A hard-coded backdoor detection method based on semantic conflict
Through a hard-coded backdoor detection method based on semantic conflict, the function call relationship and control flow diagram are used to automatically detect the hard-coded backdoor in the router firmware, solving the problems of poor detection effect and high false alarm rate in the existing technology, and achieving high precision and high recall backdoor detection.
Patent Information
- Application Number
- CN202111606858.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-27
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2041-12-27
AI Technical Summary
The prior art is difficult to effectively detect hard-coded backdoors in routers, especially because fuzzy testing cannot detect logic errors and access control vulnerabilities, static detection is highly automated but false alarm rate, symbol execution methods cannot automatically detect firmware on a large scale, and there are problems such as path explosion and time-consuming.
A hard-coded backdoor detection method based on semantic conflict is used to identify password backdoors in the firmware through data preprocessing, locating suspicious functions, building directed topology maps, deep-first traversal and filtering semantic conflict paths. This method uses the function's call relationship, control flow graph CFG and branch selection dependency strings, and combines the characteristics of MIPS and ARM instruction sets to automate large-scale detection of backdoors in firmware.
It realizes the hard-coded backdoor in automated large-scale detection of firmware, improves detection accuracy and recall rate, reduces false alarm rate, and can effectively identify password backdoors in routers. The detection effect is better than existing static detection and symbol execution methods.
Smart Images

Figure CN114490328B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of backdoor detection, and in particular relates to a hard-coded backdoor detection method based on semantic conflict. Background Art
[0002] Routers are the core switching devices of the Internet. As the basis of network interconnection, their security issues have always been the focus of research in the field of cyberspace security. There are two main aspects of router security issues: one is the backdoors or security vulnerabilities in the router itself, which are discovered and exploited by attackers; the other is the lack of effective and secure configuration management of routers, which makes them vulnerable to attacks, intrusions or implantation of backdoors. Compared with other vulnerability mining methods, fuzz testing has huge advantages: high degree of automation, low false positive rate, no need to analyze the source code or binary program of the target program, and in fact has become the most commonly used vulnerability mining method. However, fuzz testing still has its limitations: it cannot detect logical errors and access control vulnerabilities (i.e. backdoor vulnerabilities). Therefore, there is little detection and analysis of backdoor vulnerabilities.
[0003] A backdoor is a program method used to secretly bypass normal authentication processes such as software, computer systems, and password mechanisms to obtain access rights to computer systems or plain text encrypted by password systems. One of the most common backdoors is the hard-coded backdoor. The sources of hard-coded backdoors can be divided into two types: one is that some manufacturers will implant hard-coded passwords in the program for management needs; the other is that attackers tamper with the firmware to implant backdoor passwords. Password backdoors are easy to set up and only require a small amount of code to implement, but they are not easy to be discovered, especially when using confusing strings, which makes it even more difficult for reverse engineers to discover, such as the password "xmlset_roodkcableoj28840ybtide" found in D-Link routers. Regardless of the source of the hard-coded backdoor, attackers can use backdoor passwords to control devices, hijack traffic, or spread viruses.
[0004] In recent years, there are two main methods for detecting password backdoors: static analysis and symbolic execution. Hu Chaojian proposed a library function identification method based on embedded firmware for backdoor detection of firmware without file system. Costin first proposed large-scale automated analysis of embedded firmware, using fuzzy hashing to match weak keys that may exist in the firmware, and using association analysis to find firmware similarities in four different dimensions, successfully detecting 38 unknown vulnerabilities in 693 firmwares. Thoma proposed a method based on static data comparison analysis, Stringer, to detect hard-coded backdoors in commercial device firmware. Firmalice uses static program analysis to generate a program dependency graph of the firmware, obtains a program path from the entry point to the privileged program point, and then uses symbolic execution to determine whether there are deterministic constraints in the path. If so, it is identified as a backdoor. However, although the current static detection method has a high degree of automation, it also has the problems of high false alarm rate and poor detection effect; although the symbolic execution method has a high accuracy rate, it cannot automatically detect firmware on a large scale, and has the defects of path explosion and long time consumption. Summary of the invention
[0005] In view of the defects and problems existing in current backdoor detection, the present invention provides a hard-coded backdoor detection method based on semantic conflict.
[0006] The solution adopted by the present invention to solve the technical problem is: a hard-coded backdoor detection method based on semantic conflict, comprising the following steps:
[0007] Step 1: Data preprocessing: Collect device firmware from the network and use firmware analysis tools to unpack the firmware and extract binary files of the file system;
[0008] Step 2: Locate suspicious functions: Perform reverse analysis on the binary file to detect whether f exists in the file checkStr function;
[0009] If it exists, then find the cross reference f checkStr The address of the function, find the call f according to the address checkStr Functions of functions are called suspicious functions;
[0010] If it does not exist, check the next file;
[0011] Step 3: Construct a directed topology graph: Based on the suspicious function CFG graph located in step 2, consider the block as a vertex node and the jump relationship between blocks as a directed edge. Construct a directed topology graph G through conversion.
[0012] G = {nodes, edges}
[0013] node={block.startEA,flag}
[0014] edge={node curr ,node next ,str}
[0015] For no call to f checkStr In the function block, the flag of the vertex node is equal to 0;
[0016] For calling f checkStr In the function block, the flag of the vertex node is equal to 1;
[0017] In node curr In the example, the check string str is found by combining the registers used in the function call, and str and node are mapped by jump instructions. next , generate edge;
[0018] Step 4: Perform a depth-first traversal on the directed topology graph G in step 3 to find paths and dependent strings with the same starting point;
[0019] Step 5: Filter the set of paths with the same starting point, and only keep the paths whose last branch node is verified as T as successful paths; cluster the paths with the same end point into groups, and check whether the strings in the same group have semantic conflicts.
[0020] If so, save the path pair and the corresponding string;
[0021] If not, it will not be retained.
[0022] In the above-mentioned hard-coded backdoor detection method based on semantic conflict, in step 1, the binwalk firmware unpacking tool is used to unpack the firmware and extract the binary files of the file system.
[0023] In the above-mentioned hard-coded backdoor detection method based on semantic conflict, in step 2, the IDA Pro disassembly tool is used to reverse analyze the binary file.
[0024] In the above-mentioned hard-coded backdoor detection method based on semantic conflict, in step 4, a depth-first traversal is performed on the directed graph G to find the path set Paths and dependent strings with the same starting point. The specific method is as follows: mark the call f checkStr The basic block of the function, vertex node, traverses all vertices in the directed graph in turn, and only performs a depth-first traversal algorithm to find branch paths for marked vertices; when a vertex encountered during the traversal is a marked vertex, the mark is canceled.
[0025] In the above hard-coded backdoor detection method based on semantic conflict, the successful paths are clustered into groups in step 5, and the judgment criteria for detecting whether there is a semantic conflict in the same group of strings are as follows:
[0026] If the Lewenstein ratio f of the dependency strings of two paths is greater than or equal to 0.75, then there is no conflict between the two paths;
[0027] If the Lewenstein ratio f of the dependency strings of two paths is less than 0.75, then the two paths conflict.
[0028] Beneficial effects of the present invention: Starting from the commonly used string comparison function, the present invention combines the characteristics of MIPS and ARM instruction sets, and utilizes the function calling relationship, control flow graph CFG and branch selection dependent strings to identify password backdoors in firmware. This method can automatically detect firmware on a large scale.
[0029] The method of the present invention only detects whether the successfully verified branch path has semantic conflicts, and retains the paths with semantic conflicts to improve the accuracy of the method, reduce the false alarm rate, and have better detection effect. The method of the present invention is evaluated using 1191 router firmwares collected on the Internet, and 8 backdoor passwords are successfully identified from 9 backdoor firmwares, with a recall rate of 88.89%. In terms of router password backdoor detection, it is far superior to Stringer, a hard-coded backdoor detection method based on static data comparison analysis, and Costin, a weak key detection method based on fuzzy hash association analysis. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 The figure is an overall flow chart of the method of the present invention.
[0031] Figure 2 This is a login verification flow chart.
[0032] Figure 3 This is a simplified function control flow graph. DETAILED DESCRIPTION
[0033] By statistically analyzing the firmware architectures collected by web crawlers, it is shown that MIPS and ARM architectures account for a large proportion, so the detection object of the present invention is the router firmware of MIPS and ARM architectures. Both MIPS and ARM architectures adopt a processor architecture with a reduced instruction set and use a fixed-length instruction set. Whether it is MIPS or ARM, the CPU is not allowed to directly access the memory unit, and can only use registers as relays. The memory and registers interact through load / store instructions.
[0034] There are 32 general-purpose registers in the MIPS architecture, which can be represented by $0 to $31 or by the name of the register in the assembly program, as shown in Table 1 below.
[0035] Table 1 MIPS architecture general registers
[0036]
[0037] The number of registers in the ARM architecture depends on the ARM version. Except for processors based on ARMv6-M and ARMv7-M, there are generally 30 general-purpose registers, including SP and LR registers. ARM processors have 16 general-purpose registers in user mode, which are represented by register names in the assembler, as shown in Table 2.
[0038] Table 2 ARM architecture general registers
[0039]
[0040] Password backdoors often appear in the authentication login process. The principle is as follows: In the normal system login process, using a hard-coded key can bypass the login authentication through a branch bypass, thereby logging into the system or obtaining system control permissions. Therefore, the function where the backdoor password is located has the following two characteristics:
[0041] (1) There is a string comparison function: Whether it is a normal login process or a backdoor command execution process, in order to ensure that only administrators or trusted users can log in to the system, a string comparison function (abbreviated as f checkStr Function) are indispensable. The login verification process is as follows Figure 2 As shown. In the normal login process, f checkStr The function ensures that only administrators can log in to the system; in the password backdoor execution process, f checkStr The function ensures that only the password holder can control the system.
[0042] (2) The semantics of the verification strings of the paths that have been successfully verified are the same: the CFG graph of the function is converted into a directed graph, with basic blocks (blocks, basic blocks) regarded as vertices and the jump relationships between blocks as directed edges. When different branch paths converge at the same end point, the semantics of the verification strings of the paths that have failed verification are different, but the semantics of the verification strings of the branches that have been successfully verified are the same. If the semantics of the verification strings of the latter conflict, then there is a high probability that there is a password backdoor. Figure 3 As shown (in the figure, T represents successful verification, and F represents failed verification), vertex 7 is the end point of failed verification, and vertex 8 is the end point of successful verification.
[0043] The following is a detailed description of the hard-coded backdoor detection method based on semantic conflict of the present invention in conjunction with the accompanying drawings. The detection method of the present invention includes the following contents: Figure 1 .
[0044] Step 1: Firmware preprocessing: Collect device firmware from the network, use firmware analysis tools to unpack the firmware, and extract the binary files of the file system.
[0045] Commonly used unpacking tools include binwalk, Firm-Mod-Kit, BAT, etc. Among them, binwalk is easy to operate and not only supports automated scripts, but also allows customized signatures, extraction rules, and integrated plug-in modules. In this embodiment, binwalk is selected as the firmware unpacking tool.
[0046] Step 2: Locate suspicious functions: Perform reverse analysis on the binary file to detect whether there is a string comparison function in the file, referred to as f checkStr function;
[0047] Reverse analysis tools include IDA Pro, Ghidra, angr, etc. Among them, IDA Pro is an interactive disassembler that can not only generate assembly code for binary files, but also has functions such as identifying function blocks, obtaining function cross-references, and describing function flow graphs.
[0048] This example uses the IDA Pro disassembly tool to perform reverse analysis on the binary file to detect whether there is a string comparison function in the file, referred to as f checkStr function;
[0049] If it exists, then find the cross reference f checkStr The address of the function, find the call f according to the address checkStr Functions of functions are called suspicious functions;
[0050] If it does not exist, the next file is checked.
[0051] Step 3: Construct a directed topology graph: Based on the located suspicious function CFG graph, consider the block as a vertex node and the jump relationship between blocks as a directed edge. Construct a directed topology graph G through conversion. G is defined as follows:
[0052] G = {nodes, edges}
[0053] node={block.startEA,flag}
[0054] edge={node curr ,node next ,str}
[0055] For no call to f checkStr In the function block, the flag of the vertex node is equal to 0;
[0056] For calling f checkStr In the function block, the flag of the vertex node is equal to 1;
[0057] In node currIn the example, the check string str is found by combining the registers used in the function call, and str and node are mapped by jump instructions. next , generate edge.
[0058] Customize the vertex structure node and the directed edge structure edge. The node has an attribute flag, which indicates whether the current vertex has called f checkStr Function; the edge has the attribute str, indicating that this edge depends on this string.
[0059] The specific algorithm is implemented as follows:
[0060] Algorithm 1: Convert function f to directed graph G
[0061]
[0062]
[0063] Step 4: Find the set of branch paths with the same starting point:
[0064] Perform a depth-first traversal on the directed graph G in step 3 to find the path set Paths and dependent strings with the same starting point;
[0065] For a graph with N vertices and E edges, the time complexity of the depth-first traversal algorithm is O(N 2 ), in order to reduce the complexity of the algorithm and improve the detection efficiency, the path search starts from the marked vertices and the marks of the traversed marked vertices are cancelled.
[0066] Specifically: mark the call f checkStr The basic block of the function is the vertex node. (I) Traverse all vertices in the graph in sequence, and only perform a depth-first traversal algorithm on marked vertices to find the path; (II) When the vertex encountered during the traversal is a marked vertex, cancel this mark. This embodiment improves the commonly used depth-first traversal algorithm: only perform a depth-first traversal algorithm on marked vertices to find branch paths; all marked vertices will only be traversed once in depth-first order, and the branch paths will not be solved repeatedly. This improvement meets the needs and saves time.
[0067] The specific algorithm is implemented as follows:
[0068] Algorithm 2 Find the set of branch paths with the same starting point
[0069]
[0070] Step 5: Filter the path set with semantic conflicts
[0071] The set of paths with the same starting point in step 4 is filtered, and only the paths whose last branch point is verified as T are considered as the paths that have been successfully verified; T refers to the last call to f checkStr In the basic block of the function, it is based on f checkStr The return value of the function has two branches, one of which is T, which means that through f checkStr function; the other is F, which means it did not pass f checkStr function.
[0072] Cluster successful paths into groups and detect whether the strings in the same group have semantic conflicts;
[0073] If the Levenshtein ratio f of the dependent strings of two paths is greater than or equal to 0.75, then there is no conflict between the two paths, and the path pair and the corresponding string are saved;
[0074] If the Lewenstein ratio f of the dependency strings of two paths is less than 0.75, the two paths conflict and are not retained.
[0075] For a successfully authenticated endpoint, if there is a path that passes through the backdoor password, the verification string of this path has a semantic conflict with the verification string of other paths.
[0076] Experimental example: To verify the effectiveness of the method of the present invention, device firmwares of network equipment manufacturers such as TP-LINK, D-LINK, NETGEAR, Xiaomi, and Huawei were collected from the Internet, and a total of 1,191 firmwares were collected.
[0077] The firmware preprocessing process is as follows: After scanning and analyzing with the binwalk tool, 1131 firmwares were successfully unpacked, from which firmwares with MIPS and ARM architectures were screened out, and finally a data set containing 1074 firmwares was obtained. The change in the number of firmwares in the preprocessing stage is shown in Table 3. There are 9 password backdoor firmwares in the data set, including 7 MIPS firmwares and 2 ARM firmwares. The details of the backdoors are shown in Table 4.
[0078] Table 3 Statistics of firmware quantity in the preprocessing stage
[0079]
[0080] Table 4 Password backdoor firmware details
[0081]
[0082] In order to verify the effectiveness of the method of the present invention, this test example adopts three methods to detect backdoors in the experimental data set. The three methods are Stringer (THOMAS SL, CHOTHIA T, GARCIA F D. Stringer: Measuring the Importance of Static Data Comparisons to Detect Backdoors and Undocumented Functionality [M] / / Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)., 2017), Costin (COSTIN A, ZADDACH J, FRANCILLON A, et al. A large-scale analysis of the security of embedded firmwares [J]. Proceedings of the 23rd USENIX Security Symposium, 2014: 95–110.) and the password backdoor detection method based on semantic conflict of the present invention, Stect; and the effect of the password backdoor detection method is evaluated by precision, recall rate, false negative rate, average time consumption and coverage rate. Finally, the obtained results are analyzed and compared. The experimental results are shown in Table 5.
[0083] Table 5 Comparison results of evaluation indicators of different backdoor detection methods
[0084]
[0085] in:
[0086] (1) Precision P: reflects the proportion of correctly detected passwords among samples judged as passwords. P in the table is the precision value calculated for each password backdoor file, and the sum is taken as the average value;
[0087]
[0088] Where: TPs is the number of samples in the password backdoor file that are judged to be passwords and are indeed passwords; FPs is the number of samples in the password backdoor file that are judged to be passwords but are not passwords.
[0089] (2) Recall rate R: reflects the ratio of detected backdoor firmware samples to the actual number of existing backdoor firmware samples;
[0090]
[0091] Where: TP is the number of firmwares whose real passwords are detected by the method; FN is the number of firmwares whose real passwords are not detected by the method.
[0092] (3) Missing rate F: reflects the proportion of undetected backdoor firmware samples to actual backdoor firmware samples.
[0093]
[0094] (4) Average time t: reflects the time it takes to detect a single binary file.
[0095] t=T / M
[0096] Where: T is the duration of the experimental process; M is the number of binary files that have been detected.
[0097] (5) Coverage Cv: reflects the ratio of the number of binary files detected by the method to the total number of binary files.
[0098] Cv=M / N
[0099] Where: M is the number of binary files that have been detected; t is the average detection time of a single binary file; N is the total number of binary files.
[0100] It can be seen from the results in Table 5 that the Stec method of the present invention has a wider detection range and better effect than the other two methods.
[0101] At the same time, three methods are used to detect the password backdoor firmware of 9 real devices in the dataset. The comparison of the detection results of the three methods is shown in Table 6.
[0102] Table 6 Comparison of password backdoor detection results
[0103]
[0104] As can be seen from the table, Stringer detected 1, Costin detected 1, and the Stec method of the present invention detected 8.
[0105] Overall, the Stringer method only implements the backdoor detection method for ARM firmware and successfully detects the password of 1 ARM firmware; the Costin method can only detect the weak key backdoor that has been included, and the detection time is longer; while the method of the present invention has the best effect, and can successfully detect 8 backdoor instructions, with a recall rate of up to 88.89%. When evaluating the coverage Cv, the Stringer method can only detect 37.71% of the firmware, while the Stect method can detect 97.87% of the firmware. Even considering that the MIPS and ARM architectures in network devices account for 91.9%, the Cv of the Stect method of the present invention can reach 89.94%.
Claims
1. A hard-coded backdoor detection method based on semantic conflict, characterized by: The following steps are involved: Step 1: Data preprocessing: Collect device firmware from the network, use firmware analysis tools to unpack the firmware, and extract binary files from the file system; Step 2: Locate suspicious functions: Perform reverse analysis on the binary file to detect whether f exists in the file checkStr function; If it exists, then find the cross reference f checkStr The address of the function, find the call f according to the address checkStr Functions of functions are called suspicious functions; If it does not exist, check the next file; Step 3: Construct a directed topology graph: Based on the suspicious function CFG graph located in step 2, consider the block as a vertex node and the jump relationship between blocks as a directed edge. Construct a directed topology graph G through conversion. G = {nodes, edges} node={block.startEA,flag} edge={node curr ,node next ,str} For no call to f checkStr In the function block, the flag of the vertex node is equal to 0; For calling f checkStr In the function block, the flag of the vertex node is equal to 1; In node curr In the example, the check string str is found by combining the registers used in the function call, and str and node are mapped by jump instructions. next , generate edge; Step 4: Perform a depth-first traversal on the directed topology graph G in step 3 to find paths and dependent strings; Step 5: Filter the path set with the same starting point and only keep the last branch node to verify that it passes f checkStr The path of the function as a path to success; Cluster the successful paths into groups and check whether the strings in the same group have semantic conflicts. If so, save the path pairs and the corresponding strings. If not, it will not be retained.
2. The hard-coded backdoor detection method based on semantic conflict according to claim 1, characterized in that: In step 1, use the binwalk firmware unpacking tool to unpack the firmware and extract the binary files of the file system.
3. The hard-coded backdoor detection method based on semantic conflict according to claim 1, characterized in that: In step 2, use the IDA Pro disassembly tool to reverse analyze the binary file.
4. The hard-coded backdoor detection method based on semantic conflict according to claim 1, characterized in that: In step 4, a depth-first traversal is performed on the directed graph G to find the path set Paths and dependency strings with the same starting point. The specific method is: mark the call f checkStr The basic block of the function, vertex node, traverses all vertices in the directed graph in turn, and only performs a depth-first traversal algorithm on marked vertices to find branch paths; When the vertex encountered during the traversal is a marked vertex, the mark is canceled.
5. The hard-coded backdoor detection method based on semantic conflict according to claim 1, characterized in that: In step 5, the successful paths are clustered into groups, and the criteria for detecting whether there is a semantic conflict between strings in the same group are as follows: If the Lewenstein ratio f of the dependency strings of two paths is greater than or equal to 0.75, then there is no conflict between the two paths; If the Lewenstein ratio f of the dependency strings of two paths is less than 0.75, then the two paths conflict.