← USPTO Patent Grants

Cross-architecture automatic detection method and system for third-party components and security risks related to firmware in internet of things devices thereof

Grant US12579271B2 Kind: B2 Mar 17, 2026

Assignee

HANGZHOU EVERGREEN INFORMATION TECHNOLOGY CO., LTD.

Inventors

Meng Han, Changting Lin, Peng Duan, Melody Xiaoyun Shan, Lei Zhang, Qiang Gong, Binbin Zhao, Haitao Xu, Jiacheng Xu, Bin Wang, Weiping Yu

Abstract

The invention discloses a cross-architecture automated detection method and system for third-party components and security risks, comprising: identify and reverse the firmware of the IoT device, classify the resulting reverse products into binary and non-binary files; disassemble binary files to mine the semantic information in them; convert non-binary files into string text files; build a database containing third-party components and their known CVE; combine pattern matching to scan string text files automatically, collect third-party components in the firmware of IoT device, and collect and retrieve vulnerabilities of corresponding third-party components. Through organically combining the semantic information of the vulnerability assembly code and the semantic information of the firmware assembly code of IoT device, the similarity comparison across architectures and deep learning is realized, and the specific pattern vulnerability is mined and verified automatically. The invention does not require the acquisition of firmware source code, the detection process is automated, greatly reducing the difficulty and workload of manual analysis.

CPC Classifications

G06F 21/572 G06F 21/577 G06F 2221/033 G06F 21/562 G06F 21/563 G06F 21/57 G06N 3/044 G06N 3/08

Filing Date

2022-11-21

Application No.

17991691

Claims

6