Dynamic Analysis Tool for IoT Device
Dae-il Jang, Tae-Eun Kim, Dowon Kim · 2020
Many researches are considered when performing fuzzing, but the limitations are clear for IoT devices and services. First, we need to perform a blackbox fuzzing, and in most cases, we will not know the results unless it's a critical vulnerability such as device termination. Seconds, since many devices do not have a debugging port, it is difficult to analyze through a memory dump. For this reason, it is very difficult to find the vulnerability of the IoT device or to analyze the behavior of the test case that causes the crash. To analyze a behavior or vulnerability of IoT device, some framework exists for analyzing firmware such as Avatar and Firmadyne. However, most of analyzing tools operate firmware in a virtual environment, so there are various issues from whether firmware can be operated to data collection. In this study, we designed and developed a dynamic analysis tool for performing directly on IoT devices. We proposed a dynamic analysis framework based on STrace that works on IoT architectures such as MIPS and MIPSEL and proved that IoT vulnerabilities can be analyzed efficiently.