Effective On-Hardware Fuzzing of Embedded Operating Systems
Yuheng Shen, Jianzhong Liu, Qiming Guo, Yifei Chu, Qiang Zhang, Heyuan Shi, Yu Jiang
Abstract
Fuzz testing embedded OSs is difficult because their implementations vary widely and rely on specialized hardware. These factors render many existing methods ineffective, since they prevent adapting established fuzzing routines, disrupt communication with the target OS, and impede observation of runtime behavior. This paper introduces EOF, a feedback-guided fuzzer designed to test embedded OSs running on actual hardware. Through the debug port, EOF communicates with the target embedded OS, executes test cases, and collect feedback data, with no dependence on OS services. Then, EOF deploys a cross-platform agent and executes API-aware input across diverse hardware. Last, EOF collects runtime coverage and critical execution events to identify interesting seeds and find potential bugs during fuzzing. We implemented EOF and evaluated its performance on four different embedded OSs, where EOF discovered 19 bugs and achieved a 50.84% coverage improvement on average compared with other comparable fuzzing methods.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 55a04b1d-e881-4248-b8f5-eca8b86cd3ffRelated papers
- Fuzzing Embedded Systems using Debug InterfacesMax Eisele, Daniel Ebert, Christopher Huth, Andreas ZellerISSTA 2023 · 20 citations
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel et al.USENIX Security 2017 · 324 citations
- SFuzz: Slice-based Fuzzing for Real-Time Operating SystemsLibo Chen, Quanpu Cai, Zhenbang Ma, Yanhao Wang et al.CCS 2022 · 16 citations
- PathFuzz: Broadening Fuzzing Horizons with Footprint Memory for CPUsYinan Xu, Sa Wang, Dan Tang, Ninghui Sun et al.DAC 2024 · 6 citations
- Signal Breaker: Fuzzing Digital Signal ProcessorsCameron Santiago Garcia, Matthew HicksASPLOS 2026
