###
计算机系统应用英文版:2026,35(8):61-73
本文二维码信息
码上扫一扫!
认证位置识别驱动的物联网设备认证绕过漏洞检测
(复旦大学 计算与智能创新学院, 上海 200438)
Authentication-bypass Vulnerability Detection of IoT Devices Driven by Authentication Location Recognition
(College of Computer Science and Artificial Intelligence, Fudan University, Shanghai 200438, China)
摘要
图/表
参考文献
相似文献
本文已被:浏览 26次   下载 37
Received:December 29, 2025    Revised:March 02, 2026
中文摘要: 认证是物联网设备中关键的访问控制机制. 然而, 开发者设计或配置不当将可能导致设备中存在认证绕过漏洞, 从而显著削弱系统安全性. 为识别物联网设备是否存在认证绕过漏洞, 现有研究主要依赖对固件进行人工逆向分析以定位认证逻辑并结合符号执行技术求解可绕过认证的输入条件, 或采用启发式规则来检测漏洞. 然而, 人工逆向分析成本高昂, 而启发式规则的可扩展性有限, 导致认证绕过漏洞检测难以高效、规模化地开展. 针对上述问题, 本文提出了一种面向物联网设备的新型自动化认证绕过漏洞检测框架FirmAuth. 该框架首先通过自动识别固件中各类服务的认证特征, 定位认证相关代码的位置; 随后构建面向认证逻辑的符号执行引擎, 实现对认证绕过漏洞的高效检测. 实验结果表明, 与现有方法相比, FirmAuth的认证绕过漏洞检出率提高了约11.6倍. 目前, 基于该工具发现的相关漏洞已获得4个漏洞编号.
Abstract:Authentication is a key access control mechanism in Internet of Things (IoT) devices. However, improper design or configuration by developers may introduce authentication bypass vulnerabilities, significantly weakening system security. To determine whether IoT devices contain authentication-bypass vulnerabilities, existing studies mainly rely on manual reverse engineering of firmware to locate authentication logic, combined with symbolic execution techniques to identify input conditions that enable authentication-bypass, or they adopt heuristic rules for detection. However, manual reverse engineering incurs high costs, and heuristic rules have limited scalability, making it difficult to conduct authentication bypass vulnerability detection efficiently and at scale. To address these issues, this study proposes a novel automated authentication bypass vulnerability detection framework, FirmAuth, for IoT devices. The framework first automatically identifies authentication features of various services in firmware to locate authentication-related code. It then constructs a symbolic execution engine oriented to authentication logic to achieve efficient detection of authentication-bypass vulnerabilities. Experimental results show that, compared with existing methods, FirmAuth improves the detection rate of authentication-bypass vulnerabilities by approximately 11.6 times. So far, vulnerabilities discovered using this tool have been assigned four vulnerability identifiers.
文章编号:     中图分类号:    文献标志码:
基金项目:
引用文本:
魏子淇,肖浩宇,张源.认证位置识别驱动的物联网设备认证绕过漏洞检测.计算机系统应用,2026,35(8):61-73
WEI Zi-Qi,XIAO Hao-Yu,ZHANG Yuan.Authentication-bypass Vulnerability Detection of IoT Devices Driven by Authentication Location Recognition.COMPUTER SYSTEMS APPLICATIONS,2026,35(8):61-73