CISPA
Browse
spacesec2023-230707-paper.pdf (129.87 kB)

A Case Study on Fuzzing Satellite Firmware

Download (129.87 kB)
conference contribution
posted on 2024-06-07, 08:23 authored by Tobias ScharnowskiTobias Scharnowski, Felix Buchmann, Simon WörnerSimon Wörner, Thorsten HolzThorsten Holz
Satellites perform critical functions of our modern digital infrastructure, such as providing communications, navigation, and earth observation services. Maintaining a satellite requires remote access, so securing that access is an essential aspect of developing and operating a satellite. While satellites have traditionally not been subjected to regular attacks, this might not hold in the future. Hence, securing satellite firmware—the software that controls the space segment of satellite missions— becomes increasingly relevant. In this work, we perform a case study of applying recent embedded firmware analysis techniques to satellite payload data handling systems. We explore whether FUZZWARE, a state-of-the-art firmware fuzz testing system, can be used to these firmware images. During this case study, we also describe and apply the process of manually optimizing FUZZWARE configurations for firmware targets, and measure the impact of different optimizations. Finally, we identify challenging aspects of fuzz testing satellite firmware and directions for future work to optimize fuzz testing performance in a fully automated manner. As part of our case study, we identified and responsibly disclosed 6 bugs in 3 satellite firmware images.

History

Primary Research Area

  • Threat Detection and Defenses

Name of Conference

Network and Distributed System Security Symposium (NDSS)

Publisher

Internet Society

Open Access Type

  • Unknown

BibTeX

@conference{Scharnowski:Buchmann:Wörner:Holz:2023, title = "A Case Study on Fuzzing Satellite Firmware", author = "Scharnowski, Tobias" AND "Buchmann, Felix" AND "Wörner, Simon" AND "Holz, Thorsten", year = 2023, month = 1, publisher = "Internet Society", doi = "10.14722/spacesec.2023.230707" }

Usage metrics

    Categories

    No categories selected

    Licence

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC