Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 48
No
1

13.56MHz & 2.45GHz Dual-band RFID Base Station System 개발에 관한 연구 KCI 등재

이태윤, 김웅섭, 최문승, 한운수, 조용철, 권대우, 이창호

대한안전경영과학회 대한안전경영과학회지 제11권 제4호 2009.12 pp.161-168

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

Ubiquitous application is in need of high-level technology to meet various requests for ubiquitous service. In order to adopt ubiquitous technology in not only pilot projects but also regional services, many projects like u-City are implemented in and outside the country. RFID has been known as one of the important technology to provide with core benefits of Ubiquitous services. Because each band of RFID technology has merits and demerits concurrently, single-band RFID system has limitations for various RFID services. Thus, we developed dual-band RFID system enable to provide with 13.56MHz and 2.45GHz RFID service at the same time to compensate the shortage of single-band RFID system. Also we have considered the way that the firmware would control signals without collision, studied battery life and range for tag, and made hardware for dual-band RFID service.

2

Dual-band RFID System 개발에 관한 연구

이태윤, 김웅섭, 최문승, 한운수, 조용철, 권대우, 이창호

대한안전경영과학회 대한안전경영과학회 학술대회논문집 효율적인 안전경영을 위한 전략시스템 2009.11 pp.645-648

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

유비쿼터스 기술을 활용한 U-city와 같은 지역적인 서비스들이 다양한 분야에서 응용되고 있다. 유비쿼터스 기술 중 하나인 RFID는 사용하는 주파수에 따라 장 단점을 가지고 있기 때문에 단일 대역 주파수를 활용한 RFID 시스템은 다양해지는 사용자의 요구를 충족시키기에 명확한 한계를 가지고 있다. 따라서 연구를 통해 13.56MHz와 2.45GHz를 동시에 지원하는 Dual-Band RFID시스템을 개발하여 단일대역 RFID 서비스의 단점을 보완한다. 이를 위해 두 대역의 주파수를 지원하는 하드웨어와 소프트웨어를 개발하고, 능동형 태그의 배터리 수명에 관한 연구를 통해 보다 효율적으로 Dual-Band RFID 시스템을 구성한다.

3

Accelerating firmware vulnerability detection through directed reaching definition analysis

Chen Kai, Zhao Yufei, Guo Jing, Gu Zhimin, Han Longxi

[NRF 연계] 한국통신학회 ICT Express Vol.11 No.5 2025.10 pp.951-956

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

The Internet of Things (IoT) has transformed industries like smart grids and homes. However, firmware security is a growing concern due to vulnerabilities like command execution and buffer overflows. To address this, we propose ReachDFuzz, a directed fuzzing method using reaching-definition analysis. It targets risky library functions affected by external inputs and integrates static analysis for path pruning. Experiments show that ReachDFuzz outperforms FirmAFL in reducing invalid paths and detecting firmware vulnerabilities.

4

4,000원

저궤도 위성 네트워크는 전 지구적 저지연 통신을 제공하지만, 높은 손실률과 급변하는 채널 특성, 제한된 대역폭으로 인해 안정적인 무선 펌웨어 업데이트를 수행하기 어렵다. 기존의 무선 펌웨어 업데이트 방식은 펌웨어 데이터와 제어 메시지를 분리하여 전송하고 패킷 단위 ACK 교환에 의존하기 때문에, 저궤도 위성 통신환경에서 과도한 오버헤드와 반복 재전송을 유발하여 제한된 통신 시간 안에 업데이트하기 어렵다. 본 논문은 이러한 구조적 한계를 해결하기 위해 데이터와 제어 정보를 단일 전송 단위로 통합하고, 경량화된 통합 ACK 구조를 적용한 데이터-제어신호 어그리게이션 기반 전송 기법을 제안한다. 실험 결과에 따르면 제안 기법은 종래 기법 대비 전송 횟수 측면에서 최대 2배 이상의 통신 효율 향상을 보였으며, 펌웨어 크기 증가에 따른 전송 횟수는 약 8% 감소하였다. 또한, 전체 오버헤드는 약 11%를 절감되었고, 처리율은 최대 2배 수준으로 우수한 성능을 입증하였다.

Low Earth Orbit (LEO) satellite networks provide global low-latency communication, but high loss rates, rapidly changing channel characteristics, and limited bandwidth make stable wireless firmware-over-the-air (FOTA) updates challenging. Existing OTA methods transmit firmware data and control messages separately and rely on packet-level ACK exchanges, causing excessive overhead and repeated retransmissions in the LEO environment, making it difficult to complete updates within the limited communication window. This paper proposes a data-control signal aggregation-based transmission technique that integrates data and control information into a single transmission unit and applies a lightweight integrated ACK structure to overcome these structural limitations. According to the experimental results, the proposed technique demonstrated a communication efficiency improvement of up to more than twice that of the conventional technique in terms of transmission count. The transmission count per firmware size increase decreased by approximately 8%. Furthermore, the overall overhead was reduced by approximately 11%, and the throughput proved excellent performance at up to twice the level.

5

Arm 펌웨어 프레임워크 명세 기계화 가능성

김지응

한국ITS학회 한국ITS학회 학술대회 Inclusive ITS Technologies 2024.04 pp.11-13

※ 기관로그인 시 무료 이용이 가능합니다.

3,000원

6

최근 산업 제어 시스템(Industrial Control System) 또는 SCADA(Supervisory Control and Data Acquisition) 등에서 사용되는 PLC(Programmable Logic Controller)에 대한 사이버 공격이 증가하고 있다. 특히, PLC의 펌 웨어에 대한 위변조 공격이 성공할 경우, 대규모의 산업재해를 유발할 수 있다. 본 논문에서는 PLC 장치의 펌웨어에 대한 무결성을 원격으로 검증하는 효율적인 기법을 제안한다. 이 기법은 challenge-response 방식을 기반으로 하 여, 관리 PC가 시리얼 통신으로 연결된 다른 임베디드 장치에 탑재된 펌웨어의 무결성을 검증한다. 제안 기법을 uC/OS-II 운영체제를 탑재한 임베디드 보드에 구현하여 제안 기법의 효율성을 스택사용량과 수행시간의 측면에서 평가한다. 평가 결과, 제안 기법은 적은 메모리와 계산량, 네트워크 전송량을 사용하여 임베디드 환경에 적합하다.

In recent years, cyber attacks on PLCs(Programmable Logic Controllers) in industrial control systems or SCADA(Supervisory Control and Data Acquisition) systems have increased. A successful forgery(or tampering) attack on PLC's firmware may cause a large-scale industrial disaster. In this paper, we propose an efficient technique that remotely verifies the integrity of firmware installed on PLCs. Based on a challenge-response approach, a supervisory PC can verify the integrity of firmware of embedded device connected to the PC via serial communication. We implement the proposed technique in an embedded board running uC/OS-II operating system and evaluate its efficiency in terms of stack usage and execution time. The technique uses a small amount of memory, network transmission and computation, so that it is suitable for embedded environment.

8

5,500원

5G의 발달에 따라 스마트시티, 스마트팩토리, 스마트의료, 자율주행차 등의 영역에서 IoT 기 기가 적극적으로 도입되고 있으며 그에 따라 사용자의 생명까지 위협할 수 있는 보안 위협이 지 속적으로 발생되고 있다. 이러한 보안 위협에 대한 예방과 대응을 위해서는 취약점 분석이 수행 되어야 하지만 기존에 점검하던 웹·모바일 모의해킹 대비 시간과 비용이 많이 들게 된다. 본 연구에서는 IoT 구성 별 위협과 사고 사례를 살펴보고 취약점 분석 항목 별 진행하는 펌웨 어에 대한 분석에 대해서 확인하였다. 또한 IoT 펌웨어에 대한 점검 진행 시 시간과 비용의 문제 점을 제시하고 이를 해결하기 위한 자동화 기법을 제안하였다. 제안한 IoT 펌웨어 취약점 분석 시스템은 펌웨어 정보 수집과 취약점 분석을 진행하는 영역으로 구성되며, 시스템의 효율성을 검토하기 위해 인증정보 노출, 운영체제 명령어 삽입 공격, 버퍼 오버플로우 공격, 불필요한 서 비스 통제 미흡, 알려진 보안취약점 공격의 5가지 항목에 대해 보안전문가를 통해 점검 시간과 취약점 탐지율 측면에서 비교 검토하였다. 본 연구에서 제안한 시스템을 통하여 향후 다양한 영 역에서 IoT 도입 시 보안 취약점 분석에 활용되어 보다 적은 시간으로 최적의 결과 도출할 수 있 는 것이라 기대한다.

With the development of 5G, the Internet of Things is actively being introduced in areas such as smart cities, smart factories, smart medical care, and self-driving cars, and security threats that can threaten the lives of users continue to occur. Vulnerability analysis should be performed to prevent and respond to these security threats, but it will take more time and money than the previously inspected web·mobile penetration testing. In this study, threats and accident cases by composition of the Internet of Things were examined, and the analysis of firmware progressing by vulnerability analysis item was confirmed. In addition, when checking IoT firmware, problems of time and cost were presented and automation techniques were proposed to solve this problem. The proposed IoT firmware vulnerability analysis system consists of firmware information collection and vulnerability analysis, and to review the efficiency of the system, five items were compared. Through the system proposed in this study, it is expected that when the Internet of Things is introduced in various areas in the future, it will be used to analyze security vulnerabilities and produce optimal results in less time.

9

Firmware Design for Portable PCR Devices Controlled by Smart Phones through Wireless Communication SCOPUS

Wan Yeon Lee1, Min Ja Kim, YoungWoong Ko, Jong Dae Kim

보안공학연구지원센터(IJCA) International Journal of Control and Automation Vol.7 No.11 2014.11 pp.97-106

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

In this paper, we design and implement a firmware for portable PCR devices that is controlled by a smart phone. The firmware has the host-local structure in which the firmware receives operation commands from the smart phone and sends operation results to the smart phone through Bluetooth communication. The firmware is designed to accommodate unstable wireless communication of Bluetooth. We implement a low-cost small PCR device with the proposed firmware on microchip PIC18F4550, and verify that the implemented PCR device significantly re

10

An Extension of Firmware-based LFSR One-Time Password Generators

HoonJae Lee, ByungGook Lee

국제인공지능학회(구 한국인터넷방송통신학회) The International Journal of Advanced Smart Convergence Volume 13 Number 2 2024.06 pp.35-43

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

In this paper, we propose two 127-bit LFSR (Linear Feedback Shift Register)-based OTP (One-Time Password) generators. One is a 9-digit decimal OTP generator with thirty taps, while the other is a 12-digit OTP generator with forty taps. The 9-digit OTP generator includes only the positions of Fibonacci numbers to enhance randomness, whereas the 12-digit OTP generator includes the positions of prime numbers and odd numbers. Both proposed OTP generators are implemented on an Arduino module, and randomness evaluations indicate that the generators perform well across six criteria and are straightforward to implement with Arduino.

11

Implementation of Combinational and Sequential Functions in Embedded Firmware

Vaclav Dvorak

보안공학연구지원센터(IJSEIA) International Journal of Software Engineering and Its Applications Vol.2 No.1 2008.01 pp.43-54

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

The paper addresses firmware implementation of multiple-output combinational and sequential Boolean functions based on cascades of Look-Up Tables (LUTs). A LUT cascade is described as a means of compact representation of a large class of Boolean functions, which reduces their evaluation to multiple indirect memory accesses. A LUT-oriented decomposition technique is illustrated on several examples. A specialized micro-engine is proposed for sequential processing of LUT cascades by means of multi-way branching. The presented method provides high performance micro-programmed control for embedded applications.

12

스마트폰의 펌웨어 최적화 방법에 관한 연구 KCI 등재

조욱래, 김성민, 주복규

국제인공지능학회(구 한국인터넷방송통신학회) 한국인터넷방송통신학회 논문지 제12권 제5호 2012.10 pp.177-183

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

스마트폰은 음성이나 문자를 주고받는 단순한 통신 기기에서 벗어나 현대인의 일상생활에서 최고의 필수품 이 되었다. 스마트 폰의 성능 최적화를 위해 성능 향상과 여유 메모리 확보가 가장 많이 시도된다. 전체적인 성능 향 상을 위해서는 컴퓨터 제조사에서 사용하는 CPU 오버 클락 기법을 사용하며, 앱들의 동작을 원활하게 해주는 여유 메모리 확보 기법 또한 흔히 시도된다. 이 논문에서 우리는 일반 사용자가 스마트폰 성능을 최적화할 수 있는 방법을 제시하고, 대중적인 앤드로이드 폰 모델을 대상으로 이 기법을 적용하는 실험을 하고 그 결과를 제시하였다.

Cell-phones functions have advanced so rapidly and they are now called ‘smart-phones.’ Typical approach to optimization the performance of a smartphone is the increasing the speed of device and acquiring more free memory. In this paper, we propose relatively simple techniques that average users can apply to their devices to optimize the performance. For performance upgrade, we proposed an over-clocking technique usually used by computer manufacturers. For memory optimization, we proposed deleting unnecessary apps and replacing with better-functioning apps. We also performed experimentation by applying these techniques to a popular Android phone model and presented the results.

13

Stepwise 동기화 지원을 위한 CMOS 이미지 센서 Firmware 설계 및 개발

박현문, 박수현, 이명수, 서해문, 박우출, 장윤정

[Kisti 연계] 한국시뮬레이션학회 한국시뮬레이션학회논문지 Vol.17 No.4 2008 pp.199-208

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 CMOS 이미지 센서가 저전력, 저가격, 소형화를 이루면서 이를 이용한 하드웨어 및 응용 소프트웨어 연구가 활발하게 이루어지고 있다. 하지만CMOS이미지 센서 제품들은 하드웨어에 비해 아직 응용 소프트웨어 및 펌웨어의 완성도에서 여러 가지 문제를 가진다. CMOS 이미지 센서 기반 폴링 기법은 불필요한 메시지 교환으로 인해 비효율적인 동기화 문제 및 전송 지연이 일정 수준으로 높아지면 데이터 재전송에 대한 오버헤드가 크다. 이러한 이유로 폴링 방식의 구조적 안정성(structural stability)에 문제점을 가진다. 본 논문에서는 MCU를 통한 펌웨어 기반의 고속 동기화 기법으로 폴링 주기를 세분화하여 Stepwise 동기화 기법을 제안하고, 인터럽트 방식을 적용하여 재접속 및 데이터 전송을 개선하였다. 결과적으로 제안한 기법이동기화 시간 및 에러 커넥션에서 20% 이상 뛰어난 성능을 보여주는 것으로 나타났다. 또한 CMOS 이미지 센서 기반의 C328R 보드와 저전력 MCU인 ATmega128L을 이용한 보드를 개발하고, 제공 소프트웨어와 제안된 펌웨어의 카메라 모듈과 동기화 시간 및 에러 커넥션(Error Connection) 등을 비교, 분석하였다.

Lately, since Complementary Metal Oxide Semiconductor(CMOS) image sensor system has low power, low cost and been miniaturized, hardware and applied software studies using these strengths are being carrying on actively. However, the products equipped with CMOS image sensor based polling method yet has several problems in degree of completeness of applied software and firmware, compared with hardware’s. CMOS image sensor system has an ineffective synchronous problem due to superfluous message exchange. Also when a sending of data is delayed continually, overhead of re-sending is large. So because of these, it has a problem in structural stability according to Polling Method. In this study, polling cycle was subdivided in high-speed synchronization method of firmware -based through MCU and synchronization method of Stepwise was proposed. Also, re-connection and data sending were advanced more efficiently by using interrupt way. In conclusion, the proposed method showed more than 20 times better performance in synchronization time and error connection. Also, a board was created by using C328R board of CMOS image sensor-based and ATmega128L which has low power, MCU and camera modules of proposed firmware were compared with provided software and analyzed in synchronization time and error connection.

14

IoT 환경을 위한 Local WAS에서 디바이스 이질성을 줄이는 독립적인 Firmware 설계

이경호, 문은아

[Kisti 연계] 한국전자통신학회 The Journal of the Korean institute of electronic communication sciences Vol.18 No.5 2023 pp.803-808

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

IoT 산업은 매년 기록적인 성장률을 기록하며 성장하고 있으나 IoT 플랫폼을 개발하는데 앞서 개발자들은 보안, 데이터 저장, 디바이스간 이질성 등의 현실적인 문제들에 직면하게 된다. 특히 디바이스간 이질성은 네트워크 유형과 프로토콜로 발생하는데, 다비이스 Firmware를 변경하거나 경우에 따라서는 여러 개의 IoT 플랫폼을 사용해야 한다. 또한 무분별한 IoT 디바이스가 넘처나면서 중복된 센싱으로 데이터가 낭비되기도 한다. 본 논문에서는 Local WAS가 MQTT 프로토콜을 사용하는 IoT 플랫폼 환경에서 디바이스간 이질성 해결을 위한 디바이스 독립적인 Firmware 설계를 제안하고자 한다.

The IoT industry is growing at a record growth rate every year, but developers face practical problems such as security, data storage, and heterogeneity between devices before developing an IoT platform. In particular, heterogeneity between devices occurs due to network type and protocol, and device firmware must be changed or multiple IoT platforms must be used in some cases. In addition, data is wasted due to redundant sensing due to the overflow of indiscriminate IoT devices. In this paper, we propose a device-independent firmware design to solve the heterogeneity between devices in the IoT platform environment where Local WAS uses the MQTT protocol.

15

RTOS(Real Time Operation System) 환경하의 Nd:YAG 레이저 Firmware 설계

김병균, 김휘영, 박구렬, 문동성, 홍정환, 김희제, 조정수

[Kisti 연계] 대한전기학회 대한전기학회 학술대회논문집 2000 pp.2107-2109

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

A pulsed Nd:YAG laser is used widely for materials processing and medical instrument. It's very important to control the laser energy density in those fields using a pulsed Nd:YAG laser. A pulse repetition rate and a pulse width are regarded as the most dominant factors to control the energy density of laser beam. In this paper, the alternating charge and discharge system was designed to adjust a pulse repetition rate This system is controlled by microprocessor and allows to replace an expensive condenser for high frequency to cheap one for low frequency. In addition, The microcontroller monitors the flow of cooling water, short circuit. and miss firing and so on. We designed Nd:YAG laser firmware with smart microcontroller, and want to explain general matters about the firmware from now.

16

A firmware base address search technique based on MIPS architecture using $gp register address value and page granularity

Seok-Joo, Mun, Young-Ho, Sohn

[Kisti 연계] 한국컴퓨터정보학회 Journal of the Korea society of computer and information Vol.28 No.2 2023 pp.1-7

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 논문에서는 MIPS 아키택처 기반 펌웨어의 정적분석 환경을 구축하기 위한 방법으로, $gp 레지스터와 페이지 입상도를 활용한 베이스 주소 후보군 선정 방식을 제안한다. 해당 연구는 기존 연구의 귀납적 추론을 통한 베이스 주소 후보군 선정 방식의 단점인 베이스 주소 탐색 시간 단축을 위한 방법으로 기존 베이스 주소 후보군 선정방식 내 $gp 레지스터를 탐색의 기준점을 바탕으로 페이지 단위의 탐색을 수행하는 방법을 제시한다. 이후, 제시된 방법을 바탕으로 베이스 주소탐색 도구를 구현 및 정적분석 환경구축을 통해 대상 도구의 타당성을 증명하고자 한다. 본 논문에서 제시된 방법은 기존 귀납적 추론을 통한 후보군 선정 방안보다 속도 면에서 더 우수함을 나타낸다.

In this paper, we propose a base address candidate selection method using the $gp register and page granularity as a way to build a static analysis environment for firmware based on MIPS architecture. As a way to shorten the base address search time, which is a disadvantage of the base address candidate selection method through inductive reasoning in existing studies, this study proposes a method to perform page-level search based on the $gp register in the existing base address candidate selection method as a reference point for search. Then, based on the proposed method, a base address search tool is implemented and a static analysis environment is constructed to prove the validity of the target tool. The results show that the proposed method is faster than the existing candidate selection method through inductive reasoning.

17

Automatic Remote Firmware Upgrade Algorithm through Internet for DOCSIS Cable Modems

Kim, Hong-Ik, Park, Sung-Kwon

[Kisti 연계] 대한전자공학회 대한전자공학회 학술대회논문집 2002 pp.1367-1370

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

This paper introduces a new web based method to remotely upgrade firmwares of Cable Modems (CM) which are integral part in providing high-speed Internet access through Hybrid Fiber Coaxial (HFC) networks. Also, it discusses various practical problems arising in the upgrading process. Traditional upgrade has been performed by modifying the CM configuration fie. This paper shows a new web based CM firmware upgrade method using SNMP and MIB which greatly reduces upgrading time, cost and man-hour than traditional firmware upgrade methods. This method has been shown to be very efficient and practical. This method will make significant impact especially because tens of million cable modems are currently waiting to be upgraded soon to the next version from the current version.

18

A Design and Implement of the Medical Nd:YAG Laser Firmware under in ZCC method

Kim, Whi-Young

[Kisti 연계] 제어로봇시스템학회 제어로봇시스템학회 학술대회논문집 2001 p.40

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

The pulsed Nd:YAG laser is the most commonly used type of solid-state laser in many fields. In material processing and medical treatment, the power density control of a laser beam Considered to be significant, which depends on the flashlamp current pulse width and pulse repetition rate. For general laser power supply to control the laser power density, the secondary of the power transformer is connected to the rectifier and filter capacitor. The output of a rectifier is applied to a switching element in the secondary of the transformer. So power supply is complicated and the loss of switching is considerably. In addition, according to increasing pulse repetition rate, charged energy of energy-storage capacitor bank is not transferred sufficiently to flashlamp, and laser output efficiency decreases. In this study, we have ...

19

공개 펌웨어 수집 및 펌웨어 바이너리 SBOM 생성 기법 연구

이인혁, 정수은, 박정흠

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.34 No.6 2024 pp.1307-1319

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

사물인터넷(Internet of Things, IoT) 기기의 보급이 확산함에 따라 보안 위협 또한 증가하고 있다. IP 카메라 해킹과 같은 사례는 IoT 기기 보안의 중요성을 강조한다. 이러한 보안 문제를 해결하기 위해서는 분석가에게 펌웨어 버전 기반으로 구성 요소의 특성을 정리하고, 버전 간의 차이를 식별하여 잠재적인 취약성을 분석할 수 있는 정보를 제공하는 것이 필수적이다. 본 논문에서는 IoT 기기에 사용되는 13,880개의 공개 펌웨어를 수집하고, 이를 대상으로 펌웨어 내 바이너리의 관계를 고려한 'BOM(Bill of Materials)'을 생성하는 방법론을 제안한다. 제안된 방법론을 기반으로 자동화된 펌웨어 정보 추출 도구인 'FIRE(Firmware InfoRmation Extractor)'를 개발하였으며, 이는 기존의 'SBOM(Software Bill of Materials)' 개념을 확장하여 펌웨어에 특화된 BOM 정보를 생성한다. 구축된 펌웨어 데이터세트와 제안된 방법론을 통해 공개된 펌웨어의 구성 요소를 검증하고 추가 분석에 필요한 정보를 제공하여 기존보다 안전한 IoT 기기 생산에 기여될 것으로 기대한다.

The rapid proliferation of Internet of Things (IoT) devices has been accompanied by a corresponding rise in security threats. High-profile incidents, such as IP camera hacking, underscore the critical importance of ensuring IoT device security. Addressing these challenges necessitates providing analysts with comprehensive insights to characterize firmware components by version, identify inter-version differences, and assess potential vulnerabilities. This study introduces a novel methodology for generating a Bill of Materials (BOM) that considers the relationships between binaries within firmware. To support this approach, a dataset comprising 13,880 publicly available firmware samples for IoT devices was collected and analyzed. Furthermore, an automated firmware information extraction tool, FIRE (Firmware InfoRmation Extractor), was developed based on the proposed methodology. FIRE extends the concept of the Software Bill of Materials (SBOM) to generate BOMs tailored specifically for firmware. The constructed firmware dataset and the proposed methodology enable the verification of firmware components and provide actionable insights for subsequent analysis, ultimately contributing to the development of more secure IoT devices.

20

IoT 기기 취약점 분석을 위한 펌웨어 추출 및 분석 환경 구축 방법론

이예준, 이승민, 조효진

[Kisti 연계] 한국정보보호학회 정보보호학회논문지 Vol.34 No.6 2024 pp.1359-1368

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

최근 몇 년간 급속히 발전하고 있는 IoT 기술과 함께 다양한 IoT 기기가 개발되면서 사용자에게 다양한 기능과 편리함을 제공하고 있다. 하지만 이러한 발전과 동시에 개인정보 유출과 같은 보안 위협에 대한 우려도 커지고 있다. 따라서 IoT 기기의 보안 취약점을 사전에 탐지하는 것은 매우 중요하며, 이를 위해 다양한 취약점 분석 연구가 진행되고 있다. 그러나 IoT 기기의 취약점 분석을 위해 펌웨어를 획득하고 분석 환경을 구축하는 과정은 일반화되기 쉽지 않아 많은 연구자가 어려움을 겪고 있다. 본 논문에서는 IoT 기기 중 사용자가 많이 사용하는 IP 카메라와 같은 소형 IoT 기기에 탑재되는 SOP 타입의 칩을 대상으로 펌웨어를 추출하고 분석 환경을 구축하는 범용적인 방법론을 제안한다. 또한, 상용 IoT 기기에 제안된 방법론을 적용하는 과정을 통한 실장비 분석 환경 구축 사례를 통해 IoT 기기 보안 연구자들에게 펌웨어 추출 및 분석환경 구축에 대한 가이드라인을 제공하고자 한다.

In recent years, the rapid development of IoT technology has led to the creation of various IoT devices, offering users a wide range of functionalities and conveniences. However, alongside this advancement, concerns about security threats such as personal information leakage have also grown. Therefore, detecting security vulnerabilities in IoT devices in advance is of utmost importance, and various vulnerability analysis studies are being conducted to address these concerns. However, the process of acquiring firmware and establishing an analysis environment for IoT device vulnerability analysis is not easily standardized, making it challenging for many researchers. In this paper, we propose a universal methodology for extracting firmware and establishing an analysis environment for SOP-type chips embedded in small IoT devices, such as IP cameras, which are widely used by consumers. Furthermore, through the application of the proposed methodology to commercial IoT devices and the process of building an analysis environment for real devices, we aim to provide IoT security researchers with a guideline for firmware extraction and analysis environment setup.

 
1 2 3
페이지 저장