电力物联网固件漏洞检测的模糊测试引导技术

Bo Zhang, Zesheng Xi, Kunlun Gao
{"title":"电力物联网固件漏洞检测的模糊测试引导技术","authors":"Bo Zhang, Zesheng Xi, Kunlun Gao","doi":"10.1109/ICEI52466.2021.00033","DOIUrl":null,"url":null,"abstract":"The power Internet of Things has become an important part of the energy Internet, and firmware is its enabling software. The existence of firmware vulnerability is one of the fundamental reasons for smart grid to face network attacks, so detecting firmware vulnerability is the key to smart grid security. Fuzzy testing is one of the hotspots of cyberspace security research, but for firmware vulnerability detection, there are still some problems in current fuzzy testing technology, such as poor compatibility of heterogeneous firmware program simulation, firmware state space explosion and blind testing, which lead to poor efficiency and effectiveness of vulnerability detection. In order to solve the above problems, this paper proposes the technology of static instruction translation and program reconfiguration for heterogeneous firmware programs, and reconstructs heterogeneous firmware programs into cross platform executable programs through intermediate language translation. At the same time, a fuzzy test method based on static targeting model and dynamic symbol execution is proposed to further improve the guidance, intelligence, accuracy and automation of firmware vulnerability fuzzy test technology.","PeriodicalId":113203,"journal":{"name":"2021 IEEE International Conference on Energy Internet (ICEI)","volume":"7 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Fuzzy Test Guidance Technology for Power Internet of Things Firmware Vulnerability Detection\",\"authors\":\"Bo Zhang, Zesheng Xi, Kunlun Gao\",\"doi\":\"10.1109/ICEI52466.2021.00033\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The power Internet of Things has become an important part of the energy Internet, and firmware is its enabling software. The existence of firmware vulnerability is one of the fundamental reasons for smart grid to face network attacks, so detecting firmware vulnerability is the key to smart grid security. Fuzzy testing is one of the hotspots of cyberspace security research, but for firmware vulnerability detection, there are still some problems in current fuzzy testing technology, such as poor compatibility of heterogeneous firmware program simulation, firmware state space explosion and blind testing, which lead to poor efficiency and effectiveness of vulnerability detection. In order to solve the above problems, this paper proposes the technology of static instruction translation and program reconfiguration for heterogeneous firmware programs, and reconstructs heterogeneous firmware programs into cross platform executable programs through intermediate language translation. At the same time, a fuzzy test method based on static targeting model and dynamic symbol execution is proposed to further improve the guidance, intelligence, accuracy and automation of firmware vulnerability fuzzy test technology.\",\"PeriodicalId\":113203,\"journal\":{\"name\":\"2021 IEEE International Conference on Energy Internet (ICEI)\",\"volume\":\"7 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-09-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2021 IEEE International Conference on Energy Internet (ICEI)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICEI52466.2021.00033\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE International Conference on Energy Internet (ICEI)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICEI52466.2021.00033","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

摘要

电力物联网已成为能源互联网的重要组成部分,而固件是其使能软件。固件漏洞的存在是智能电网面临网络攻击的根本原因之一,因此固件漏洞检测是智能电网安全的关键。模糊测试是网络空间安全研究的热点之一,但对于固件漏洞检测,目前的模糊测试技术还存在异构固件程序仿真兼容性差、固件状态空间爆炸、盲测等问题,导致漏洞检测效率和有效性不高。为了解决上述问题,本文提出了异构固件程序的静态指令翻译和程序重构技术,通过中间语言翻译将异构固件程序重构为跨平台可执行程序。同时,提出了基于静态目标模型和动态符号执行的模糊测试方法,进一步提高了固件漏洞模糊测试技术的导向性、智能性、准确性和自动化程度。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Fuzzy Test Guidance Technology for Power Internet of Things Firmware Vulnerability Detection
The power Internet of Things has become an important part of the energy Internet, and firmware is its enabling software. The existence of firmware vulnerability is one of the fundamental reasons for smart grid to face network attacks, so detecting firmware vulnerability is the key to smart grid security. Fuzzy testing is one of the hotspots of cyberspace security research, but for firmware vulnerability detection, there are still some problems in current fuzzy testing technology, such as poor compatibility of heterogeneous firmware program simulation, firmware state space explosion and blind testing, which lead to poor efficiency and effectiveness of vulnerability detection. In order to solve the above problems, this paper proposes the technology of static instruction translation and program reconfiguration for heterogeneous firmware programs, and reconstructs heterogeneous firmware programs into cross platform executable programs through intermediate language translation. At the same time, a fuzzy test method based on static targeting model and dynamic symbol execution is proposed to further improve the guidance, intelligence, accuracy and automation of firmware vulnerability fuzzy test technology.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信