Validation of Firmware Security using Fuzzing and Penetration Methodologies

Mahesh Sarikonda, R. Shanmughasundaram · 2022

Firmware is the area where hackers embed malware and other malicious code into it. The main reason for a hacker to target firmware is, malware injected can gain complete access over the latest generation systems. The most vulnerable area in firmware includes System Management Mode (SMM) code injection, Data tampering, Unauthorized access, and Information disclosure. To maintain integrity of the firmware, it should securely perform updates. This paper focusses on fuzzing and penetration testing where a firmware is validated for security vulnerabilities. The Fuzz Modules used are Unified Extensible Firmware Interface (UEFI) Variable Fuzzing, Input-Output (IO) Fuzzing, Model Specific Register (MSR) Fuzzing and CPU ID Fuzzing. Security Validation of firmware is carried out using CHIPSEC tool. Experimental results show that fuzzing of invalid parameters result in standard kernel error codes and Blue Screen of Death (BSoD) or system crash at different offset regions of MSR's, IO Ports. Each module is randomly or sequentially fuzzed with values 0×00 to 0×FF for 1000 iterations. The penetration test is performed at various vulnerable regions that observed using Fuzz modules and manually writes random/invalid data to the failed registers/ports.

Read the paper · More papers on PaperTik