Skip to main content
QUICK REVIEW

[논문 리뷰] A Measurement Study on the (In)security of End-of-Life (EoL) Embedded Devices

Dingding Wang, Muhui Jiang|arXiv (Cornell University)|2021. 05. 29.
Advanced Malware Detection Techniques참고 문헌 25인용 수 5
한 줄 요약

이 연구는 사이버스페이스 검색 엔진과 펌웨어 분석을 활용하여 최초로 종료된 지원 기간(End-of-Life, EoL) 기반 임베디드 장치의 실시간 검출 및 취약성 평가를 수행한다. 연구 결과, 200만 개 이상의 활성 EoL 장치가 확인되었으며, 이 중 100만 개 이상가 취약한 상태로, 거의 절반은 고위험 취약성에 노출되어 있으며, 명령 주입 공격을 통해 최대 2.79 Tbps의 DDoS 공격이 가능할 것으로 예측된다.

ABSTRACT

Embedded devices are becoming popular. Meanwhile, researchers are actively working on improving the security of embedded devices. However, previous work ignores the insecurity caused by a special category of devices, i.e., the End-of-Life (EoL in short) devices. Once a product becomes End-of-Life, vendors tend to no longer maintain its firmware or software, including providing bug fixes and security patches. This makes EoL devices susceptible to attacks. For instance, a report showed that an EoL model with thousands of active devices was exploited to redirect web traffic for malicious purposes. In this paper, we conduct the first measurement study to shed light on the (in)security of EoL devices. To this end, our study performs two types of analysis, including the aliveness analysis and the vulnerability analysis. The first one aims to detect the scale of EoL devices that are still alive. The second one is to evaluate the vulnerabilities existing in (active) EoL devices. We have applied our approach to a large number of EoL models from three vendors (i.e., D-Link, Tp-Link, and Netgear) and detect the alive devices in a time period of ten months. Our study reveals some worrisome facts that were unknown by the community. For instance, there exist more than 2 million active EoL devices. Nearly 300,000 of them are still alive even after five years since they became EoL. Although vendors may release security patches after the EoL date, however, the process is ad hoc and incomplete. As a result, more than 1 million active EoL devices are vulnerable, and nearly half of them are threatened by high-risk vulnerabilities. Attackers can achieve a minimum of 2.79 Tbps DDoS attack by compromising a large number of active EoL devices. We believe these facts pose a clear call for more attention to deal with the security issues of EoL devices.

연구 동기 및 목표

  • 인터넷에 연결된 종료된 지원 기간(End-of-Life, EoL) 임베디드 장치의 규모와 지속성을 조사하기 위해.
  • 제조사 지원 종료 후에도 활성 상태인 EoL 장치 내에 존재하는 취약성의 유무와 심각도를 평가하기 위해.
  • 보안 패치가 제공되지 않음으로 인해 EoL 장치가 악용 위험에 노출되어 있는지 평가하기 위해.
  • 손상된 EoL 장치를 활용한 대규모 봇넷 형성 가능성을 정량화하기 위해.

제안 방법

  • 10개월에 걸쳐 지속적인 스캔을 수행하기 위해 사이버스페이스 검색 엔진(특히 ZoomEye)을 활용하여 활성 EoL 장치를 탐지하였다.
  • EoL 장치가 네트워크 프로브에 응답하고 계속 온라인 상태를 유지하는지를 확인함으로써 생존 분석을 수행하였다.
  • 공개 자료(예: CVE, NVD) 및 제조사 릴리스 노트에서 취약성을 수집하여 알려진 결함를 식별하였다.
  • FIRMADYNE, IDA Pro, Ghidra를 활용한 동적 및 정적 펌웨어 분석을 수행하여 취약성 존재 여부를 검증하였다.
  • 펌웨어 이미지에 EoL 상태를 매핑하고 패치 가용성 및 릴리스 일정을 분석하였다.
  • 윤리적 연구 지침을 준수하고 IP 주소를 익명화하였으며, 오용을 방지하기 위해 민감하지 않은 데이터만 공개하였다.

실험 결과

연구 질문

  • RQ1몇 대의 종료된 지원 기간(End-of-Life, EoL) 임베디드 장치가 여전히 인터넷에 연결되어 활성화되어 있는가?
  • RQ2EoL 일자 이후에도 활성 EoL 장치 내에 존재하는 취약성의 보급률과 심각도는 어떠한가?
  • RQ3EoL 이후에도 제조사에서 보안 패치를 제공하는가? 만약 그렇다면, 패치 제공 과정은 얼마나 완전하고 빠른가?
  • RQ4활성 EoL 장치가 해킹되어 대규모 DDoS 공격을 유도할 수 있는 잠재적 영향은 어떠한가?

주요 결과

  • 200만 대 이상의 활성 EoL 장치가 탐지되었으며, 이 중 약 30만 대는 EoL 선언 후 5년이 넘게 운영 중이었다.
  • 분석한 294개의 취약성 중 절반 이상(182개)이 EoL 일자 이후에 발견되어 결함 노출이 지연됨을 시사한다.
  • 200만 대 이상의 활성 EoL 장치가 취약하며, 이 중 거의 절반은 고위험 취약성에 노출되어 있다.
  • 활성 EoL 장치의 운영 체제 명령 주입 취약성을 악용할 경우 최대 2.79 Tbps의 DDoS 공격이 가능하다.
  • EoL 장치의 제조사 보안 패치는 비계획적이고 불완전하게 제공되어 대부분의 장치가 보호되지 않은 상태이다.
  • 공개된 EoL 장치 해킹 사례가 있었음에도 불구하고, 이와 같은 시스템의 규모와 위험성을 정량적으로 측정한 대규모 측정 연구는 이전에 없었다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.