5 ASSESSMENT TIER #3 – SOFTWARE BINARY ANALYSIS 5.1 OBJECTIVE 5.1.1 The objective of this activity is to determine if the firmware and companion mobile application of the Device Under Test (DUT) is free from: • Common software errors such as buffer overflows; • Known vulnerabilities in any of the third-party libraries being used; and • Known Malware. 5.1.2 Devices that passes Assessment Tier 3 would likely be capable of resisting against script kiddies that leverages on readily available exploit kits. 5.2 REQUIREMENTS 5.2.1 The firmware and the companion mobile application shall be subjected to testing under automated binary analysers which shall be performed by a testing laboratory. 5.3 PROCESS 5.3.1 The developer shall provide the firmware binary and the companion mobile applications (if available) of the DUT to the testing laboratory. 5.3.2 To facilitate testing, the firmware binary and companion mobile applications must be provided in a format that is supported by the binary scanners (e.g. unencrypted, specific file extension, etc.). The developer shall exercise due diligence to scan and remove any malwares before submission. 5.3.3 The developer shall also provide a list of all software components (e.g. Micro_Httpd, OpenSSL, etc.) used in the DUT’s firmware and companion mobile applications (iOS/Android), and state all permissions requested by the mobile applications (e.g. camera, location, Bluetooth, etc.). 5.3.4 In addition, the hash values (SHA-256) of all files submitted shall be provided. 5.3.5 On the receipt of the binary files, the testing laboratory shall proceed to perform the binary scans using a suite of binary analysis tools. 5.3.6 The generated binary analyser reports shall be analysed by the testing laboratory. 5.3.7 The required binary analysis tools are also available at the National Integrated Centre for Evaluation (NICE). For more information, please contact the CCC team. CLS Publication #2 | Page 10 of 49

Select target paragraph3