AutoPatch: Automated Generation of Hotpatches for Real-Time Embedded Devices
Mohsen Salehi, Karthik Pattabiraman
Abstract
Real-time embedded devices like medical or industrial devices are increasingly targeted by cyber-attacks. Prompt patching is crucial to mitigate the serious consequences of such attacks on these devices. Hotpatching is an approach to apply a patch to mission-critical embedded devices without rebooting them. However, existing hotpatching approaches require developers to manually write the hotpatch for target systems, which is time-consuming and error-prone. To address these issues, we propose AutoPatch 1 , a new hotpatching technique that automatically generates functionally equivalent hotpatches via static analysis of the official patches. AutoPatch introduces a new software triggering approach that supports diverse embedded devices, and preserves the functionality of the official patch. In contrast to prior work, AutoPatch does not rely on hardware support for triggering patches, or on executing patches in specialized virtual machines. We implemented AutoPatch using the LLVM compiler, and evaluated its efficiency, effectiveness and generality using 62 real CVEs on four embedded devices with different specifications and architectures running popular RTOSes. We found that AutoPatch can fix more than 90% of CVEs, and resolve the vulnerability successfully. The results revealed an average total delay of less than 12.7 𝜇𝑠 for fixing the vulnerabilities, representing a performance improvement of 50% over RapidPatch, a state-ofthe-art approach. Further, our memory overhead, on average, was slightly lower than theirs (23%). Finally, AutoPatch was able to generate hotpatches for all four devices without any modifications. CCS CONCEPTS • Security and privacy → Systems security; • Computer systems organization → Real-time systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on8
- Adaptive Android Kernel Live PatchingYue Chen, Yulong Zhang, Zhi Wang, Liangzhao Xia et al.USENIX Security 2017 · 60 citations
- Your Firmware Has Arrived: A Study of Firmware Update VulnerabilitiesYuhao Wu, Jinwen Wang, Yujie Wang, Shixuan Zhai et al.USENIX Security 2024 · 33 citations
- InstaGuard: Instantly Deployable Hot-patches for Vulnerable System Programs on AndroidYaohui Chen, Yuping Li, Long Lu, Yueh-Hsun Lin et al.NDSS 2018 · 32 citations
- Undo Workarounds for Kernel BugsSeyed Mohammadjavad Seyed Talebi, Zhihao Yao, Ardalan Amiri Sani, Zhiyun Qian et al.USENIX Security 2021 · 27 citations
- Automatic Hot Patch Generation for Android KernelsZhengzi Xu, Yulong Zhang, Longri Zheng, Liangzhao Xia et al.USENIX Security 2020
Related papers
- RapidPatch: Firmware Hotpatching for Real-Time Embedded DevicesYi He, Zhenhua Zou, Kun Sun, Zhuotao Liu et al.USENIX Security 2022
- HERA: Hotpatching of Embedded Real-time ApplicationsChristian Niesler, Sebastian Surminski, Lucas DaviNDSS 2021
- Kintsugi: Secure Hotpatching for Code-Shadowing Real-Time Embedded SystemsPhilipp Mackensen, Christian Niesler, Roberto Blanco, Lucas Davi et al.USENIX Security 2025
- APPATCH: Automated Adaptive Prompting Large Language Models for Real-World Software Vulnerability PatchingYu Nong, Haoran Yang, Long Cheng, Hongxin Hu et al.USENIX Security 2025
- ICSPatch: Automated Vulnerability Localization and Non-Intrusive Hotpatching in Industrial Control Systems using Data Dependence GraphsPrashant Hari Narayan Rajput, Constantine Doumanidis, Michail ManiatakosUSENIX Security 2023
