User-Space Dependency-Aware Rehosting for Linux-Based Firmware Binaries
Chuan Qin, Cen Zhang, Yaowen Zheng, Puzhuo Liu, Jian Zhang, Yeting Li, Weidong Zhang, Yang Liu, Limin Sun
Abstract
Firmware rehosting is a fundamental emulation technique that enables dynamic analysis of firmware binaries at scale. Successfully rehosting Linux-based firmware services requires proper emulation of both system-level functionalities like device interfaces and user-space dependencies such as configuration files, inter-process communications. However, existing solutions inadequately leverage user-space knowledge. The init routine, which is the first user-space process sets up operating environments, is often incompletely executed, leading to incomplete initialization. Besides, all emulation failures are treated uniformly, failing to distinguish between direct system-level emulation issues and their indirect effects on user-space dependencies. To fill this gap, we developed FIRMWELL, a framework which first models firmware rehosting as the coordinated emulation of both the target binary and its user-space dependencies. It first rehosts the init routine for environment construction and then launches the target, which is a procedure that typically involves more than one hundred processes. When emulation failures occur, FIRMWELL identifies the blocking process, analyzes incorrectly emulated resources, and applies targeted fixes. The key strategy is to address user-space dependency failures by correcting the underlying system-level emulation errors, while employing program analysis for precise resource value inference. In evaluation of 14,049 firmware images, FIRMWELL successfully rehosted 6,490 services, outperforming state-of-the-art by 1.6 - 8x (3,581 for FirmAE, 3,962 for Greenhouse, and 810 for Pandawan), while reducing average rehosting time by 1.8 - 8.4x (12 vs. 22, 74, and 101 minutes). FIRMWELL was applied to fuzz 1,043 firmware images, uncovering 67 zero-day vulnerabilities with ten assigned CVE identifiers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 356722a1-c181-4e54-aacb-a47ebfe4bb67Builds on33
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard et al.USENIX Security 2017 · 2,003 citations
- Neural Network-based Graph Embedding for Cross-Platform Binary Code Similarity DetectionXiaojun Xu, Chang Liu, Qian Feng, Heng Yin et al.CCS 2017 · 682 citations
- Scalable Graph-based Bug Search for Firmware ImagesQian Feng, Rundong Zhou, Chengcheng Xu, Yao Cheng et al.CCS 2016 · 456 citations
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 428 citations
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo et al.NDSS 2018 · 311 citations
Related papers
- Firmenstein: Scaling Dynamic Analysis for Linux-Based Firmware Services via API-Centric Intervention Code SynthesisYanzhong Wang, Wenhui Zhang, Ruigang Liang, Kai Chen et al.USENIX Security 2026
- Pandawan: Quantifying Progress in Linux-based Firmware RehostingIoannis Angelakopoulos, Gianluca Stringhini, Manuel EgeleUSENIX Security 2024 · 5 citations
- Greenhouse: Single-Service Rehosting of Linux-Based Firmware Binaries in User-Space EmulationHui Jun Tay, Kyle Zeng, Jayakrishna Menon Vadayath, Arvind S. Raj et al.USENIX Security 2023
- FirmGuide: Boosting the Capability of Rehosting Embedded Linux Kernels through Model-Guided Kernel ExecutionQiang Liu, Cen Zhang, Lin Ma, Muhui Jiang et al.ASE 2021 · 10 citations
- Forming Faster Firmware FuzzersLukas Seidel, Dominik Christian Maier, Marius MuenchUSENIX Security 2023
