USENIX Security2026Top-tier venue
Firmenstein: Scaling Dynamic Analysis for Linux-Based Firmware Services via API-Centric Intervention Code Synthesis
Yanzhong Wang, Wenhui Zhang, Ruigang Liang, Kai Chen, Yi Yang, Zhiyu Zhang, Junyan Jiang
Abstract
The rapid proliferation of Linux-based IoT devices necessitates rigorous security analysis. To achieve scalable, hardware-free analysis, firmware rehosting has become essential for constructing faithful emulated environments. However, existing approaches rely on inflexible heuristics to perform semantic-agnostic interventions, failing to generalize to diverse targets and leaving many firmware samples unanalyzable. In this paper, we propose FIRMENSTEIN, a novel API-centric framework that unifies the complex and cumbersome rehosting process into a systematic program analysis and synthesis task. Specifically, we introduce an agentic cross-program analysis built upon the API Dependency Graph to automatically diagnose rehosting roadblocks. Guided by these diagnostics, FIRMENSTEIN further introduces a roadblock-driven workflow to synthesize high-fidelity intervention code that resolves environmental dependencies, thereby enabling successful firmware execution. Evaluation on an LFwC-based dataset demonstrates that FIRMENSTEIN enables 2.5×, 3.1×, and 2.1× more firmware samples to reach interact states than the state-of-the-art rehosting tools Greenhouse, FirmAE, and Penguin, respectively. Even with incomplete rehosting, FIRMENSTEIN executes 29% more basic blocks than Greenhouse. Furthermore, FIRMENSTEIN executes 5.2% more basic blocks than Greenhouse in interactive testing, validates 29 out of 31 known N-day vulnerabilities, and facilitates the discovery of 43 previously unknown vulnerabilities, with 19 CVE IDs assigned to date.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 55137ad8-ec72-4206-9fbd-85196cbe64e4Builds on35
- SWE-agent: Agent-Computer Interfaces Enable Automated Software EngineeringJohn Yang, Carlos E. Jimenez, Alexander Wettig, Kilian Lieret et al.NeurIPS 2024 · 2,059 citations
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 428 citations
- FIRM-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process EmulationYaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song et al.USENIX Security 2019 · 279 citations
- Plan-and-Solve Prompting: Improving Zero-Shot Chain-of-Thought Reasoning by Large Language ModelsLei Wang, Wanyu Xu, Yihuai Lan, Zhiqiang Hu et al.ACL 2023 · 249 citations
- Snipuzz: Black-box Fuzzing of IoT Firmware via Message Snippet InferenceXiaotao Feng, Ruoxi Sun, Xiaogang Zhu, Minhui Xue et al.CCS 2021 · 146 citations
Related papers
- User-Space Dependency-Aware Rehosting for Linux-Based Firmware BinariesChuan Qin, Cen Zhang, Yaowen Zheng, Puzhuo Liu et al.NDSS 2026 · 2 citations
- Greenhouse: Single-Service Rehosting of Linux-Based Firmware Binaries in User-Space EmulationHui Jun Tay, Kyle Zeng, Jayakrishna Menon Vadayath, Arvind S. Raj et al.USENIX Security 2023
- FirmAgent: Leveraging Fuzzing to Assist LLM Agents with IoT Firmware Vulnerability DiscoveryJiangan Ji, Chao Zhang, Shuitao Gan, Lin Jian et al.NDSS 2026 · 12 citations
- Pandawan: Quantifying Progress in Linux-based Firmware RehostingIoannis Angelakopoulos, Gianluca Stringhini, Manuel EgeleUSENIX Security 2024 · 5 citations
- SHiFT: Semi-hosted Fuzz Testing for Embedded ApplicationsAlejandro Mera, Changming Liu, Ruimin Sun, Engin Kirda et al.USENIX Security 2024 · 15 citations
