Stop Starving or Stuffing Me: Boosting Firmware Fuzzing Efficiency with On-Demand Input Delivery
Shandian Shen, Wei Zhou, Keming Zhao, Peng Liu, Chung Hwan Kim, Le Guan
Abstract
Firmware fuzzing has gained attention for its ability to identify firmware bugs. While progress has been made in firmware emulation to support fuzzing, current approaches often directly integrate fuzzing tools for general software. However, unlike general software, which receives input as it encounters I/O functions, firmware input can be received asynchronously and independently of the firmware's execution, with uncertain timing and quantity. Without full awareness of firmware's exceptions, existing solutions often imprudently deliver fuzzer-generated input to the firmware in an ad-hoc way. This either overwhelms the processing function of the firmware (i.e., stuffing problem) or fails to deliver enough input data to trigger input processing functions (i.e., starving problem). In both cases, fuzzing capability is weakened. In this paper, we comprehensively investigate the input delivery issue, a unique and less studied field in firmware fuzzing. To accurately determine the optimal timing and quantity for delivering test cases, we leverage the fact that firmware has to check input availability before using any data. Therefore, we employ static and dynamic analysis to map each input processing route into three stages: input retrieval, availability check, and processing. This recovered semantic information allows the fuzzer to accurately deliver input at the availability check points within the expected length range. Since firmware may have multiple input routes, we also optimize the scheduling algorithm to reach more diverse routes. Our prototype, named FIDO, can serve as an add-on to existing firmware fuzzers to enhance their test-case delivery effectiveness. Compared to ad-hoc input delivery methods used in Fuzzware and MULTIFUZZ, FIDO increases their median code coverage by up to 115 % and 54 %, respectively. Compared to SEmu, which requires humans to manually specify input delivery points, FIDO still improves its coverage by up to 19 %. As a result of improved input delivery strategy, FIDO discovers known bugs significantly faster and also identifies five previously unknown bugs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 604782cf-e4ad-492b-aae5-ca37c8774eacBuilds on17
- Charm: Facilitating Dynamic Analysis of Device Drivers of Mobile SystemsSeyed Mohammadjavad Seyed Talebi, Hamid Tavakoli, Hang Zhang, Zheng Zhang et al.USENIX Security 2018 · 81 citations
- Automatic Firmware Emulation through Invalidity-guided Knowledge InferenceWei Zhou, Le Guan, Peng Liu, Yuqing ZhangUSENIX Security 2021 · 76 citations
- Sharing More and Checking Less: Leveraging Common Input Keywords to Detect Bugs in Embedded SystemsLibo Chen, Yanhao Wang, Quanpu Cai, Yunfan Zhan et al.USENIX Security 2021 · 71 citations
- PASAN: Detecting Peripheral Access Concurrency Bugs within Bare-Metal Embedded ApplicationsTaegyu Kim, Vireshwar Kumar, Junghwan Rhee, Jizhou Chen et al.USENIX Security 2021 · 21 citations
- What Your Firmware Tells You Is Not How You Should Emulate It: A Specification-Guided Approach for Firmware EmulationWei Zhou, Lan Zhang, Le Guan, Peng Liu et al.CCS 2022 · 18 citations
Related papers
- MultiFuzz: A Multi-Stream Fuzzer For Testing Monolithic FirmwareMichael Chesser, Surya Nepal, Damith C. RanasingheUSENIX Security 2024 · 13 citations
- Fuzzware: Using Precise MMIO Modeling for Effective Firmware FuzzingTobias Scharnowski, Nils Bars, Moritz Schloegel, Eric Gustafson et al.USENIX Security 2022
- Hoedur: Embedded Firmware Fuzzing using Multi-Stream InputsTobias Scharnowski, Simon Wörner, Felix Buchmann, Nils Bars et al.USENIX Security 2023
- AidFuzzer: Adaptive Interrupt-Driven Firmware Fuzzing via Run-Time State RecognitionJianqiang Wang, Qinying Wang, Tobias Scharnowski, Li Shi et al.USENIX Security 2025
- Protocol-Aware Firmware Rehosting for Effective Fuzzing of Embedded Network StacksMoritz Bley, Tobias Scharnowski, Simon Wörner, Moritz Schloegel et al.CCS 2025
