Skip to main content
QUICK REVIEW

[論文レビュー] A Measurement Study on the (In)security of End-of-Life (EoL) Embedded Devices

Dingding Wang, Muhui Jiang|arXiv (Cornell University)|May 29, 2021
Advanced Malware Detection Techniques参考文献 25被引用数 5
ひとこと要約

本研究では、サイバースペース検索エンジンとファームウェア分析を用いて、エンド・オブ・ライフ(EoL)機器の最初の測定を実施し、稼働中のEoL機器を特定し、その脆弱性を評価した。200万件を超える稼働中のEoL機器が検出され、そのうち100万件以上が脆弱であることが判明。そのうち約半数が深刻度の高い脆弱性にさらわれており、コマンドインジェクションを介したDDoS攻撃で2.79 Tbpsを超える攻撃の可能性がある。

ABSTRACT

Embedded devices are becoming popular. Meanwhile, researchers are actively working on improving the security of embedded devices. However, previous work ignores the insecurity caused by a special category of devices, i.e., the End-of-Life (EoL in short) devices. Once a product becomes End-of-Life, vendors tend to no longer maintain its firmware or software, including providing bug fixes and security patches. This makes EoL devices susceptible to attacks. For instance, a report showed that an EoL model with thousands of active devices was exploited to redirect web traffic for malicious purposes. In this paper, we conduct the first measurement study to shed light on the (in)security of EoL devices. To this end, our study performs two types of analysis, including the aliveness analysis and the vulnerability analysis. The first one aims to detect the scale of EoL devices that are still alive. The second one is to evaluate the vulnerabilities existing in (active) EoL devices. We have applied our approach to a large number of EoL models from three vendors (i.e., D-Link, Tp-Link, and Netgear) and detect the alive devices in a time period of ten months. Our study reveals some worrisome facts that were unknown by the community. For instance, there exist more than 2 million active EoL devices. Nearly 300,000 of them are still alive even after five years since they became EoL. Although vendors may release security patches after the EoL date, however, the process is ad hoc and incomplete. As a result, more than 1 million active EoL devices are vulnerable, and nearly half of them are threatened by high-risk vulnerabilities. Attackers can achieve a minimum of 2.79 Tbps DDoS attack by compromising a large number of active EoL devices. We believe these facts pose a clear call for more attention to deal with the security issues of EoL devices.

研究の動機と目的

  • インターネットに接続されたままのエンド・オブ・ライフ(EoL)埋め込み機器の規模と持続性を調査すること。
  • ベンダー支援終了後に残存するEoL機器に存在する脆弱性の有無と深刻度を評価すること。
  • セキュリティパッチの提供が停止しているため、EoL機器が攻撃の対象として依然として危険にさらされているかどうかを評価すること。
  • 脆弱なEoL機器を用いた大規模なボットネット形成の可能性を定量的に評価すること。

提案手法

  • 10か月にわたり継続的なスキャンを実施し、特にZoomEyeを活用したサイバースペース検索エンジンを用いて、稼働中のEoL機器を検出する。
  • ネットワークプローブへの応答を確認することで、EoL機器が実際に稼働しているかを特定するアライブ分析を実施する。
  • 公開リソース(例:CVE、NVD)およびベンダーのリリースノートから脆弱性を収集し、既知の欠陥を同定する。
  • FIRMADYNE、IDA Pro、Ghidraを用いた動的および静的ファームウェア分析により、脆弱性の存在を検証する。
  • EoLステータスをファームウェアイメージにマッピングし、パッチの入手可能性とリリースタイムラインを分析する。
  • 倫理的な研究ガイドラインに従い、IPアドレスを匿名化し、悪用を防ぐために非機密データのみを公開した。

実験結果

リサーチクエスチョン

  • RQ1エンド・オブ・ライフ(EoL)埋め込み機器のうち、どれだけが依然としてインターネットに接続されて稼働しているか?
  • RQ2EoL日付以降に、稼働中のEoL機器に存在する脆弱性の頻度と深刻度はどの程度か?
  • RQ3EoL日付以降に、ベンダーからセキュリティパッチが提供されることがあるのか?もしあるなら、そのプロセスはどれほど完全で迅速か?
  • RQ4稼働中のEoL機器が改ざんされた場合、大規模なDDoS攻撃に及ぼす影響はどの程度か?

主な発見

  • 200万件を超える稼働中のEoL機器が検出され、そのうち約30万件がEoL宣言後5年以上も稼働し続けていることが判明した。
  • 分析対象の294の脆弱性の半数以上(182件)がEoL日付以降に発見されたことから、欠陥の暴露が遅延していることが示された。
  • 200万件を超える稼働中のEoL機器が脆弱であり、そのうち約半数が深刻度の高い脆弱性にさらわれている。
  • 稼働中のEoL機器に存在するOSコマンドインジェクション脆弱性を悪用すれば、最大2.79 TbpsのDDoS攻撃が可能になる。
  • EoL機器向けのベンダーのセキュリティパッチは、任意的かつ不完全な形で提供されており、大多数の機器が保護されていない状態である。
  • EoL機器の改ざんに関する公的報告は存在するが、これまでにこのようなシステムの規模とリスクを定量的に測定した大規模な研究は存在しなかった。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。