USENIX Security2026Top-tier venue
Bond: Constraint-Directed Fuzzing for Automated Validation of Taint Analysis Results in Linux-based IoT Firmware
Jiaqian Peng, Puzhuo Liu, Kai Cheng, Zhaoteng Yan, Jie Liu, Chengnian Sun, Hongsong Zhu
Abstract
Firmware vulnerabilities in IoT devices pose serious security threats, yet state-of-the-art taint analysis tools often generate large numbers of reports with limited validation. We present Bond, a directed fuzzing framework that bridges static taint analysis and dynamic vulnerability validation. Bond introduces constraint-guided input mutation by integrating three categories of constraints with six semantic types, enabling efficient exploration of paths associated with taint reports. We evaluate Bond on 19 IoT devices from 8 vendors, covering 2,776 taint reports produced by four state-of-the-art taint analyzers. Bond successfully validated 1,349 reports as real vulnerabilities, including 155 previously unknown vulnerabilities, of which 108 have been assigned CVE/PSV identifiers. On 60 known vulnerabilities, Bond achieved a 91.67% recall rate. Compared with four leading IoT fuzzers, Bond improves vulnerability validation by up to 5.5X. Ablation studies further demonstrate the effectiveness of Bond's key components and constraint extraction. These results establish Bond as a practical and effective framework for validating firmware taint analysis results.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3485b515-09c8-428a-95c4-082b6e8f1fd0Builds on35
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 428 citations
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo et al.NDSS 2018 · 311 citations
- FIRM-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process EmulationYaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song et al.USENIX Security 2019 · 279 citations
- What You Corrupt Is Not What You Crash: Challenges in Fuzzing Embedded DevicesMarius Muench, Jan Stijohann, Frank Kargl, Aurélien Francillon et al.NDSS 2018 · 202 citations
- Neural Nets Can Learn Function Type Signatures From BinariesZheng Leong Chua, Shiqi Shen, Prateek Saxena, Zhenkai LiangUSENIX Security 2017 · 175 citations
Related papers
- Bridge: High-Order Taint Vulnerabilities Detection in Linux-Based IoT FirmwareJiaqian Peng, Puzhuo Liu, Yicheng Zeng, Kai Cheng et al.S&P 2026 · 1 citation
- FirmAgent: Leveraging Fuzzing to Assist LLM Agents with IoT Firmware Vulnerability DiscoveryJiangan Ji, Chao Zhang, Shuitao Gan, Lin Jian et al.NDSS 2026 · 12 citations
- Operation Mango: Scalable Discovery of Taint-Style Vulnerabilities in Binary Firmware ServicesWil Gibbs, Arvind S. Raj, Jayakrishna Menon Vadayath, Hui Jun Tay et al.USENIX Security 2024 · 20 citations
- Labrador: Response Guided Directed Fuzzing for Black-box IoT DevicesHangtian Liu, Shuitao Gan, Chao Zhang, Zicong Gao et al.S&P 2024 · 25 citations
- PATA: Fuzzing with Path Aware Taint AnalysisJie Liang, Mingzhe Wang, Chijin Zhou, Zhiyong Wu et al.S&P 2022 · 84 citations
