Hardcoded Vulnerability Mining Method in a Simulated Environment Based on Router Backdoor Detection Technology
Songming Han, Jieke Lu, Shaofeng Ming · 2024
To solve the problem of hardcoded backdoor detection, this paper combines the idea of taint analysis, divides different paths in the function control flow into two sets based on the return value: the succeeded verification path set and the failed verification path set, and determines to only conduct semantic conflict analysis on the succeeded verification path set. On the above basis, a hardcoded backdoor detection method based on semantic conflict — the Select is proposed in this paper. The Select identifies the hardcoded backdoor in the firmware based on the commonly used string comparison functions, the characteristics of the MIPS and ARM instruction sets, the calling relation between functions, the control flow graph (CFG), and string dependencies for branch selection.