Precise Discovery of More Taint-Style Vulnerabilities in Embedded Firmware

Xiaokang Yin, Ruijie Cai, Xiaoya Zhu, Qichao Yang, Enzhou Song, Shengli Liu · IEEE Transactions on Dependable and Secure Computing · 2024

The proliferation of taint-style vulnerabilities in embedded devices poses a significant threat to cybersecurity. However, discovering these vulnerabilities is challenging due to their vast number and variety. While current solutions for discovering vulnerabilities in embedded firmware have achieved some success, they suffer from imprecision, are time-consuming, and fail to consider sensitive sinks and constraints. To address these challenges, we propose a novel taint-style vulnerability discovery method called SinkTaint. SinkTaint incorporates backtracking and constraint analysis to achieve high precision and employs a global taint keyword identification strategy to identify implicit taint keywords. It identifies additional sinks using static analysis and performs backtracking analysis to eliminate sanitized sinks, while retrieving the parameter's length for risky sinks. Furthermore, SinkTaint employs dual-label labeling strategies for taint keywords and data, propagating taint labels based on function return values. Finally, SinkTaint employs symbolic execution-based taint analysis to discover taint-style vulnerabilities. We evaluate SinkTaint on datasets released by SaTC and 10 known overflow vulnerabilities. Compared to state-of-the-art methods, including Karonte, SaTC, and EmTaint, SinkTaint demonstrated superior performance, discovering more vulnerabilities with an increase in vulnerability discovery effectiveness by 472%. To date, SinkTaint has identified 21 high-risk taint-style vulnerabilities that were previously undisclosed.

Read the paper · More papers on PaperTik