Browse > Article
http://dx.doi.org/10.6109/jkiice.2017.21.5.1003

Vulnerability analysis on the ARMv7 Thumb Architecture  

Kim, Si-Wan (Department of Information Security, Tongmyong University)
Seong, Ki-Taek (Department of Information Security, Tongmyong University)
Abstract
The Internet of Things has attracted considerable research attention in recent years. In order for the new IoT technology to be widely used, the reliability and protection of information is required. IoT systems are very vulnerable to physical security due to their easy accessibility. Along with the development of SoC technology, many operating systems have been developed and many new operating systems have been introduced. In this paper, we describe the vulnerability analysis results for operating systems running on the ARMv7 Thumb Architecture hardware platform. For the recently introduced "Windows 10 IoT Core" operating system, I implemented the Zero-Day Attack by implanting the penetration code developed through the research into a specific IoT system. The virus detection test for the resulting penetration code was validated by referral to the "virustotal" site.
Keywords
IoT Systems; ARMv7 Thumb Architecture; Penetration Testing; Zero-Day Attack; Local System Hacking;
Citations & Related Records
연도 인용수 순위
  • Reference
1 M. S. Smith, "Protecting Privacy in an IoT-Connected World," Information Management Journal, vol. 49, Issue 6, pp. 36-39, Nov./Dec. 2015.
2 R. H. Weber, "Internet of things: Privacy issues revisited," Computer Law & Security Review, Vol. 31, Issue 5, pp. 618 -627, Oct. 2015.   DOI
3 Windows 10 IoT Core [Internet]. Available : https://developer.microsoft.com/ko-kr/windows/iot.
4 The penetration testing standard [Internet]. Available : http://www.pentest-standard.org/index.php/PTES_Technical _Guidelines.
5 ARM architecture penetration information [Internet]. Available : https://www.defcon.org/html/links/dc-archives/dc-18-archive.html.
6 Microsoft Windows platform [Internet]. Available : https://docs.microsoft.com/ko-kr/windows/uwp/get-started/ universal-application-platform-guide.
7 Microsoft Windsock code [Internet]. Available : https://msdn.microsoft.com/ko-kr/library/windows/desktop/ ms737593(v=vs.85).aspx.
8 Analyzes malicious contents by online antivirus engines [Internet]. Available : https://www.virustotal.com/.