arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Fuzz'EMup:利用电磁侧信道发射来指导黑盒嵌入式固件模糊测试

Fuzz'EMup: Leveraging EM Side-Channel Emanation to Guide Black-Box Embedded Firmware Fuzzing

Fatemeh Moradihaghighi, Zihao Zhan, Yanan Guo, Ziming Zhao, Mashrur Chowdhury, Zhenkai Zhang

arXiv 2607.16487首次发表:更新:

AI 中文总结

针对许多设备无法获取覆盖信息只能进行低效黑盒固件模糊测试的问题,提出利用电磁侧信道发射指导模糊测试的方法,通过频带选择与动态时间规整相结合解决挑战,在四个固件目标上评估,证明该方法能提高代码覆盖率。

AI 中文摘要

随着物联网和嵌入式设备在各个领域的激增,保护其固件安全变得至关重要。模糊测试提供了一种系统方法来发现固件中的漏洞,覆盖反馈可通过引导探索来提高其有效性。然而,许多设备通过阻止固件提取、检测或精确仿真来使覆盖信息无法获取,在这种情况下,测试人员只能进行低效的黑盒模糊测试。本文提出一种利用电磁(EM)侧信道发射在纯黑盒设置中指导固件模糊测试的方法。将原始EM测量转化为可靠指导具有挑战性:EM迹线有噪声,定时抖动导致不同迹线中的相应特征在时间上偏移。我们通过基于活动与空闲信号对比度的频带选择与动态时间规整相结合来对齐每个输入迹线并检测持续差异,同时通过基于差异时间以树结构组织执行来保持可扩展性。我们在四个真实固件目标上评估了我们的方法,并证明基于EM的反馈增强了路径探索,比无引导的模糊测试产生更高的代码覆盖率。

英文摘要

As IoT and embedded devices proliferate across various domains, securing their firmware has become critical. Fuzzing offers a systematic approach to uncovering vulnerabilities in firmware, and coverage feedback can improve its effectiveness by guiding exploration. However, many devices make coverage information impossible to obtain by preventing firmware extraction, instrumentation, or accurate emulation; in such cases, testers are left with only inefficient black-box fuzzing. In this paper, we present an approach that leverages electromagnetic (EM) side-channel emanations to guide firmware fuzzing in purely black-box settings. However, turning raw EM measurements into reliable guidance is challenging: EM traces are noisy, and timing jitter causes corresponding features in different traces to shift in time. We address these challenges by combining frequency band selection based on the activity-to-idle signal contrast with dynamic time warping to align per-input traces and detect sustained divergence, while maintaining scalability by organizing executions in a tree structure based on their divergence times. We evaluate our approach on four real firmware targets and demonstrate that EM-derived feedback enhances path exploration, yielding higher code coverage than unguided fuzzing.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑