A methodology for determining the image base of ARM-based industrial control system firmware

Ruijin Zhu, Baofeng Zhang, Junjie Mao, Quanxin Zhang, Yu an Tan*

*此作品的通讯作者

科研成果: 期刊稿件文章同行评审

34 引用 (Scopus)

摘要

A common way to evaluate the security of an industrial control system is to reverse engineer its firmware; this is typically performed when the source code of the device is not available and the firmware is not trusted. However, many industrial control systems are based on the ARM architecture for which the firmware format is always unknown. Therefore, it is difficult to obtain the image base of firmware directly, which significantly complicates reverse engineering efforts. This paper describes a methodology for automatically determining the image base of firmware of ARM-based industrial control systems. Two algorithms, FIND-String and FIND-LDR, are presented that obtain the offsets of strings in firmware and the string addresses loaded by LDR instructions, respectively. Additionally, the DBMSSL algorithm is presented that uses the outputs of the FIND-String and FIND-LDR algorithms to determine the image base of firmware. Experiments are performed with 10 samples of industrial control system firmware collected from the Internet. The experimental results demonstrate that the proposed methodology is effective at determining the image bases of the majority of the firmware samples.

源语言英语
页(从-至)26-35
页数10
期刊International Journal of Critical Infrastructure Protection
16
DOI
出版状态已出版 - 1 3月 2017

指纹

探究 'A methodology for determining the image base of ARM-based industrial control system firmware' 的科研主题。它们共同构成独一无二的指纹。

引用此