arrow
返回

FuzzDocs: An Automated Security Evaluation Framework for IoT

delete2022-01-01
delete3
delete
OA
AI
M
Myoungsung You
Y
Yeonkeun Kim
J
Jaehan Kim
M
Minjae Seo
S
Sooel Son
S
Seungwon Shin
S
Seungsoo Lee *
DOI:10.1109/ACCESS.2022.3208146delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
As Internet of Things (IoT) devices have rooted themselves in the daily life of billions of people, security threats targeting IoT devices are emerging rapidly. Thus, IoT vendors have employed security testing frameworks to examine IoT devices before releasing them. However, existing frameworks have difficulty providing automated testing, as they require a lot of manual effort to support new devices due to the lack of information about the input formats of the new devices. To address this challenge, we introduce FuzzDocs, a document-based black-box IoT testing framework designed to automatically analyze publicly accessible API documents about target IoT devices and extract information, including valid inputs used to call each functionality of the target devices. Based on the extracted information, it generates valid-enough test inputs that are not easily rejected by target devices but can trigger vulnerabilities deep inside them. This document-based input generation allows FuzzDocs to support new devices without manual work, as well as provide effective security testing. To prove its feasibility, we evaluated FuzzDocs in a real-world IoT environment, and the results showed that FuzzDocs extracted input formats with 93% accuracy from hundreds of pages of documents. Also, it outperformed the existing frameworks in testing coverage and found 35 potential vulnerabilities, including two unexpected system failures in five popular IoT devices.
Keyword:
Internet of Things
Security
Testing
Microprogramming
Fuzzing
Manuals
IoT security
IoT security scanning
fuzz testing
document-based fuzzing

期刊

IEEE Access 封面图
IEEE Access
IF:
3.6
论文数:
9.8W
被引数:
29.4W

机构

I
incheon national university
学者数:
3.9K
论文数: 4.3K
被引数: 4