Microcontroller Based IoT System Firmware Security: Case Studies

Chao Gao, Lan Luo, Yue Zhang, Bryan Pearson, Xinwen Fu · 2019

The Internet of Things (IoT) has attracted much interest recently from the industry given its flexibility, convenience and smartness. However, security issues and exploits have become amongst the most colossal concerns for IoT. This paper studies the security of Microcontroller (MCU) based IoT firmware. Given the varieties of MCUs and their running environments, we perform case studies to exploit the flaws behind contemporary firmware upgrade models. Specifically, we validate our attacks on a popular air quality sensor from PurpleAir. We also investigate a prototype of a secure firmware upgrade system on an ATmega1284P chip. To demonstrate the attack surface of the implemented countermeasure, we discuss the potential pitfalls identified through our own practice, since these pitfalls may occur during the implementation by other manufacturers.

Read the paper · More papers on PaperTik