Method and system for detecting firmware leakage vulnerability of Internet of Things system

By combining static analysis technology and large language model technology, the firmware update process of IoT supporting applications is automated, and firmware leakage vulnerabilities are identified and detected, which solves the limitations of the existing technology in detecting firmware leakage vulnerabilities in IoT systems, and efficient and accurate vulnerability detection is achieved, which improves the security of IoT devices.

CN120105433APending Publication Date: 2025-06-06SHANDONG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510189223.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

The existing technology has limitations in detecting firmware leak vulnerabilities in IoT systems. Traditional static analysis methods are difficult to understand the firmware update process and accurately track data flows. Dynamic analysis methods have problems with code coverage and environment dependence. The methods based on network traffic analysis mainly focus on the firmware transmission stage, making it difficult to effectively detect vulnerabilities in the firmware acquisition stage.

Method used

By combining static analysis technology and large language model technology, the Internet of Things supporting applications are automatically analyzed to identify the risk of firmware leakage during firmware update. The specific steps include obtaining the installation package of the Internet of Things supporting applications for pre-processing, identifying network request methods related to firmware updates, using static analysis technology to track and reconstruct the target parameter values ​​of the network request methods, extracting firmware update request information, and formatting and classifying the request information through a large language model, and finally simulating the acquisition of firmware files to identify firmware leakage vulnerabilities.

Benefits of technology

It realizes comprehensive and accurate detection of firmware leak vulnerabilities in IoT systems, improves the efficiency and accuracy of vulnerability detection, reduces the cost of manual analysis, and enhances the security and stability of IoT devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120105433A_ABST
    Figure CN120105433A_ABST
Patent Text Reader

Abstract

The invention discloses a method and a system for detecting firmware leakage vulnerabilities of an Internet of Things system, and relates to the technical field of Internet of Things security. The method comprises the following steps: acquiring an installation package of an Internet of Things matched application of an Internet of Things system to be detected, and preprocessing the installation package; identifying a network request method related to firmware update in the matched application, tracking and reconstructing a target parameter value of the network request method by using a static analysis technology, and extracting firmware update request information; the method comprises the following steps: receiving firmware updating request information, formatting and classifying the firmware updating request information by utilizing a large language model, simulating and acquiring a firmware file according to the firmware updating request information, and identifying a firmware leakage vulnerability according to a firmware file acquisition result. According to the method, the matched application of the Internet of Things can be automatically analyzed, and the firmware leakage risk of the matched application in the firmware updating process can be identified, so that the security of the Internet of Things equipment is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet of Things security technology, and in particular to a method and system for detecting firmware leakage vulnerabilities in an Internet of Things system. Background Art

[0002] The statements in this section merely provide background information related to the present invention and do not necessarily constitute prior art.

[0003] In recent years, with the continuous growth of the IoT ecosystem, IoT devices have been widely used in smart homes, industrial control, smart cities and other fields. In order to enable users and manufacturers to conveniently control and remotely manage IoT devices, suppliers usually equip their IoT devices with dedicated supporting applications. After these applications are released by suppliers, users can choose to install them on their mobile devices (smartphones) for important functions such as initialization, operation monitoring and firmware updates of IoT devices.

[0004] Firmware, as the core software of IoT devices, controls the operation logic and function implementation of the device, and stores a large amount of key information related to hardware and algorithms. Therefore, the protection of firmware is the key to the security of IoT devices. However, compared with traditional system updates, firmware updates for IoT devices through supporting applications introduce new security risks. During the firmware update process, if there are vulnerabilities in the firmware update mechanism implemented in the supporting application, it may be exploited by malicious attackers, resulting in firmware leaks. Attackers can maliciously tamper with the firmware, spread it, or invade IoT devices by reversing these leaked firmware files, or even forge update instructions to perform illegal operations.

[0005] Among them, the risks that may exist in the firmware update mechanism of IoT supporting applications mainly include the following aspects: (1) Improper encryption during firmware transmission: Some supporting applications do not take effective encryption measures during the firmware upload or download process. Data transmission may be performed in plain text, which may allow attackers to steal the content.

[0006] (2) Exposure of hard-coded keys and security tokens: Some supporting applications directly hard-code and store keys or security tokens used for authentication and encryption in the code. This information may be obtained by attackers after decompilation, thereby bypassing the verification mechanism and illegally obtaining the firmware.

[0007] (3) Lack of authentication mechanism: The firmware update mechanism implemented by some supporting applications does not strictly authenticate the legitimacy of the firmware update, allowing unauthorized attackers to directly access or obtain firmware files without authentication.

[0008] (4) Improper storage of firmware files: Some supporting applications may save firmware files directly on the local device or cache, or store them on the server in a predictable manner, increasing the risk of leakage.

[0009] At present, security research on IoT devices and their supporting applications mainly focuses on the following aspects: (1) Existing static analysis methods: They can be used to detect some common security vulnerabilities in applications or firmware, such as stack overflow, remote execution, malicious privilege escalation, etc. These methods analyze the source code or intermediate representation of the application to find known vulnerability patterns. However, when such methods are directly applied to detect firmware leakage vulnerabilities in IoT supporting applications, there are the following limitations: a) Lack of understanding of the firmware update process: Traditional static analysis tools usually do not have a deep understanding of the firmware update process of IoT devices and have difficulty identifying specific security risk points related to firmware acquisition and storage. For example, they may not be able to identify specific API calls used in supporting applications to request firmware, as well as the lack or insufficient authentication issues in these API calls.

[0010] b) Insufficient data flow tracking accuracy: Firmware URLs and related parameters may be passed and modified between different components and functions of the application. Traditional static analysis tools may have difficulty accurately tracking the flow of these sensitive data, resulting in missed reports or false positives. For example, the firmware URL may be used after multiple string concatenation operations, or the final value may be determined through complex logical judgments, which poses a challenge to traditional static analysis.

[0011] c) Insufficient understanding of contextual information: To determine whether a firmware update request has a security vulnerability, it is often necessary to analyze it in combination with contextual information. For example, to determine whether an unauthorized firmware download URL will actually lead to firmware leakage, it is necessary to analyze whether the URL is hard-coded in the code or whether it can be obtained through simple enumeration or speculation. Traditional static analysis tools usually lack this complex context understanding capability.

[0012] (2) Dynamic analysis and penetration testing: Discover vulnerabilities by actually running the application and simulating various attack scenarios. This method can effectively discover runtime errors and configuration defects. However, in terms of detecting firmware leakage vulnerabilities in IoT supporting applications, the dynamic analysis method also has some shortcomings: a) Code coverage issue: The effectiveness of dynamic analysis depends largely on the coverage of test cases. If the test cases do not cover the code paths related to firmware updates, potential firmware leakage vulnerabilities will be difficult to detect. Since firmware updates usually occur in specific scenarios, such as device connection, version check, etc., it is often difficult to construct test cases that can trigger all relevant code paths.

[0013] b) Strong environmental dependence: Dynamic analysis usually needs to be performed in a specific device and network environment, which increases the complexity and cost of testing. Simulating real IoT devices and server environments may require a lot of resources and expertise.

[0014] c) Difficult to find logical vulnerabilities: Firmware leakage vulnerabilities are often caused by defects in authentication and authorization logic, which may be difficult to trigger in normal functional testing. For example, a subtle permission judgment error may allow an attacker to access firmware that does not belong to him, and this vulnerability may not be revealed in regular dynamic testing.

[0015] (3) Methods based on network traffic analysis: Some research works analyze the data transmission behavior during the firmware update process by monitoring the network traffic between the supporting application and the server, such as detecting whether the firmware transmission uses an encryption protocol. However, this method mainly focuses on the security of the firmware transmission process, and it is difficult to effectively detect vulnerabilities in the firmware acquisition stage, such as insufficient server-side authentication leading to the leakage of the firmware download URL. In addition, if the supporting application directly packages the firmware in the installation package, or uses other non-standard firmware acquisition methods, the method based on network traffic analysis will also fail.

[0016] (4) Detection tools and methods for specific vulnerabilities: There are also some detection tools and methods for specific types of security vulnerabilities, such as detection tools for hard-coded keys in Android applications. However, there are many types of firmware leakage vulnerabilities in IoT supporting applications, such as firmware URL hardcoding, unauthenticated access, and enumeration attacks based on device IDs, making it difficult to cover all situations with a single tool or method.

[0017] (5) Limitations of existing patents and research results: There are currently some security studies on IoT supporting applications. These studies use automated analysis methods to analyze privacy leaks, SDK security flaws and other issues in supporting applications, but do not involve firmware leakage-related vulnerabilities and cannot detect the existence of firmware leakage vulnerabilities. At the same time, there are also some studies on vulnerabilities in the firmware update process or the firmware itself, but they focus on firmware tampering, known vulnerabilities in the firmware, and do not address the situation where IoT supporting applications have firmware leakage vulnerabilities in the process of obtaining new firmware. The proposed automated tools are also unable to detect the existence of firmware leakage vulnerabilities.

[0018] In summary, existing technical solutions have limitations in detecting firmware leakage vulnerabilities in IoT systems. Traditional static analysis methods have difficulty in deeply understanding the firmware update process and accurately tracking data flows; dynamic analysis methods have problems with code coverage and environmental dependencies; and methods based on network traffic analysis mainly focus on the firmware transmission stage. Therefore, a technical solution is needed that can automatically, efficiently, and accurately detect firmware leakage vulnerabilities based on the characteristics of IoT supporting applications, so as to improve the overall security level of IoT devices. Summary of the invention

[0019] In view of the deficiencies in the prior art, the purpose of the present invention is to provide a method and system for detecting firmware leakage vulnerabilities in an Internet of Things system, which can automatically analyze the supporting applications of the Internet of Things and identify the firmware leakage risks that exist during the firmware update process, thereby improving the security of Internet of Things devices.

[0020] In order to achieve the above object, the present invention is implemented through the following technical solutions: A first aspect of the present invention provides a method for detecting a firmware leakage vulnerability in an Internet of Things system, comprising the following steps: Obtain the installation package of the IoT supporting application of the IoT system to be detected and perform preprocessing; Identify the network request method related to firmware update in the supporting application, and use static analysis technology to track and reconstruct the target parameter value of the network request method to extract the firmware update request information; Receive firmware update request information, format and classify the firmware update request information using a large language model, simulate obtaining a firmware file according to the firmware update request information, and identify a firmware leakage vulnerability according to a firmware file obtaining result.

[0021] Furthermore, the specific steps of preprocessing include: Decompile the installation package of the IoT companion application, generate an intermediate representation for code analysis, and generate a function call graph.

[0022] Furthermore, the specific steps of identifying the network request method related to the firmware update in the supporting application include: Identify the network request client code in the supporting application; In the identified network request client code, further locate information about methods related to firmware update.

[0023] Furthermore, the specific steps of using static analysis technology to track and reconstruct the target parameter value of the network request method are as follows: Identifying target parameters associated with constructing a firmware update request in the firmware update-related method; Using static analysis techniques, tracing the sources and possible values ​​of the target parameters; Based on the results of static analysis, the complete firmware update request information is reconstructed.

[0024] Furthermore, the static analysis technology includes field sensitivity analysis and value set analysis. The field sensitivity analysis is used to distinguish the field values ​​of different object instances when analyzing the values ​​of object fields to avoid confusing the states of different objects; the value set analysis is used to calculate the possible value range of the parameters when the program is running by tracing the parameter assignment statements and data flow backwards and simulating code execution forwards.

[0025] Furthermore, the specific steps of formatting and classifying the firmware update request information using the large language model are as follows: The extracted firmware update request information is formatted using a large language model through prompt word engineering technology; The large language model is used to classify the formatted request information and determine the type and characteristics of the request.

[0026] Furthermore, the specific steps of simulating obtaining the firmware file according to the firmware update request information are: For requests that are classified as not requiring authentication, directly use the extracted URL and request method to initiate the request and check the HTTP response status code; For requests that are classified as requiring identity authentication, if valid authentication information can be obtained through static analysis, the request is initiated with the authentication information. For requests classified as containing dynamic parameters, since it is difficult to obtain the actual values ​​of the dynamic parameters through static analysis, the relevant request information is output to assist in dynamic analysis.

[0027] A second aspect of the present invention provides a system for detecting firmware leakage vulnerabilities in an Internet of Things system, comprising: A preprocessing module is configured to obtain an installation package of an IoT supporting application of the IoT system to be detected and perform preprocessing; A firmware update request extraction module is configured to identify a network request method related to firmware update in a supporting application, and use static analysis technology to track and reconstruct a target parameter value of the network request method to extract firmware update request information; The firmware acquisition verification module is configured to receive firmware update request information, format and classify the firmware update request information using a large language model, simulate obtaining a firmware file according to the firmware update request information, and identify a firmware leakage vulnerability according to the firmware file acquisition result.

[0028] A third aspect of the present invention provides a medium on which a program is stored. When the program is executed by a processor, the steps in the method for detecting firmware leakage vulnerabilities in an Internet of Things system as described in the first aspect of the present invention are implemented.

[0029] The fourth aspect of the present invention provides a device, including a memory, a processor, and a program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps in the method for detecting firmware leakage vulnerabilities in an Internet of Things system as described in the first aspect of the present invention are implemented.

[0030] One or more of the above technical solutions have the following beneficial effects: The present invention discloses a method and system for detecting firmware leakage vulnerabilities in an Internet of Things system. Compared with the prior art, the present invention can more comprehensively and accurately identify the firmware leakage risks existing in the supporting applications of the Internet of Things by combining static analysis technology and large language model technology.

[0031] The present invention can automatically analyze a large number of IoT supporting applications, greatly improving the efficiency of vulnerability detection and reducing the cost of manual analysis. The solution of the present invention has a wide range of application coverage, can discover a variety of firmware leakage risks, and improve the security and stability of the IoT system. For situations that cannot be covered by static analysis, the present invention can also provide effective auxiliary analysis information, thereby improving the efficiency of manual dynamic analysis and increasing the coverage of vulnerability analysis.

[0032] Advantages of additional aspects of the present invention will be given in part in the following description, and in part will become obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] The accompanying drawings in the specification, which constitute a part of the present invention, are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.

[0034] Figure 1 A flow chart of a method for detecting firmware leakage vulnerabilities in an Internet of Things system provided in Embodiment 1 of the present invention.

[0035] Figure 2 This is a system architecture diagram for detecting firmware leakage vulnerabilities in an Internet of Things system provided by Embodiment 2 of the present invention.

[0036] Figure 3 This is a workflow diagram of preprocessing in Example 1 of the present invention.

[0037] Figure 4 This is a workflow diagram for extracting a firmware update request in Embodiment 1 of the present invention.

[0038] Figure 5 This is a workflow diagram for firmware acquisition verification in Embodiment 1 of the present invention. DETAILED DESCRIPTION

[0039] It should be noted that the following detailed descriptions are exemplary and are intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meanings as those commonly understood by those skilled in the art to which the present invention belongs.

[0040] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present invention. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "include" and / or "include" are used in this specification, it indicates the presence of features, steps, operations, devices, components and / or their combinations; Embodiment 1: Embodiment 1 of the present invention provides a method for detecting a firmware leakage vulnerability in an Internet of Things system. Figure 1 As shown, the following steps are included: Step S1: Preprocessing: Obtain the installation package of the IoT supporting application of the IoT system to be detected and perform preprocessing.

[0041] In a specific implementation, an installation package of an IoT supporting application, such as an APK file, is received, the installation package of the IoT supporting application is decompiled, an intermediate representation (Jimple code) for code analysis is generated, and a function call graph is generated. Figure 3 As shown, specifically including: S101: APK decompilation: The decompilation operation of the APK file can adopt an existing decompilation tool, such as dex2jar. Specifically, by calling the dex2jar open source tool, the target IoT supporting application is decompiled from a binary file to a JAR file.

[0042] S102: Jimple code generation: The decompiled JAR file is analyzed by calling the open source Java static analysis framework Soot Framework to generate an intermediate representation that can be used for static analysis, namely Jimple code.

[0043] S103: Function call graph construction: Use the traversal method and the analysis interface of the Soot Framework to analyze the call relationship in the program, analyze all custom classes and their methods contained in the target application, establish call relationship edges, and process virtual function calls and interface calls to generate a function call graph.

[0044] Step S2: Firmware update request extraction: Identify the network request method related to firmware update in the supporting application, and use static analysis technology to track and reconstruct the target parameter value of the network request method to extract the firmware update request information.

[0045] This step is responsible for extracting network request information related to firmware update from the decompiled code, such as Figure 4 As shown, specifically including the following: The specific steps to identify the network request methods related to firmware updates in the companion application include: S201: Request client identification: Identify the entry point method information used to send firmware update network requests in the supporting application, that is, the network request client code, such as the code using network libraries such as OkHttp and Retrofit.

[0046] In a specific implementation, this is achieved by analyzing the network library API called in the code, for example, by searching for instantiations and method calls of classes such as okhttp3.OkHttpClient and retrofit2.Retrofit through a recursive backtracking algorithm, and building a call chain.

[0047] S202: Identifying methods related to firmware update: In the identified network request client code, further locating information about methods related to firmware update, such as methods whose method names contain keywords such as "update" and "firmware".

[0048] In a specific implementation, it can be determined by analyzing features such as method name, parameter type, return value type, etc. For example, the method name contains keywords such as "update", "firmware", "dfu (device firmware update)", or the parameter type contains firmware version information, etc.

[0049] In this embodiment, program slicing technology and regular expression matching are used. First, the target program code segment is sliced, and the method name, variable name and its type, constant value, return value type in the method body and other information used therein are extracted. Then, regular expressions are used to match the information extracted from the code slices to see if it contains keywords related to firmware updates. If the matched keywords meet the preset conditions (for example, two or more keywords related to firmware updates are included at the same time), the method is considered to be related to the firmware update network request.

[0050] Among them, the keywords used here come from some characteristic words extracted from manually analyzing the decompiled codes of a large number of supporting applications, such as some typical words mentioned in the article.

[0051] The specific steps of using static analysis technology to track and reconstruct the target parameter value of the network request method are: S203: Target parameter identification: identifying target parameters related to constructing a firmware update request in the firmware update related method, such as parameters used to construct a request URL, a request method (GET, POST, etc.), a request header, and a request body.

[0052] In a specific implementation, the target code segment is first sliced ​​and analyzed using program slicing technology. Then, based on data flow and control flow analysis, starting from the exit of the network API, the parameter construction process is traced back step by step to find the construction source of the parameters required for the network request, and the type of the corresponding parameters is determined according to the specific method called in the code slice. For example, the incoming parameters of the setBaseUrl method in the Retrofit library correspond to the URL parameters of the request, and the incoming parameters of the addHeader method in the OkHttpClient library correspond to the request header (Header) parameters.

[0053] S204: Static analysis and value reconstruction: using static analysis technology to track the source and possible values ​​of the target parameter.

[0054] In a specific implementation, the static analysis technique includes field sensitivity analysis and value set analysis (VSA).

[0055] (1) The field sensitivity analysis is used to distinguish the field values ​​of different object instances when analyzing the value of an object field, avoid confusing the states of different objects, and improve the accuracy of the analysis. This embodiment is a Java class field. For example, for different object instances of the same class, their field values ​​may be different, and the field sensitivity analysis can distinguish these different values.

[0056] (2) The value set analysis identifies possible values ​​of a specific program entry point through backward program slicing and forward value calculation. Specifically, the value set analysis is used to determine the source of the target parameter in the entry point method by tracing the parameter assignment statements and data flow backward, and reconstruct the value set of the target parameter by forward reconstruction, simulating code execution, calculating the possible value range of the parameter when the program is running. For example, if the value of a parameter comes from dynamic assignment during class initialization or is obtained from a call outside the class, the value set analysis can analyze these possible values.

[0057] The specific steps for calculating the possible range of values ​​of the parameters when the program is running are as follows: according to the code slices collected during the value set analysis, the construction of the values ​​in the code slices is simulated to restore the possible values ​​of the target variable. For example, if the variable a=b[i], and b[i]=c (c is a specific value) exists in the previous text, the value a=c can be obtained through slice simulation execution. In actual programs, there may be multiple updates to the same variable or a dynamic value, so a possible range of values ​​is calculated here.

[0058] S205: Request message reconstruction: Based on the results of static analysis, the complete firmware update request information is reconstructed, including the request URL, request method, request header, request body, etc.

[0059] Furthermore, for the encryption or complex format processing methods contained in the firmware update request, the method semantic information and parameter value set are submitted to the large language model for parsing to obtain its functional logic and parameter information to assist in understanding and reconstructing the request information.

[0060] Step S3: Firmware acquisition verification: receiving firmware update request information, formatting and classifying the firmware update request information using a large language model, simulating the acquisition of firmware files according to the firmware update request information, and identifying firmware leakage vulnerabilities according to the firmware file acquisition results.

[0061] This step is responsible for verifying the extracted firmware update request information and trying to obtain the firmware to determine whether there is a firmware leakage vulnerability. Figure 5 As shown, the specific content of formatting and classifying the firmware update request information using the large language model is: S301: Request message formatting (based on a large language model): The extracted firmware update request information is formatted using a large language model through prompt word engineering technology, for example, the request header, request body and other information are organized into structured data that is easy to analyze.

[0062] The large language model can understand request information of different formats and types and convert them into structured data. In this embodiment, the large language model can use the GPT-4o mini model to format the extracted firmware update request information through prompt word engineering technology, such as organizing the request header, request body and other information into a JSON format that is easy to analyze.

[0063] S302: Request message classification (based on large language model) The formatted request information is classified using the large language model to determine the type and characteristics of the request, such as whether the request requires identity authentication, whether it contains dynamic parameters, etc. Dynamic parameters include device ID, user token, etc. Through preset prompt words, the large language model can classify the request information into different security risk categories according to its characteristics.

[0064] S303: Firmware acquisition attempt: according to the classification result of the request information, attempt to simulate initiating a firmware update request, and check whether the firmware resource can be successfully acquired.

[0065] For complete request information that does not contain dynamic fields, the large language model is used to call the network API and try to obtain the firmware file. Specifically, based on the function calling technology of the large language model, the large language model parses the request content, generates each parameter required to send the request, and then automatically calls the network request API and sends the network request. The reply content of the network request is then sent to the large language model again to determine whether the request is successful and whether the response content can successfully obtain the firmware.

[0066] For incomplete request information containing dynamic fields, auxiliary information is provided to support manual dynamic analysis.

[0067] The specific steps of simulating obtaining the firmware file according to the firmware update request information are as follows: (1) Requests that do not require authentication: For requests that are classified as not requiring authentication, directly initiate the request and check the response status code and content.

[0068] Specifically, directly use the extracted URL and request method to initiate a request and check the HTTP response status code. If the status code is 200 OK, it indicates that there may be a firmware leakage vulnerability of unauthorized access.

[0069] (2) Requests that require authentication: For requests that are classified as requiring authentication, if valid authentication information (such as a hard-coded token) can be obtained through static analysis, the request is initiated with the authentication information. If the information cannot be obtained, the request is considered to contain dynamic parameters.

[0070] (3) Requests containing dynamic parameters: For requests that are classified as containing dynamic parameters, since it is difficult to obtain the actual values ​​of the dynamic parameters through static analysis, the relevant request information is output and presented to the user to assist in dynamic analysis. For example, use a packet capture tool to obtain the dynamic parameters and manually construct a request for testing.

[0071] Among them, the relevant information includes each parameter type contained in the firmware update network request used in the supporting application, such as possible URLs, header fields, possible encryption and decryption algorithms and their keys, etc.

[0072] This embodiment automatically locates the firmware update interface through reverse engineering, and realizes the correlation analysis between the transmission link and the storage node. It integrates static code feature extraction and dynamic request verification technology to accurately identify security risks such as interface authentication defects. This solution can effectively detect the risk of firmware leakage in the update, transmission and storage links, and provide targeted security protection solutions for IoT devices.

[0073] This embodiment successfully discovered firmware leakage risks including but not limited to hard-coded firmware URLs, unauthenticated firmware acquisition, weak identity authentication, and embedded firmware files by conducting large-scale running tests on an open source supporting application dataset (including more than 10,000 applications). After responsible vulnerability disclosure to the corresponding manufacturers, the corresponding CVE vulnerability certification number was applied for.

[0074] It should be noted that the data involved in this embodiment are all derived from public data sets.

[0075] Embodiment 2: Embodiment 2 of the present invention provides a system for detecting firmware leakage vulnerabilities in an Internet of Things system, such as Figure 2 As shown, after obtaining the supporting application installation package APK file, it passes through the pre-processing module 10, the firmware update request extraction module 20 and the firmware acquisition verification module 30 in sequence to obtain the firmware leakage vulnerability detection result.

[0076] Specifically include: The preprocessing module is configured to obtain the installation package of the Internet of Things supporting application of the Internet of Things system to be detected and perform preprocessing.

[0077] The firmware update request extraction module is configured to identify the network request method related to the firmware update in the supporting application, and use static analysis technology to track and reconstruct the target parameter value of the network request method to extract the firmware update request information.

[0078] The firmware update request extraction module specifically includes: (1) a request client identification unit, used to identify the entry point method in the supporting application for sending a firmware update network request; (2) Field sensitivity analysis unit, used to determine the possible values ​​of the class field; (3) a backward tracing unit for determining the source of the target parameter in the entry point method; (4) A forward reconstruction unit, which is used to simulate code execution, reconstruct the value set of the target parameter, and reconstruct the firmware update request information according to the parameters required by the requesting client.

[0079] The firmware acquisition verification module is configured to receive firmware update request information, format and classify the firmware update request information using a large language model, simulate obtaining a firmware file according to the firmware update request information, and identify a firmware leakage vulnerability according to the firmware file acquisition result.

[0080] The firmware acquisition verification module specifically includes: (1) a request information formatting unit, used to format the extracted firmware update request information using a large language model; (2) a request information classification unit, used to classify the formatted request information using a large language model and determine whether the request information contains a dynamic field; (3) A firmware acquisition unit, used to attempt to acquire the firmware file based on the classification results and provide auxiliary analysis information for incomplete request information.

[0081] The system adopts a modular architecture design, including a preprocessing module, a firmware update request extraction module, and a firmware acquisition verification module. It detects the firmware update mechanism in the IoT supporting application and identifies potential firmware leakage risks. The method decompiles the supporting application, extracts the firmware update request information using static analysis technology, and formats and classifies the request information using a large language model, and finally attempts to obtain the firmware file to identify the firmware leakage vulnerability.

[0082] Embodiment three: Embodiment 3 of the present invention provides a medium on which a program is stored. When the program is executed by a processor, the steps in the method for detecting firmware leakage vulnerabilities in an Internet of Things system as described in Embodiment 1 of the present invention are implemented.

[0083] Embodiment 4: Embodiment 4 of the present invention provides a device, including a memory, a processor, and a program stored in the memory and executable on the processor. When the processor executes the program, the steps in the method for detecting firmware leakage vulnerabilities in an Internet of Things system as described in Embodiment 1 of the present invention are implemented.

[0084] The steps involved in the above embodiments 2, 3 and 4 correspond to the method embodiment 1. For the specific implementation methods, please refer to the relevant description part of embodiment 1.

[0085] Those skilled in the art should understand that the modules or steps of the present invention described above can be implemented by a general-purpose computer device, or alternatively, they can be implemented by a program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. The present invention is not limited to any specific combination of hardware and software.

[0086] Although the above describes the specific implementation mode of the present invention in conjunction with the accompanying drawings, it is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art on the basis of the technical solution of the present invention without creative work are still within the scope of protection of the present invention.

Claims

1. A method for detecting firmware leakage vulnerabilities in an Internet of Things system, characterized in that: The following steps are involved: Obtain the installation package of the IoT supporting application of the IoT system to be tested and perform preprocessing; Identify the network request method related to firmware update in the supporting application, and use static analysis technology to track and reconstruct the target parameter value of the network request method to extract the firmware update request information; Receive firmware update request information, format and classify the firmware update request information using a large language model, simulate obtaining a firmware file according to the firmware update request information, and identify a firmware leakage vulnerability according to a firmware file obtaining result.

2. The method for detecting firmware leakage vulnerabilities in an Internet of Things system according to claim 1, characterized in that: The specific steps of preprocessing include: Decompile the installation package of the IoT companion application, generate an intermediate representation for code analysis, and generate a function call graph.

3. The method for detecting firmware leakage vulnerabilities in an Internet of Things system according to claim 1, characterized in that: The specific steps to identify the network request methods related to firmware updates in the companion application include: Identify the network request client code in the supporting application; In the identified network request client code, further locate information about methods related to firmware update.

4. The method for detecting firmware leakage vulnerabilities in an Internet of Things system according to claim 1, characterized in that: The specific steps of using static analysis technology to track and reconstruct the target parameter value of the network request method are: Identifying target parameters associated with constructing a firmware update request in the firmware update-related method; Using static analysis techniques, tracing the sources and possible values ​​of the target parameters; Based on the results of static analysis, the complete firmware update request information is reconstructed.

5. The method for detecting firmware leakage vulnerabilities in an Internet of Things system according to claim 4, characterized in that: The static analysis technology includes field sensitivity analysis and value set analysis. The field sensitivity analysis is used to distinguish the field values ​​of different object instances when analyzing the values ​​of object fields, so as to avoid confusion between the states of different objects. The value set analysis is used to calculate the possible value range of the parameter when the program is running by tracing the parameter assignment statements and data flow backwards and simulating the code execution forwards.

6. The method for detecting firmware leakage vulnerabilities in an Internet of Things system according to claim 1, characterized in that: The specific steps of formatting and classifying the firmware update request information using the large language model are as follows: The extracted firmware update request information is formatted using a large language model through prompt word engineering technology; The large language model is used to classify the formatted request information and determine the type and characteristics of the request.

7. The method for detecting firmware leakage vulnerabilities in an Internet of Things system according to claim 6, characterized in that: The specific steps of simulating obtaining the firmware file according to the firmware update request information are as follows: For requests that are classified as not requiring authentication, directly use the extracted URL and request method to initiate the request and check the HTTP response status code; For requests that are classified as requiring identity authentication, if valid authentication information can be obtained through static analysis, the request is initiated with the authentication information. For requests classified as containing dynamic parameters, since it is difficult to obtain the actual values ​​of the dynamic parameters through static analysis, the relevant request information is output to assist in dynamic analysis.

8. A system for detecting firmware leakage vulnerabilities in an Internet of Things system, characterized in that: include: A preprocessing module is configured to obtain an installation package of an IoT supporting application of the IoT system to be detected and perform preprocessing; A firmware update request extraction module is configured to identify a network request method related to firmware update in a supporting application, and use static analysis technology to track and reconstruct a target parameter value of the network request method to extract firmware update request information; The firmware acquisition verification module is configured to receive firmware update request information, format and classify the firmware update request information using a large language model, simulate obtaining a firmware file according to the firmware update request information, and identify a firmware leakage vulnerability according to the firmware file acquisition result.

9. A computer-readable storage medium, characterized in that: A plurality of instructions are stored therein, and the instructions are suitable for being loaded by a processor of a terminal device and executed by a method for detecting firmware leakage vulnerabilities in an Internet of Things system as described in any one of claims 1-7.

10. A terminal device, characterized in that: The invention comprises a processor and a computer-readable storage medium, wherein the processor is used to implement various instructions; and the computer-readable storage medium is used to store multiple instructions, wherein the instructions are suitable for being loaded by the processor and executing the method for detecting firmware leakage vulnerabilities of an Internet of Things system according to any one of claims 1 to 7.