NetWare 2018
September 16 - 20, 2018 - Venice, Italy

  • SENSORCOMM 2018, The Twelfth International Conference on Sensor Technologies and Applications
  • SENSORDEVICES 2018, The Ninth International Conference on Sensor Device Technologies and Applications
  • SECURWARE 2018, The Twelfth International Conference on Emerging Security Information, Systems and Technologies
  • AFIN 2018, The Tenth International Conference on Advances in Future Internet
  • CENICS 2018, The Eleventh International Conference on Advances in Circuits, Electronics and Micro-electronics
  • ICQNM 2018, The Twelfth International Conference on Quantum, Nano/Bio, and Micro Technologies
  • FASSI 2018, The Fourth International Conference on Fundamentals and Advances in Software Systems Integration
  • GREEN 2018, The Third International Conference on Green Communications, Computing and Technologies

SoftNet 2018
October 14 - 18, 2018 - Nice, France

  • ICSEA 2018, The Thirteenth International Conference on Software Engineering Advances
  • ICSNC 2018, The Thirteenth International Conference on Systems and Networks Communications
  • CENTRIC 2018, The Eleventh International Conference on Advances in Human-oriented and Personalized Mechanisms, Technologies, and Services
  • VALID 2018, The Tenth International Conference on Advances in System Testing and Validation Lifecycle
  • SIMUL 2018, The Tenth International Conference on Advances in System Simulation
  • SOTICS 2018,The Eighth International Conference on Social Media Technologies, Communication, and Informatics
  • INNOV 2018, The Seventh International Conference on Communications, Computation, Networks and Technologies
  • HEALTHINFO 2018, The Third International Conference on Informatics and Assistive Technologies for Health-Care, Medical Support and Wellbeing

NexTech 2018
November 18 - 22, 2018 - Athens, Greece

  • UBICOMM 2018, The Twelfth International Conference on Mobile Ubiquitous Computing, Systems, Services and Technologies
  • ADVCOMP 2018, The Twelfth International Conference on Advanced Engineering Computing and Applications in Sciences
  • SEMAPRO 2018, The Twelfth International Conference on Advances in Semantic Processing
  • AMBIENT 2018, The Eighth International Conference on Ambient Computing, Applications, Services and Technologies
  • EMERGING 2018, The Tenth International Conference on Emerging Networks and Systems Intelligence
  • DATA ANALYTICS 2018, The Seventh International Conference on Data Analytics
  • GLOBAL HEALTH 2018, The Seventh International Conference on Global Health Challenges
  • CYBER 2018, The Third International Conference on Cyber-Technologies and Cyber-Systems

DigitalWorld 2019
February 24 - 28, 2019 - Athens, Greece

  • ICDS 2019, The Thirteenth International Conference on Digital Society and eGovernments
  • ACHI 2019, The Twelfth International Conference on Advances in Computer-Human Interactions
  • GEOProcessing 2019, The Eleventh International Conference on Advanced Geographic Information Systems, Applications, and Services
  • eTELEMED 2019, The Eleventh International Conference on eHealth, Telemedicine, and Social Medicine
  • eLmL 2019, The Eleventh International Conference on Mobile, Hybrid, and On-line Learning
  • eKNOW 2019, The Eleventh International Conference on Information, Process, and Knowledge Management
  • ALLSENSORS 2019, The Fourth International Conference on Advances in Sensors, Actuators, Metering and Sensing
  • SMART ACCESSIBILITY 2019, The Fourth International Conference on Universal Accessibility in the Internet of Things and Smart Environments

NexComm 2019
March 24 - 28, 2019 - Valencia, Spain

  • ICDT 2019, The Fourteenth International Conference on Digital Telecommunications
  • SPACOMM 2019, The Eleventh International Conference on Advances in Satellite and Space Communications
  • ICN 2019, The Eighteenth International Conference on Networks
  • ICONS 2019, The Fourteenth International Conference on Systems
  • MMEDIA 2019, The Eleventh International Conference on Advances in Multimedia
  • PESARO 2019, The Ninth International Conference on Performance, Safety and Robustness in Complex Systems and Applications
  • CTRQ 2019, The Twelfth International Conference on Communication Theory, Reliability, and Quality of Service
  • ALLDATA 2019, The Fifth International Conference on Big Data, Small Data, Linked Data and Open Data
  • SOFTENG 2019, The Fifth International Conference on Advances and Trends in Software Engineering

ComputationWorld 2019
May 5 - 9, 2019 - Venice, Italy

  • SERVICE COMPUTATION 2019, The Eleventh International Conference on Advanced Service Computing
  • CLOUD COMPUTING 2019, The Tenth International Conference on Cloud Computing, GRIDs, and Virtualization
  • FUTURE COMPUTING 2019, The Eleventh International Conference on Future Computational Technologies and Applications
  • COGNITIVE 2019, The Eleventh International Conference on Advanced Cognitive Technologies and Applications
  • ADAPTIVE 2019, The Eleventh International Conference on Adaptive and Self-Adaptive Systems and Applications
  • CONTENT 2019, The Eleventh International Conference on Creative Content Technologies
  • PATTERNS 2019, The Eleventh International Conference on Pervasive Patterns and Applications
  • COMPUTATION TOOLS 2019, The Tenth International Conference on Computational Logics, Algebras, Programming, Tools, and Benchmarking
  • BUSTECH 2019, The Ninth International Conference on Business Intelligence and Technology

InfoSys 2019
June 2 - 6, 2019 - Athens, Greece

  • ICNS 2019, The Fiteenth International Conference on Networking and Services
  • ICAS 2019, The FIfteenth International Conference on Autonomic and Autonomous Systems
  • ENERGY 2019, The Ninth International Conference on Smart Grids, Green Communications and IT Energy-aware Technologies
  • WEB 2019, The Sseventh International Conference on Building and Exploring Web Based Environments
  • DBKDA 2019, The Eleventh International Conference on Advances in Databases, Knowledge, and Data Applications
  • SIGNAL 2019, The Fourth International Conference on Advances in Signal, Image and Video Processing
  • BIOTECHNO 2019, The Eleventh International Conference on Bioinformatics, Biocomputational Systems and Biotechnologies

(to be completed)

 


ThinkMind // SECURWARE 2016, The Tenth International Conference on Emerging Security Information, Systems and Technologies // View article securware_2016_2_10_30082


Embedded Security Testing with Peripheral Device Caching and Runtime Program State Approximation

Authors:
Markus Kammerstetter
Daniel Burian
Wolfgang Kastner

Keywords: Embedded Systems; Security Analysis; State Explosion; Program Slicing; Virtual Machine Introspection

Abstract:
Today, interconnected embedded devices are widely used in the Internet of Things, in sensor networks or in security critical areas such as the automotive industry or smart grids. Security on these devices is often considered to be bad which is in part due to the challenging security testing approaches that are necessary to conduct security audits. Security researchers often turn to firmware extraction with the intention to execute the device firmware inside a virtual analysis environment. The drawback of this approach is that required peripheral devices are typically no longer accessible from within the Virtual Machine and the firmware does no longer work as intended. To improve the situation, several ways to make the actual peripheral devices accessible to software running inside an emulator have been demonstrated. Yet, a persistent problem of peripheral device forwarding approaches is the typically significant slowdown inside the analysis environment, rendering resource intense software security analysis techniques infeasible. In addition, security tests are hard to parallelize as each instance would also require its own embedded system hardware. In this work, we demonstrate an approach that could address both of these issues by utilizing a cache for peripheral device communication in combination with runtime program state approximation. We evaluated our approach utilizing well known programs from the GNU core utilities package. Our feasibility study indicates that caching of peripheral device communication in combination with runtime program state approximation might be an approach for some of the major drawbacks in embedded firmware security analysis but, similar to symbolic execution, it suffers from state explosion.

Pages: 21 to 26

Copyright: Copyright (c) IARIA, 2016

Publication date: July 24, 2016

Published in: conference

ISSN: 2162-2116

ISBN: 978-1-61208-493-0

Location: Nice, France

Dates: from July 24, 2016 to July 28, 2016

SERVICES CONTACT
2010 - 2017 © ThinkMind. All rights reserved.
Read Terms of Service and Privacy Policy.