Internet of Things equipment firmware homology vulnerability detection method and system
By disassembly and parsing, preprocessing and comparing the disclosed vulnerability function data information on the firmware, the homology vulnerabilities in the firmware are detected, and the vulnerability problems caused by the multiplexing of third-party components in the firmware of IoT devices are solved, and effective detection and improvement of device security is achieved.
Patent Information
- Application Number
- CN202510007067.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-03
- Publication Date
- 2025-05-16
AI Technical Summary
As the number of IoT devices increases, the same third-party open source components are reused in the firmware of different devices, resulting in the existence of the same vulnerabilities, threatening the device's data confidentiality, data integrity and access control, which may lead to data leakage and system paralysis.
Provide a method and system for detecting homology vulnerability in IoT device firmware, which includes obtaining IoT device firmware, disassembly and parsing to obtain assembly code, preprocessing, collecting public vulnerability data information to build a function vulnerability database, and comparing the preprocessed assembly code with the function vulnerability database to detect homology and determine the vulnerability.
This method can effectively detect homology vulnerabilities in the firmware of IoT devices, discover and determine the types of vulnerabilities, improve the security of the device, and prevent data leakage and system paralysis.
Smart Images

Figure CN120011197A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of vulnerability detection, and in particular to a method and system for detecting homology vulnerabilities in firmware of an Internet of Things device. Background Art
[0002] In recent years, with the rapid increase in the number of IoT devices, R&D personnel have reused a large number of third-party open source components in order to improve development efficiency, which has led to the inclusion of the same vulnerabilities in the firmware of different IoT devices. Firmware vulnerabilities threaten all aspects of IoT devices, such as data confidentiality, data integrity, and access control, and may cause serious consequences such as data information leakage and system paralysis. Therefore, a method for detecting homology vulnerabilities in IoT device firmware is needed to detect vulnerabilities in firmware. Summary of the invention
[0003] The purpose of the embodiments of the present invention is to provide a method and system for detecting homology vulnerabilities in firmware of an Internet of Things device. The detection method can perform homology vulnerability detection on the acquired firmware of the Internet of Things device to discover vulnerabilities in the firmware.
[0004] In order to achieve the above object, an embodiment of the present invention provides a method for detecting firmware homology vulnerabilities of IoT devices, the detection method comprising:
[0005] Get IoT device firmware;
[0006] Disassembling and parsing the IoT device firmware to obtain assembly code;
[0007] Preprocessing the assembly code;
[0008] Collect publicly available vulnerability function data information to build a function vulnerability database;
[0009] The preprocessed assembly code is compared with the function vulnerability database to detect the homology between the assembly code and the function vulnerability database, thereby determining the vulnerability in the IoT device firmware.
[0010] Optionally, disassembling and parsing the IoT device firmware to obtain assembly code includes:
[0011] Performing a reverse analysis on the IoT device firmware to obtain system files;
[0012] Classifying the system files, finding executable files, and extracting relevant information to obtain program source code;
[0013] Compile the program source code according to different compilation configurations to obtain a binary file;
[0014] The binary file is disassembled to obtain the assembly code.
[0015] Optionally, preprocessing the assembly code includes:
[0016] Obtaining the assembly code;
[0017] Obtain all macros in the assembly code and expand all macros;
[0018] Delete all comments in the assembly code;
[0019] Deleting extra spaces, tabs, and line breaks in the assembly code;
[0020] The variable names and function names in the assembly code are standardized.
[0021] Optionally, collect publicly available vulnerability function data information to build a function vulnerability database, including:
[0022] Collect publicly available vulnerability function data information;
[0023] Normalize the vulnerability function data information, use a unified standard format to describe the vulnerability information, and annotate the vulnerability information through CVE;
[0024] Marking the vulnerability severity of the vulnerability function data information;
[0025] According to the severity marking of the vulnerability function data information, the vulnerability function data information is classified according to the severity to construct a function vulnerability database.
[0026] Optionally, comparing the preprocessed assembly code with the function vulnerability database to detect homology between the assembly code and the function vulnerability database, and then determining the vulnerability in the IoT device firmware, includes:
[0027] Obtain the preprocessed assembly code;
[0028] Determine whether the preprocessed assembly code contains a CVE annotation in the function vulnerability database;
[0029] When the assembly code contains the CVE annotation in the function vulnerability database, it is determined that the assembly code has a corresponding vulnerability, and then the corresponding vulnerability in the IoT device firmware is determined.
[0030] Optionally, comparing the preprocessed assembly code with the function vulnerability database to detect homology between the assembly code and the function vulnerability database, and then determining the vulnerability in the IoT device firmware, includes:
[0031] When there is no CVE annotation in the function vulnerability database in the assembly code, feature extraction is performed on the assembly code and the vulnerability function data information;
[0032] Extracting features of the assembly code and the vulnerability function data information to obtain assembly code features and vulnerability function features;
[0033] Calculating the Euclidean distance between the assembly code feature and the vulnerability function feature;
[0034] Acquire the vulnerability function feature whose Euclidean distance with the assembly code feature exceeds a preset threshold;
[0035] According to the calculated Euclidean distance, the smallest Euclidean distance and the second smallest Euclidean distance are obtained;
[0036] When the ratio of the smallest Euclidean distance to the second smallest Euclidean distance is less than a preset ratio, the vulnerability function feature corresponding to the smallest Euclidean distance is determined as the matching vulnerability function feature, thereby obtaining the corresponding vulnerability.
[0037] Optionally, extracting features of the assembly code and the vulnerability function data information to obtain assembly code features and vulnerability function features includes:
[0038] Decomposing and marking the assembly code and the vulnerable function data information;
[0039] Performing feature extraction on the decomposed marked assembly code and vulnerability function data information by using the TF-IDF method;
[0040] The extracted features are aggregated to obtain corresponding assembly code features and the vulnerability function features.
[0041] On the other hand, the present invention also provides a system for detecting firmware homology vulnerabilities of IoT devices, the detection system comprising:
[0042] Code acquisition module, which obtains the firmware of the IoT device that needs to be tested;
[0043] The computing module is used to receive the IoT device firmware and execute the IoT device firmware homology vulnerability detection method as described above.
[0044] Through the above technical scheme, the present invention provides a method and system for detecting homology vulnerabilities in the firmware of an Internet of Things device, which can obtain the firmware of the Internet of Things device and then disassemble and parse the firmware of the Internet of Things device, so as to obtain the assembly code. After obtaining the assembly code, the assembly code can be preprocessed. Public vulnerability function data information can be collected, so that a function vulnerability database can be constructed. After obtaining the function vulnerability database, the preprocessed assembly code can be compared with the function vulnerability database, so that the homology of the assembly code and the vulnerability function data information in the function vulnerability database can be detected. When it is determined that there is homology, it can be determined that there is a vulnerability in the firmware of the Internet of Things device, and the type of vulnerability in the firmware of the Internet of Things device can be determined based on the function vulnerability database. The detection method can perform homology vulnerability detection on the acquired firmware of the Internet of Things device to discover vulnerabilities in the firmware.
[0045] Other features and advantages of the embodiments of the present invention will be described in detail in the subsequent detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] The accompanying drawings are used to provide a further understanding of the embodiments of the present invention and constitute a part of the specification. Together with the following specific implementations, they are used to explain the embodiments of the present invention, but do not constitute a limitation on the embodiments of the present invention. In the accompanying drawings:
[0047] Figure 1 is a flow chart of a method for detecting firmware homology vulnerabilities of IoT devices according to an embodiment of the present invention;
[0048] Figure 2 It is a flowchart of disassembly and analysis of a method for detecting firmware homology vulnerabilities of IoT devices according to an embodiment of the present invention;
[0049] Figure 3 It is a flowchart of preprocessing of a method for detecting homology vulnerabilities in firmware of IoT devices according to an embodiment of the present invention;
[0050] Figure 4 It is a flowchart of building a function vulnerability database of a method for detecting homology vulnerabilities in firmware of an IoT device according to an embodiment of the present invention;
[0051] Figure 5 It is a flow chart of determining vulnerabilities in a method for detecting homology vulnerabilities in firmware of an IoT device according to an embodiment of the present invention;
[0052] Figure 6 The present invention is a flowchart of feature extraction of a method for detecting firmware homology vulnerabilities in IoT devices according to an embodiment of the present invention. DETAILED DESCRIPTION
[0053] The specific implementation of the embodiment of the present invention is described in detail below in conjunction with the accompanying drawings. It should be understood that the specific implementation described here is only used to illustrate and explain the embodiment of the present invention, and is not used to limit the embodiment of the present invention.
[0054] It should be noted that the acquisition, transmission, storage, use, and processing of data in the technical solution of this application are in compliance with the relevant provisions of national laws and regulations. In the embodiments of this application, some existing solutions in the industry such as certain software, components, and models may be mentioned, which should be considered as exemplary. Their purpose is only to illustrate the feasibility of implementing the technical solution of this application, but it does not mean that the applicant has or will necessarily use the solution.
[0055] Figure 1 The flowchart of a method for detecting a firmware homology vulnerability of an IoT device according to an embodiment of the present invention is shown in FIG. In the present invention, the process of the detection method may include:
[0056] In step S1, the IoT device firmware is obtained.
[0057] In step S2, the IoT device firmware is disassembled and parsed to obtain assembly code.
[0058] In step S3, the assembly code is preprocessed.
[0059] In step S4, publicly available vulnerability function data information is collected to build a function vulnerability database.
[0060] In step S5, the preprocessed assembly code is compared with the function vulnerability database to detect the homology between the assembly code and the function vulnerability database, thereby determining the vulnerability in the IoT device firmware.
[0061] In the present invention, when detecting vulnerabilities in the firmware of an IoT device, the IoT device firmware can be obtained first, and then the IoT device firmware can be disassembled and parsed, so that the assembly code can be obtained. After obtaining the assembly code, the assembly code can be preprocessed. Public vulnerability function data information can be collected, so that a function vulnerability database can be constructed. After obtaining the function vulnerability database, the preprocessed assembly code can be compared with the function vulnerability database, so that the homology of the assembly code and the vulnerability function data information in the function vulnerability database can be detected. When it is determined that there is homology, it can be determined that there is a vulnerability in the IoT device firmware, and the vulnerability type in the IoT device firmware can be determined based on the function vulnerability database. The detection method can perform homology vulnerability detection on the acquired IoT device firmware to discover vulnerabilities in the firmware.
[0062] In one embodiment of the present invention, Figure 2 As shown, the process of disassembly parsing may include:
[0063] In step S6, the IoT device firmware is retroactively parsed to obtain system files.
[0064] In step S7, the system files are classified, executable files are found, and relevant information is extracted to obtain program source codes.
[0065] In step S8, the program source code is compiled according to different compilation configurations to obtain a binary file.
[0066] In step S9, the binary file is deassembled to obtain assembly code.
[0067] In the present invention, when disassembling, the firmware of the Internet of Things device can be retrogradely parsed, so that the system file can be obtained. After obtaining the system file, the system file can be classified, the executable file can be found, and the relevant information can be extracted, so that the program source code can be obtained. After obtaining the program source code, the program source code can be compiled according to different compilation configurations, so that the binary file can be obtained. After obtaining the binary file, the binary file can be disassembled, so that the assembly code can be obtained. The detection method proposed by the present invention needs to disassemble the binary file and convert the machine language into assembly language. There are many mature disassembly tools on the market, such as: OD, IDAPro, radare2, DEBUG, C32, etc. These tools generally have the characteristics of supporting multi-architecture, multi-platform, and multi-compilers, but in comparison, IDA Pro is more powerful than other tools in terms of function, performance, and reliability, and also has a built-in plug-in IDA python to support automated analysis. Therefore, IDA Pro can be selected for disassembly work.
[0068] In one embodiment of the present invention, Figure 3 As shown, the pre-processing process may include:
[0069] In step S10, the assembly code is obtained.
[0070] In step S11, all macros in the assembly code are obtained and expanded.
[0071] In step S12, all comments in the assembly code are deleted.
[0072] In step S13, redundant spaces, tabs and line breaks in the assembly code are deleted.
[0073] In step S14, the variable names and function names in the assembly code are standardized.
[0074] In the present invention, when the assembly code is preprocessed, the assembly code can be obtained first, then all macros in the assembly code can be obtained, and all macros can be expanded. After the expansion is completed, all comments in the assembly code can be deleted, and then redundant spaces, tabs and line breaks in the assembly code can be deleted. After the above processing, the variable names and function names in the assembly code can be standardized, so that the assembly code that meets the requirements can be obtained.
[0075] In one embodiment of the present invention, Figure 4 As shown in the figure, the process of building a function vulnerability database may include:
[0076] In step S15, publicly available vulnerability function data information is collected.
[0077] In step S16, the vulnerability function data information is normalized, the vulnerability information is described using a unified standard format, and the vulnerability information is annotated using CVE.
[0078] In step S17, the vulnerability function data information is marked with the severity of the vulnerability.
[0079] In step S18, based on the severity labeling of the vulnerability function data information, the vulnerability function data information is classified according to the severity to construct a function vulnerability database.
[0080] In the present invention, when constructing a function vulnerability database, publicly available vulnerability function data information may be collected first, and then the vulnerability function data information may be normalized, and the vulnerability information may be described using a unified standard format, and the vulnerability information may be annotated through CVE. The vulnerability function data information may be annotated with the severity of the vulnerability, such as being extremely critical, critical, etc. After the annotation is completed, the vulnerability function data information may be classified according to the severity according to the severity annotation of the vulnerability function data information, so that a function vulnerability database may be constructed, so that different responses may be made according to the severity after the data in the function vulnerability database is subsequently matched.
[0081] In one embodiment of the present invention, Figure 5 As shown, the process of identifying vulnerabilities can include:
[0082] In step S19, the preprocessed assembly code is obtained.
[0083] In step S20, it is determined whether the preprocessed assembly code contains a CVE annotation in the function vulnerability database.
[0084] In step S21, when the assembly code contains a CVE annotation in the function vulnerability database, it is determined that the assembly code has a corresponding vulnerability, and then the vulnerability in the corresponding IoT device firmware is determined.
[0085] In the present invention, after constructing the function vulnerability database, the assembly code can be subjected to homology detection to determine whether the assembly code contains vulnerabilities. When performing homology detection, the preprocessed assembly code and the vulnerability function data information in the function vulnerability database can be obtained, and then it can be determined whether the preprocessed assembly code contains the CVE annotation in the function vulnerability database. In the case where the assembly code contains the CVE annotation in the function vulnerability database, it can be determined that the assembly code has a vulnerability, and the corresponding vulnerability can be determined according to the CVE annotation, and then the vulnerability in the corresponding IoT device firmware can be determined.
[0086] In one embodiment of the present invention, Figure 5 As shown, the process of identifying vulnerabilities can include:
[0087] In step S22, when there is no CVE annotation in the function vulnerability database in the assembly code, feature extraction is performed on the assembly code and the vulnerability function data information.
[0088] In step S23, the assembly code features and the vulnerability function features are obtained based on the feature extraction of the assembly code and the vulnerability function data information.
[0089] In step S24, the Euclidean distance between the assembly code feature and the vulnerability function feature is calculated.
[0090] In step S25, a vulnerability function feature whose Euclidean distance with the assembly code feature exceeds a preset threshold is obtained.
[0091] In step S26, the minimum Euclidean distance and the second minimum Euclidean distance are obtained according to the calculated Euclidean distances.
[0092] In step S27, when the ratio of the smallest Euclidean distance to the second smallest Euclidean distance is less than a preset ratio, the vulnerability function feature corresponding to the smallest Euclidean distance is determined as a matching vulnerability function feature, thereby obtaining the corresponding vulnerability.
[0093] In the present invention, when detecting the vulnerability of the assembly code, if it is determined that there is no CVE annotation in the function vulnerability database in the assembly code, the assembly code and the vulnerability function data information can be feature extracted. According to the feature extraction of the assembly code and the vulnerability function data information, the assembly code feature and the vulnerability function feature can be obtained. After obtaining the corresponding feature, the Euclidean distance between the assembly code feature and the vulnerability function feature can be calculated. Because the number of the vulnerability function features can be multiple, the Euclidean distance between the assembly code feature and the vulnerability function feature can also be multiple. After obtaining multiple Euclidean distances, the vulnerability function feature and the corresponding Euclidean distance between the Euclidean distance of the assembly code feature exceeding the preset threshold can be obtained. According to the obtained Euclidean distance, the smallest Euclidean distance and the second smallest Euclidean distance can be obtained. Because there are multiple Euclidean distances greater than the preset threshold, it can be indicated that the distance between the corresponding vulnerability function feature and the assembly code feature is close, and the most matching vulnerability function feature cannot be determined. Therefore, when the minimum Euclidean distance and the second minimum Euclidean distance are obtained, when the ratio of the minimum Euclidean distance to the second minimum Euclidean distance is less than the preset ratio, the assembly code feature corresponding to the minimum Euclidean distance can be determined as the best matching feature, and the corresponding vulnerability function feature can be determined as the matching vulnerability function feature, so that the vulnerability corresponding to the assembly code can be obtained.
[0094] In one embodiment of the present invention, Figure 6 As shown, the feature extraction process may include:
[0095] In step S28, the assembly code and the vulnerable function data information are decomposed and marked.
[0096] In step S29, feature extraction is performed on the decomposed marked assembly code and vulnerability function data information using the TF-IDF method.
[0097] In step S30, the extracted features are aggregated to obtain corresponding assembly code features and vulnerability function features.
[0098] In the present invention, when extracting features from the assembly code and the vulnerability function data information, the assembly code and the vulnerability function data information can be decomposed and marked, and then the decomposed and marked assembly code and the vulnerability function data information can be feature extracted by the TF-IDF method. After the extraction is completed, the extracted features can be aggregated to obtain the corresponding assembly code features and vulnerability function features.
[0099] On the other hand, the present invention also provides a system for detecting homology vulnerabilities in firmware of an Internet of Things device, the detection system comprising: a code acquisition module and a calculation module. The code acquisition module is used to acquire the firmware of the Internet of Things device to be detected. The calculation module is used to receive the firmware of the Internet of Things device and execute the method for detecting homology vulnerabilities in firmware of an Internet of Things device as described above.
[0100] Through the above technical scheme, the present invention provides a method and system for detecting homology vulnerabilities in the firmware of an Internet of Things device, which can obtain the firmware of the Internet of Things device, and then disassemble and parse the firmware of the Internet of Things device, so as to obtain the assembly code. After obtaining the assembly code, the assembly code can be preprocessed. Public vulnerability function data information can be collected, so that a function vulnerability database can be constructed. After obtaining the function vulnerability database, the preprocessed assembly code can be compared with the function vulnerability database, so that the homology of the assembly code and the vulnerability function data information in the function vulnerability database can be detected. When it is determined that there is homology, it can be determined that there is a vulnerability in the firmware of the Internet of Things device, and the type of vulnerability in the firmware of the Internet of Things device can be determined according to the function vulnerability database. The detection method can perform homology vulnerability detection on the acquired firmware of the Internet of Things device to discover vulnerabilities in the firmware.
[0101] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.
[0102] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0103] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0104] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0105] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0106] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0107] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0108] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0109] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.
Claims
1. A method for detecting homology vulnerabilities in firmware of IoT devices, characterized in that: The detection method comprises: Get IoT device firmware; Disassembling and parsing the IoT device firmware to obtain assembly code; Preprocessing the assembly code; Collect publicly available vulnerability function data information to build a function vulnerability database; The preprocessed assembly code is compared with the function vulnerability database to detect the homology between the assembly code and the function vulnerability database, thereby determining the vulnerability in the IoT device firmware.
2. The detection method according to claim 1, characterized in that: Disassemble and parse the IoT device firmware to obtain assembly code, including: Performing a reverse analysis on the IoT device firmware to obtain system files; Classifying the system files, finding executable files, and extracting relevant information to obtain program source code; Compile the program source code according to different compilation configurations to obtain a binary file; The binary file is disassembled to obtain the assembly code.
3. The detection method according to claim 1, characterized in that: Preprocessing the assembly code includes: Obtaining the assembly code; Obtain all macros in the assembly code and expand all macros; Delete all comments in the assembly code; Deleting extra spaces, tabs, and line breaks in the assembly code; The variable names and function names in the assembly code are standardized.
4. The detection method according to claim 1, characterized in that: Collect publicly available vulnerability function data information to build a function vulnerability database, including: Collect publicly available vulnerability function data information; Normalize the vulnerability function data information, use a unified standard format to describe the vulnerability information, and annotate the vulnerability information through CVE; Marking the vulnerability severity of the vulnerability function data information; According to the severity marking of the vulnerability function data information, the vulnerability function data information is classified according to the severity to construct a function vulnerability database.
5. The detection method according to claim 1, characterized in that: Comparing the preprocessed assembly code with the function vulnerability database to detect the homology between the assembly code and the function vulnerability database, and then determining the vulnerability in the IoT device firmware, including: Obtain the preprocessed assembly code; Determine whether the preprocessed assembly code contains a CVE annotation in the function vulnerability database; When the assembly code contains the CVE annotation in the function vulnerability database, it is determined that the assembly code has a corresponding vulnerability, and then the corresponding vulnerability in the IoT device firmware is determined.
6. The detection method according to claim 5, characterized in that: Comparing the preprocessed assembly code with the function vulnerability database to detect the homology between the assembly code and the function vulnerability database, and then determining the vulnerability in the IoT device firmware, including: When there is no CVE annotation in the function vulnerability database in the assembly code, feature extraction is performed on the assembly code and the vulnerability function data information; Extracting features of the assembly code and the vulnerability function data information to obtain assembly code features and vulnerability function features; Calculating the Euclidean distance between the assembly code feature and the vulnerability function feature; Acquire the vulnerability function feature whose Euclidean distance with the assembly code feature exceeds a preset threshold; According to the calculated Euclidean distance, the smallest Euclidean distance and the second smallest Euclidean distance are obtained; When the ratio of the smallest Euclidean distance to the second smallest Euclidean distance is less than a preset ratio, the vulnerability function feature corresponding to the smallest Euclidean distance is determined as the matching vulnerability function feature, thereby obtaining the corresponding vulnerability.
7. The detection method according to claim 6, characterized in that: According to the feature extraction of the assembly code and the vulnerability function data information, the assembly code features and the vulnerability function features are obtained, including: Decomposing and marking the assembly code and the vulnerable function data information; Performing feature extraction on the decomposed marked assembly code and vulnerability function data information by using the TF-IDF method; The extracted features are aggregated to obtain corresponding assembly code features and the vulnerability function features.
8. A firmware homology vulnerability detection system for IoT devices, characterized in that: The detection system comprises: Code acquisition module, which obtains the firmware of the IoT device that needs to be tested; A computing module is used to receive the IoT device firmware and execute an IoT device firmware homology vulnerability detection method as described in any one of claims 1 to 7.