversity of compression (even encryption) formats, how to unpack the obtained firmware is nontrivial as well.When it comes to the security analysis of the files extracted from firmware, the main challenge comes from diverse underlying architectures (memory layout, instruction set, and so forth).Existing techniques mainly rely on emulation for certain architectures [23], [17], [13].However, the programs running in the emulator will frequently crash due to unavailable NVRAM parameters.Some other related studies utilize symbolic execution to analyze firmware.This attempt is also impeded by the architecture issue.For example, FIE [21] only supports the security analysis of firmware images built on the TI MSP430 microcontroller family, and FirmUSB [31] only supports 8051 architecture.Our Approach.Unlike traditional embedded devices, most IoT devices are controlled by users through mobile applications (IoT app for short).Such an IoT app is designed to act as its device's phone-side control panel, and therefore carries rich information about the device, particularly the way to talk to its firmware.Examples of such information include command (seed) messages, URLs, and encryption/decryption schemes that embedded in the app.Based on this observation, in this paper, we present IOTFUZZER, an automatic, blackbox fuzzing framework designed specifically for detecting memory-corruption flaws in IoT firmware.A unique property of IOTFUZZER is that it runs a protocol-guided fuzz and utilizes the information carried by the IoT app without reverse-