USENIX Security2026Top-tier venue
FirmReBugger: A Benchmark Framework for Monolithic Firmware Fuzzers
Mathew Duong, Michael Chesser, Guy Farrelly, Surya Nepal, Damith C. Ranasinghe
Abstract
Monolithic Firmware is widespread. Unsurprisingly, fuzz testing firmware is an active research field with new advances addressing the unique challenges in the domain. However, understanding and evaluating improvements by deriving metrics such as code coverage and unique crashes are problematic, leading to a desire for a reliable bug-based benchmark. To address the need, we design and build FirmReBugger, a holistic framework for fairly assessing monolithic firmware fuzzers with a realistic, diverse, bug-based benchmark. FirmReBugger proposes using bug oracles—C syntax expressions of bug descriptors—with an interpreter to automate analysis and accurately report on bugs discovered, discriminating between states of detected , triggered , reached and not reached . Importantly, our idea of benchmarking does not modify the target binary and simply replays fuzzing seeds to isolate the benchmark implementation from the fuzzer while providing a simple means to extend with new bug oracles. Further, analyzing fuzzing roadblocks, we created FirmBench, a set of diverse, real-world binary targets with 313 software bug oracles. Incorporating our analysis of roadblocks challenging monolithic firmware fuzzing, the bench provides for rapid evaluation of future advances. We implement FirmReBugger in a FuzzBench-for-Firmware type service and use FirmBench to evaluate 9 state-of-the art monolithic firmware fuzzers in the style of a reproducibility study, using a 10 CPU-year effort, to report our findings.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 246da5be-cbbd-4b1c-b7fe-59936747f259Builds on20
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik et al.NDSS 2019 · 413 citations
- LAVA: Large-Scale Automated Vulnerability AdditionBrendan Dolan-Gavitt, Patrick Hulin, Engin Kirda, Tim Leek et al.S&P 2016 · 354 citations
- UNIFUZZ: A Holistic and Pragmatic Metrics-Driven Platform for Evaluating FuzzersYuwei Li, Shouling Ji, Yuan Chen, Sizhuang Liang et al.USENIX Security 2021 · 142 citations
- Inception: System-Wide Security Testing of Real-World Embedded Systems SoftwareNassim Corteggiani, Giovanni Camurati, Aurélien FrancillonUSENIX Security 2018 · 117 citations
Related papers
- MultiFuzz: A Multi-Stream Fuzzer For Testing Monolithic FirmwareMichael Chesser, Surya Nepal, Damith C. RanasingheUSENIX Security 2024 · 13 citations
- Fuzzware: Using Precise MMIO Modeling for Effective Firmware FuzzingTobias Scharnowski, Nils Bars, Moritz Schloegel, Eric Gustafson et al.USENIX Security 2022
- FIXREVERTER: A Realistic Bug Injection Methodology for Benchmarking Fuzz TestingZenong Zhang, Zach Patterson, Michael Hicks, Shiyi WeiUSENIX Security 2022
- Stop Starving or Stuffing Me: Boosting Firmware Fuzzing Efficiency with On-Demand Input DeliveryShandian Shen, Wei Zhou, Keming Zhao, Peng Liu et al.S&P 2026 · 1 citation
- PathFuzz: Broadening Fuzzing Horizons with Footprint Memory for CPUsYinan Xu, Sa Wang, Dan Tang, Ninghui Sun et al.DAC 2024 · 6 citations
