5
ASSESSMENT TIER #3 – SOFTWARE BINARY ANALYSIS
5.1
OBJECTIVE
5.1.1 The objective of this activity is to determine if the firmware and companion
mobile application of the Device Under Test (DUT) is free from:
•
Common software errors such as buffer overflows;
•
Known vulnerabilities in any of the third-party libraries being used;
and
•
Known Malware.
5.1.2 Devices that passes Assessment Tier 3 would likely be capable of resisting
against script kiddies that leverages on readily available exploit kits.
5.2
REQUIREMENTS
5.2.1 The firmware and the companion mobile application shall be subjected to
testing under automated binary analysers which shall be performed by a
testing laboratory.
5.3
PROCESS
5.3.1 The developer shall provide the firmware binary and the companion mobile
applications (if available) of the DUT to the testing laboratory.
5.3.2 To facilitate testing, the firmware binary and companion mobile applications
must be provided in a format that is supported by the binary scanners (e.g.
unencrypted, specific file extension, etc.). The developer shall exercise due
diligence to scan and remove any malwares before submission.
5.3.3 The developer shall also provide a list of all software components (e.g.
Micro_Httpd, OpenSSL, etc.) used in the DUT’s firmware and companion
mobile applications (iOS/Android), and state all permissions requested by
the mobile applications (e.g. camera, location, Bluetooth, etc.).
5.3.4 In addition, the hash values (SHA-256) of all files submitted shall be
provided.
5.3.5 On the receipt of the binary files, the testing laboratory shall proceed to
perform the binary scans using a suite of binary analysis tools.
5.3.6 The generated binary analyser reports shall be analysed by the testing
laboratory.
5.3.7 The required binary analysis tools are also available at the National
Integrated Centre for Evaluation (NICE). For more information, please
contact the CCC team.
CLS Publication #2 | Page 10 of 49