<p>The escalating deployment of Internet of Things (IoT) devices across critical sectors such as healthcare, automotive, and industrial automation has introduced unprecedented vulnerabilities at the firmware level. Traditional malware detection approaches—primarily designed for desktop or mobile operating systems—fail to scale effectively to the fragmented, resource-constrained, and architecture-specific landscape of embedded systems. This paper presents a novel hybrid framework that integrates firmware-level static reverse engineering with an artificial intelligence (AI)- augmented deobfuscation engine to detect and analyze malware embedded within IoT firmware binaries. Our method leverages control flow graph (CFG) extraction, opcode sequence learning, and transfer learning from malicious code image embeddings to build a robust model that can generalize across architectures and identify previously unseen malware variants. Additionally, we introduce a dataset of obfuscated firmware samples collected from router firmware, vehicle ECUs, and smart home hubs to evaluate our approach in a real-world setting. The dataset includes real-world firmware-infecting malware such as VPNFilter (targeting routers), UEFI rootkits like LoJax, and automotive ECU malware like the Jeep Cherokee hack, alongside synthetic samples mimicking their embedding and obfuscation behaviors, ensuring focus on threats that persist in firmware layers. Comparative analysis against state-of-the-art static and dynamic analysis tools demonstrates that our approach outperforms existing methods in detection accuracy, time-to-analysis, and resilience to code obfuscation techniques. The proposed framework provides a critical step forward in the evolution of automated embedded security systems, especially for detecting sophisticated threats targeting firmware layers in mission-critical infrastructures.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Firmware-level reverse engineering and AI-augmented deobfuscation for IoT malware detection in embedded systems

  • Milad Rahmati,
  • Nima Rahmati

摘要

The escalating deployment of Internet of Things (IoT) devices across critical sectors such as healthcare, automotive, and industrial automation has introduced unprecedented vulnerabilities at the firmware level. Traditional malware detection approaches—primarily designed for desktop or mobile operating systems—fail to scale effectively to the fragmented, resource-constrained, and architecture-specific landscape of embedded systems. This paper presents a novel hybrid framework that integrates firmware-level static reverse engineering with an artificial intelligence (AI)- augmented deobfuscation engine to detect and analyze malware embedded within IoT firmware binaries. Our method leverages control flow graph (CFG) extraction, opcode sequence learning, and transfer learning from malicious code image embeddings to build a robust model that can generalize across architectures and identify previously unseen malware variants. Additionally, we introduce a dataset of obfuscated firmware samples collected from router firmware, vehicle ECUs, and smart home hubs to evaluate our approach in a real-world setting. The dataset includes real-world firmware-infecting malware such as VPNFilter (targeting routers), UEFI rootkits like LoJax, and automotive ECU malware like the Jeep Cherokee hack, alongside synthetic samples mimicking their embedding and obfuscation behaviors, ensuring focus on threats that persist in firmware layers. Comparative analysis against state-of-the-art static and dynamic analysis tools demonstrates that our approach outperforms existing methods in detection accuracy, time-to-analysis, and resilience to code obfuscation techniques. The proposed framework provides a critical step forward in the evolution of automated embedded security systems, especially for detecting sophisticated threats targeting firmware layers in mission-critical infrastructures.