Research on Security Detection Technology of IoT Device Based on AFL
Jingjian He, Yingying Liu, Jianchu Xiao, Yuhang Shen · 2021
With the explosive growth of the number of IoT devices, firmware security have become increasingly serious. Obstacles such as closed source, large number, and high hardware dependence make effective fuzzing techniques perform poorly in the field of firmware vulnerability detection. The main problems are difficult firmware simulation and low throughput. Firm-AFL has initially solved the throughput problem of AFL under firmware system-level simulation by combining Firmadyne and AFL, but there is still room for improvement in efficiency. Through the research on the Firm-AFL test mechanism, we proposes a hash-based active synchronization fuzzing method based on the two defects of synchronous test case passive and test case duplication in AFL parallel mode, which can effectively reduce the cost of synchronous test cases, Shortenshorten the crash generation time. Through experimental tests, the method requires a shorter time to trigger a crash compared to the traditional parallel mode of Firm-AFL, and the queue quality is higher, which makes the overall fuzzing test optimized, and the vulnerability detection efficiency for firmware is higher.