Automatic Security Analysis of IoT Firmware

Automatic Security Analysis of IoT Firmware

While the hacker community has sounded the alarm on IoT security issues in the past several years the companies producing these vulnerable devices often lack the security skills and funds to deal with the problems. What we don’t need is another expensive commercial security product. We need Free Software tools. In this talk, we introduce ByteSweep: A Free Software IoT security analysis platform. This platform will allow IoT device makers, large and small, to conduct fully automated security checks before they ship firmware. First, we will walk through our process for firmware extraction, file data enrichment, key and password hash identification, unsafe function use detection, 3rd party component identification and CVE correlation. Then we will demonstrate the ByteSweep platform using the firmware from a couple of wireless security cameras.

Presented by