As a guest user you are not logged in or recognized by your IP address. You have
access to the Front Matter, Abstracts, Author Index, Subject Index and the full
text of Open Access publications.
Third-party libraries are widely used in IoT firmware, and different versions of libraries have different vulnerabilities. Therefore, extracting versions of third-party libraries is of great significance for discovering known vulnerabilities of IoT devices. However, identifying the version of third-party library in IoT firmware is very challenging due to cross-architecture, cross-compiler, and cross-optimization options issues. To address this challenge, we present FirmAd, a GNN-based system that accurately detects third-party libraries’ versions in IoT firmware. The system leverages a two-stage approach that calculates the similarity of different granularity features to obtain the final TPL version. We evaluate FirmAd on a large-scale dataset comprising 10,699 TPLs and achieve a version information identification accuracy of 92.68%, which is 8% higher than existing methods.
This website uses cookies
We use cookies to provide you with the best possible experience. They also allow us to analyze user behavior in order to constantly improve the website for you. Info about the privacy policy of IOS Press.
This website uses cookies
We use cookies to provide you with the best possible experience. They also allow us to analyze user behavior in order to constantly improve the website for you. Info about the privacy policy of IOS Press.