Netinfo Security ›› 2018, Vol. 18 ›› Issue (6): 36-44.doi: 10.3969/j.issn.1671-1122.2018.06.005

• Orginal Article • Previous Articles     Next Articles

Research on Smart Home Vulnerability Mining Technology Based on Taint Analysis

Jian ZHAO1, Rui WANG1(), Siqi LI2   

  1. 1. School of Information Science and Technology, Northwest University, Xi’an Shannxi 710127, China;
    2. Yunnan Police College, Kunming Yunnan 650223, China
  • Received:2018-02-18 Online:2018-06-15 Published:2020-05-11

Abstract:

The control center is the core of the smart home, and it can be controlled remotely through mobile phones, flat panels and other terminals. Once the control center is attacked, the attacker can get the majority of the household control authority, resulting in great destruction. At present, in the intelligent Home Furnishing system, control center through the router using wireless communication technology to connect to the remote terminal equipment, operation and control of all kinds of intelligent home furnishing in the system, the router is directly related to the safety of the whole intelligent system home furnishing and user privacy security.This paper designs a framework to discover vulnerabilities of the router based on sulley, and proposes a three-phase test case generation module (TPFTGM) to guide the generation of specific test cases in the process of fuzzing, and applies the framework to mining vulnerabilities in the Dlink. The experimental results show that the framework can successfully mine and restore the remote code execution vulnerability in the Dlink, and optimize the low efficiency of test cases and low code coverage in Fuzzing.

Key words: smart home, taint tracking, router vulnerabilities, vulnerability detection

CLC Number: