LuaTaint: A Static Analysis System for Web Configuration Interface Vulnerability of Internet of Things Devices

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Xiang, Jiahui, Fu, Lirong, Ye, Tong, Liu, Peiyu, Le, Huan, Zhu, Liming, Wang, Wenhai
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866913768870510592
author Xiang, Jiahui
Fu, Lirong
Ye, Tong
Liu, Peiyu
Le, Huan
Zhu, Liming
Wang, Wenhai
author_facet Xiang, Jiahui
Fu, Lirong
Ye, Tong
Liu, Peiyu
Le, Huan
Zhu, Liming
Wang, Wenhai
contents The diversity of web configuration interfaces for IoT devices has exacerbated issues such as inadequate permission controls and insecure interfaces, resulting in various vulnerabilities. Owing to the varying interface configurations across various devices, the existing methods are inadequate for identifying these vulnerabilities precisely and comprehensively. This study addresses these issues by introducing an automated vulnerability detection system, called LuaTaint. It is designed for the commonly used web configuration interface of IoT devices. LuaTaint combines static taint analysis with a large language model (LLM) to achieve widespread and high-precision detection. The extensive traversal of the static analysis ensures the comprehensiveness of the detection. The system also incorporates rules related to page handler control logic within the taint detection process to enhance its precision and extensibility. Moreover, we leverage the prodigious abilities of LLM for code analysis tasks. By utilizing LLM in the process of pruning false alarms, the precision of LuaTaint is enhanced while significantly reducing its dependence on manual analysis. We develop a prototype of LuaTaint and evaluate it using 2,447 IoT firmware samples from 11 renowned vendors. LuaTaint has discovered 111 vulnerabilities. Moreover, LuaTaint exhibits a vulnerability detection precision rate of up to 89.29%.
format Preprint
id arxiv_https___arxiv_org_abs_2402_16043
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle LuaTaint: A Static Analysis System for Web Configuration Interface Vulnerability of Internet of Things Devices
Xiang, Jiahui
Fu, Lirong
Ye, Tong
Liu, Peiyu
Le, Huan
Zhu, Liming
Wang, Wenhai
Cryptography and Security
Software Engineering
The diversity of web configuration interfaces for IoT devices has exacerbated issues such as inadequate permission controls and insecure interfaces, resulting in various vulnerabilities. Owing to the varying interface configurations across various devices, the existing methods are inadequate for identifying these vulnerabilities precisely and comprehensively. This study addresses these issues by introducing an automated vulnerability detection system, called LuaTaint. It is designed for the commonly used web configuration interface of IoT devices. LuaTaint combines static taint analysis with a large language model (LLM) to achieve widespread and high-precision detection. The extensive traversal of the static analysis ensures the comprehensiveness of the detection. The system also incorporates rules related to page handler control logic within the taint detection process to enhance its precision and extensibility. Moreover, we leverage the prodigious abilities of LLM for code analysis tasks. By utilizing LLM in the process of pruning false alarms, the precision of LuaTaint is enhanced while significantly reducing its dependence on manual analysis. We develop a prototype of LuaTaint and evaluate it using 2,447 IoT firmware samples from 11 renowned vendors. LuaTaint has discovered 111 vulnerabilities. Moreover, LuaTaint exhibits a vulnerability detection precision rate of up to 89.29%.
title LuaTaint: A Static Analysis System for Web Configuration Interface Vulnerability of Internet of Things Devices
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2402.16043