面向信创产品的固件解析与漏洞扫描框架
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

基金项目:


Firmware Analysis and Vulnerability Scanning Framework for Information Technology Application Innovation Products
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    信创产业作为国家信息技术自主可控战略的关键组成部分, 其固件安全对保障关键信息基础设施的安全具有重要意义. 面对国产处理器架构多样性、国密算法集成以及复杂供应链环境所带来的安全挑战, 本文提出了一种面向信创产品的多平台固件解析与漏洞扫描框架. 该框架通过扩展反汇编工具以支持非主流指令集, 结合动态构建的指纹库与自动化特征提取技术, 实现了对固件中已知漏洞及潜在安全风险的有效检测. 在龙芯、鲲鹏、飞腾这3大主流国产平台的固件样本上开展实验, 结果表明, 该框架的总体固件解析成功率达到75.61%, 优于现有通用工具. 在漏洞检测方面, 平均精确率为72.70%, 召回率为79.00%, F1分数达到75.72%, 在保持较低误报率的同时实现了较高的检测覆盖率, 展现出良好的实用性与可扩展性. 本文为信创产品固件的安全评估提供了可行的技术方案, 具有重要的现实意义与应用价值.

    Abstract:

    As a key component of the national strategy for independent and controllable information technology, firmware security in the information technology application innovation industry is of great significance for ensuring the security of critical information infrastructure. To address security challenges arising from diverse domestic processor architectures, the adoption of national cryptographic algorithms, and complex supply chain environments, this study proposes a multi-platform firmware analysis and vulnerability scanning framework for information technology application innovation products. By extending disassembly tools to support non-mainstream instruction sets and integrating a dynamically constructed fingerprint library with automated feature extraction techniques, the proposed framework effectively detects known vulnerabilities and potential security risks in firmware. Experiments are conducted on firmware samples from three major domestic platforms, including Loongson, Kunpeng, and Phytium. The results show that the overall firmware analysis success rate of the proposed framework reaches 75.61%, which is superior to existing general-purpose tools. In terms of vulnerability detection, the average precision is 72.70%, the recall is 79.00%, and the F1-score reaches 75.72%. The framework achieves high detection coverage while maintaining a relatively low false positive rate, demonstrating strong practicality and scalability. This study provides a feasible technical solution for the security assessment of firmware in information technology application innovation products and has important practical significance and application value.

    参考文献
    相似文献
    引证文献
引用本文

江楠,赵创业,田叶.面向信创产品的固件解析与漏洞扫描框架.计算机系统应用,2026,35(7):316-327

复制
分享
相关视频

文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2025-11-13
  • 最后修改日期:2025-12-02
  • 录用日期:
  • 在线发布日期: 2026-05-22
  • 出版日期:
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62661041 传真: Email:csa@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号