Skip to main content
QUICK REVIEW

[논문 리뷰] DICE: Automatic Emulation of DMA Input Channels for Dynamic Firmware Analysis

Alejandro Mera, Bo Feng|arXiv (Cornell University)|2020. 07. 03.
Advanced Malware Detection Techniques참고 문헌 21인용 수 6
한 줄 요약

DICE는 하드웨어에 종속되지 않고 분석기와 무관한 프레임워크로, 동적 분석 중에 임베디드 펌웨어 내 DMA 입력 채널을 자동으로 식별하고 시뮬레이션함으로써 소스 코드나 하드웨어 없이도 전체 코드 커버리지 및 취약점 탐지가 가능하다. 이는 89%의 참 양성 검출률을 기록했으며, 실제 펌웨어에서 코드 경로 커버리지가 최대 79배 향상되었고, 기존에 알려지지 않은 버그 5개를 발견했다.

ABSTRACT

Microcontroller-based embedded devices are at the core of Internet-of-Things and Cyber-Physical Systems. The security of these devices is of paramount importance. Among the approaches to securing embedded devices, dynamic firmware analysis gained great attention lately, thanks to its offline nature and low false-positive rates. However, regardless of the analysis and emulation techniques used, existing dynamic firmware analyzers share a major limitation, namely the inability to handle firmware using DMA. It severely limits the types of devices supported and firmware code coverage. We present DICE, a drop-in solution for firmware analyzers to emulate DMA input channels and generate or manipulate DMA inputs. DICE is designed to be hardware-independent, and compatible with common MCU firmware and embedded architectures. DICE identifies DMA input channels as the firmware writes the source and destination DMA transfer pointers into the DMA controller. Then DICE manipulates the input transferred through DMA on behalf of the firmware analyzer. We integrated DICE to the firmware analyzer P2IM (Cortex-M architecture) and a PIC32 emulator (MIPS M4K/M-Class architecture). We evaluated it on 83 benchmarks and sample firmware, representing 9 different DMA controllers from 5 different vendors. DICE detected 33 out of 37 DMA input channels, with 0 false positives. It correctly supplied DMA inputs to 21 out of 22 DMA buffers, which previous firmware analyzers cannot achieve due to the lack of DMA emulation. DICE's overhead is fairly low, it adds 3.4% on average to P2IM execution time. We also fuzz-tested 7 real-world firmware using DICE and compared the results with the original P2IM. DICE uncovered tremendously more execution paths (as much as 79X) and found 5 unique previously-unknown bugs that are unreachable without DMA emulation. All our source code and dataset are publicly available.

연구 동기 및 목표

  • 기존 도구가 DMA 기반 입력 채널을 처리하지 못하는 동적 펌웨어 분석의 핵심적 한계를 해결하기 위해.
  • 펌웨어 소스 코드나 하드웨어 종속성을 요구하지 않고도 DMA 기반 MCU 펌웨어에서 전체 코드 커버리지 및 취약점 탐지를 가능하게 하기 위해.
  • 다양한 임베디드 아키텍처와 DMA 컨트롤러와 호환되는 일반적인 하드웨어 무관 솔루션을 설계하기 위해.
  • 기존 펌웨어 분석기와의 원활한 통합을 위해 드롭인 모듈로 작동하도록 설계하기 위해.
  • 실행 중에 동적으로 DMA 입력을 탐지하고 공급하여 펌웨어 실행이 정상적으로 진행되도록 하기 위해.

제안 방법

  • DICE는 DMA 컨트롤러 레지스터에 쓰여지는 내용을 모니터링하여 DMA 입력 채널을 식별한다. 특히 소스 및 대상 전송 포인터 레지스터를 대상으로 한다.
  • 실행 중에 이러한 레지스터 쓰기 내용을 분석함으로써 DMA 전송에 사용되는 메모리 버퍼의 위치와 크기를 동적으로 유추한다.
  • 펌웨어 분석기 대신 DMA 입력 데이터를 시뮬레이션하여, 실제 외부 장치가 쓴 것처럼 메모리 버퍼에 유효한 데이터를 공급한다.
  • 펌웨어를 수정하거나 소스 코드가 필요 없기 때문에, 어떤 펌웨어 분석기나 임베디드 아키텍처와도 호환된다.
  • P 2 IM 및 MIPS PIC32 에뮬레이터와 통합되어 투명한 DMA 입력 지원을 제공한다.
  • 실행 중 인strumentation을 사용하여 펌웨어 실행 중에 DMA 설정 및 데이터 전송 이벤트를 감지한다.

실험 결과

연구 질문

  • RQ1소스 코드 없이 하드웨어에 종속되지 않는 일반적인 프레임워크가 임베디드 펌웨어 내 DMA 입력 채널을 자동으로 식별하고 시뮬레이션할 수 있는가?
  • RQ2이러한 프레임워크가 펌웨어 실행 중에 동적으로 구성된 DMA 버퍼를 얼마나 정확히 식별할 수 있는가?
  • RQ3기존 펌웨어 분석 파이프라인에 DMA 시뮬레이션을 통합할 경우 성능 오버헤드는 어느 정도인가?
  • RQ4실제 펌웨어에서 DMA 시뮬레이션은 코드 경로 커버리지 및 취약점 탐지에 얼마나 기여하는가?
  • RQ5DMA에 의존하는 펌웨어에서 기존 분석 도구가 DMA 시뮬레이션 없이 도달할 수 없는 이전에 알려지지 않은 버그를 프레임워크가 발견할 수 있는가?

주요 결과

  • DICE는 83개의 벤치마크 및 샘플 펌웨어에서 37개의 DMA 입력 채널 중 33개를 탐지하여 0%의 가짜 양성률과 89%의 참 양성률을 기록했다.
  • 펌웨어가 실제로 사용한 22개의 DMA 버퍼 중 21개에 대해 정확히 DMA 입력을 공급하여 이전에 도달할 수 없었던 코드 실행을 가능케 했다.
  • P 2 IM에 DICE를 통합했을 때 평균 실행 시간에 3.4%의 오버헤드만 발생시켰다.
  • 실제 펌웨어 퍼즈링에서 DICE는 DMA 지원이 없는 원래의 P 2 IM 대비 코드 경로 커버리지를 최대 79배 향상시켰다.
  • DICE는 이전 분석 도구가 DMA 시뮬레이션 없이 접근할 수 없어 발견하지 못했던 실제 펌웨어에서 고유한 5개의 알려지지 않은 취약점을 발견했다.
  • 모든 소스 코드와 데이터셋은 공개되어 있어 재현성 및 펌웨어 분석 분야의 향후 연구를 지원한다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.