
Karonte é uma ferramenta de análise estática para detectar vulnerabilidades multi-binários em firmware embarcado.
Karonte é uma ferramenta de análise estática para detectar vulnerabilidades multi-binárias em firmware embarcado.
O branch master fornece a versão mais recente do Karonte, portada para python3. Para a implementação original e experimentos apresentados em nosso artigo, por favor, verifique o branch IEEE-SP-20 e dê uma olhada em nosso docker container.
Apresentamos nossa abordagem e as descobertas deste trabalho no seguinte artigo de pesquisa:
KARONTE: Detectando Interações Inseguras Multi-binárias em Firmware Embarcado
[PDF]
Nilo Redini, Aravind Machiry, Ruoyu Wang, Chad Spensky, Andrea Continella, Yan Shoshitaishvili, Christopher Kruegel, Giovanni Vigna.
In Proceedings of the IEEE Symposium on Security & Privacy (S&P), Maio de 2020
Se você usar Karonte em uma publicação científica, agradeceríamos citações usando esta entrada Bibtex:
@inproceedings{redini_karonte_20,
author = {Nilo Redini and Aravind Machiry and Ruoyu Wang and Chad Spensky and Andrea Continella and Yan Shoshitaishvili and Christopher Kruegel and Giovanni Vigna},
booktitle = {In Proceedings of the IEEE Symposium on Security & Privacy (S&P)},
month = {May},
title = {KARONTE: Detecting Insecure Multi-binary Interactions in Embedded Firmware},
year = {2020}
}
Existem quatro diretórios principais:
Para executar o karonte, a partir do diretório raiz, basta executar
SINOPSE python tool/karonte.py JSON_CONFIG_FILE [LOG_NAME]
DESCRIÇÃO executa o karonte na amostra de firmware representada pelo JSON_CONFIG_FILE, e salva os resultados em LOG_NAME
EXEMPLO python tool/karonte.py config/NETGEAR/r_7800.json Executa o karonte no firmware NETGEAR R7800
Por padrão, os resultados são salvos em /tmp/ com o sufixo Karonte.txt.
Para inspecionar os alertas gerados, basta executar:
python tool/pretty_print.py LOG_NAME
Você pode obter o dataset que usamos para avaliar o Karonte neste link.