USENIX Security2024Top-tier venue
MultiFuzz: A Multi-Stream Fuzzer For Testing Monolithic Firmware
Michael Chesser, Surya Nepal, Damith C. Ranasinghe
Abstract
Rapid embedded device proliferation is creating new targets and opportunities for adversaries. However, the complex interactions between firmware and hardware pose challenges to applying automated testing, such as fuzzing. State-of-the-art methods re-host firmware in emulators and facilitate complex interactions with hardware by provisioning for inputs from a diversity of methods (such as interrupts) from a plethora of devices (such as modems). We recognize a significant disconnect between how a fuzzer generates inputs (as a monolithic file) and how the inputs are consumed during re-hosted execution (as a stream, in slices, per peripheral). We demonstrate the disconnect to significantly impact a fuzzer's effectiveness at discovering inputs that explore deeper code and bugs. We rethink the input generation process for fuzzing monolithic firmware and propose a new approach-multi-stream input generation and representation; inputs are now a collection of independent streams, one for each peripheral. We demonstrate the versatility and effectiveness of our approach by implementing: i) stream specific mutation strategies; ii) efficient methods for generating useful values for peripherals; iii) enhancing the use of information learned during fuzzing; and iv) improving a fuzzer's ability to handle roadblocks. We design and build a new fuzzer, MULTIFUZZ, for testing monolithic firmware and evaluate our approach on synthetic and real-world targets. MULTIFUZZ passes all 66 unit tests from a benchmark consisting of 46 synthetic binaries targeting a diverse set of microcontrollers. On an evaluation with 23 real-world firmware targets, MULTIFUZZ outperforms the state-of-the-art fuzzers Fuzzware and Ember-IO. MULTIFUZZ reaches significantly more code on 14 out of the 23 firmware targets and similar coverage on the remainder. Further, MUL-TIFUZZ discovered 18 new bugs on real-world targets, many thoroughly tested by previous fuzzers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 052508d5-df2e-46d6-a8c7-e8d255bd0540Cited by top-tier papers10
- FlexEmu: Towards Flexible MCU Peripheral EmulationChongqing Lei, Zhen Ling, Xiangyu Xu, Shaofeng Li et al.CCS 2025 · 1 citation
- Stop Starving or Stuffing Me: Boosting Firmware Fuzzing Efficiency with On-Demand Input DeliveryShandian Shen, Wei Zhou, Keming Zhao, Peng Liu et al.S&P 2026 · 1 citation
- FirmReBugger: A Benchmark Framework for Monolithic Firmware FuzzersMathew Duong, Michael Chesser, Guy Farrelly, Surya Nepal et al.USENIX Security 2026
- Khost: KVM-based Near Native MCU Firmware RehostingChunlin Wang, Yicheng Yang, Yuan Zhang, Haoyu Xiao et al.USENIX Security 2026
- GDMA: Fully Automated DMA Rehosting via Iterative Type OverlaysTobias Scharnowski, Simeon Hoffmann, Moritz Bley, Simon Wörner et al.USENIX Security 2025
Builds on36
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 428 citations
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik et al.NDSS 2019 · 413 citations
- NAUTILUS: Fishing for Deep Bugs with GrammarsCornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig et al.NDSS 2019 · 291 citations
- FIRM-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process EmulationYaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song et al.USENIX Security 2019 · 279 citations
Related papers
- Fuzzware: Using Precise MMIO Modeling for Effective Firmware FuzzingTobias Scharnowski, Nils Bars, Moritz Schloegel, Eric Gustafson et al.USENIX Security 2022
- Hoedur: Embedded Firmware Fuzzing using Multi-Stream InputsTobias Scharnowski, Simon Wörner, Felix Buchmann, Nils Bars et al.USENIX Security 2023
- Protocol-Aware Firmware Rehosting for Effective Fuzzing of Embedded Network StacksMoritz Bley, Tobias Scharnowski, Simon Wörner, Moritz Schloegel et al.CCS 2025
- DyMA-Fuzz: Dynamic Direct Memory Access Abstraction for Re-hosted Monolithic Firmware FuzzingGuy Farrelly, Michael Chesser, Seyit Camtepe, Damith C. RanasingheICSE 2026
- Icicle: A Re-designed Emulator for Grey-Box Firmware FuzzingMichael Chesser, Surya Nepal, Damith C. RanasingheISSTA 2023 · 10 citations
