USENIX Security2021Top-tier venue
Automatic Firmware Emulation through Invalidity-guided Knowledge Inference
Wei Zhou, Le Guan, Peng Liu, Yuqing Zhang
Abstract
Emulating firmware for microcontrollers is challenging due to the tight coupling between the hardware and firmware. This has greatly impeded the application of dynamic analysis tools to firmware analysis. The state-of-the-art work automatically models unknown peripherals by observing their access patterns, and then leverages heuristics to calculate the appropriate responses when unknown peripheral registers are accessed. However, we empirically found that this approach and the corresponding heuristics are frequently insufficient to emulate firmware. In this work, we propose a new approach called uEmu to emulate firmware with unknown peripherals. Unlike existing work that attempts to build a general model for each peripheral, our approach learns how to correctly emulate firmware execution at individual peripheral access points. It takes the image as input and symbolically executes it by representing unknown peripheral registers as symbols. During symbolic execution, it infers the rules to respond to unknown peripheral accesses. These rules are stored in a knowledge base, which is referred to during the dynamic firmware analysis. uEmu achieved a passing rate of 95% in a set of unit tests for peripheral drivers without any manual assistance. We also evaluated uEmu with real-world firmware samples and new bugs were discovered.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 696e6960-8d1f-4936-a3c9-a6fad844967cCited by top-tier papers32
- SymLM: Predicting Function Names in Stripped Binaries via Context-Sensitive Execution-Aware Code EmbeddingsXin Jin, Kexin Pei, Jun Yeon Won, Zhiqiang LinCCS 2022 · 56 citations
- From One Thousand Pages of Specification to Unveiling Hidden Bugs: Large Language Model Assisted Fuzzing of Matter IoT DevicesXiaoyue Ma, Lannan Luo, Qiang ZengUSENIX Security 2024 · 49 citations
- HEAPSTER: Analyzing the Security of Dynamic Allocators for Monolithic Firmware ImagesFabio Gritti, Fabio Pagani, Ilya Grishchenko, Lukas Dresel et al.S&P 2022 · 31 citations
- : Non-intrusive Feedback-driven Fuzzing for Microcontroller FirmwareWenqiang Li, Jiameng Shi, Fengjun Li, Jingqiang Lin et al.ICSE 2022 · 27 citations
- Fuzzing Embedded Systems using Debug InterfacesMax Eisele, Daniel Ebert, Christopher Huth, Andreas ZellerISSTA 2023 · 20 citations
Builds on8
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 428 citations
- What You Corrupt Is Not What You Crash: Challenges in Fuzzing Embedded DevicesMarius Muench, Jan Stijohann, Frank Kargl, Aurélien Francillon et al.NDSS 2018 · 202 citations
- SweynTooth: Unleashing Mayhem over Bluetooth Low EnergyMatheus E. Garbelini, Chundong Wang, Sudipta Chattopadhyay, Sumei Sun et al.USENIX ATC 2020 · 83 citations
- DICE: Automatic Emulation of DMA Input Channels for Dynamic Firmware AnalysisAlejandro Mera, Bo Feng, Long Lu, Engin KirdaS&P 2021 · 81 citations
- Charm: Facilitating Dynamic Analysis of Device Drivers of Mobile SystemsSeyed Mohammadjavad Seyed Talebi, Hamid Tavakoli, Hang Zhang, Zheng Zhang et al.USENIX Security 2018 · 81 citations
Related papers
- FlexEmu: Towards Flexible MCU Peripheral EmulationChongqing Lei, Zhen Ling, Xiangyu Xu, Shaofeng Li et al.CCS 2025 · 1 citation
- What Your Firmware Tells You Is Not How You Should Emulate It: A Specification-Guided Approach for Firmware EmulationWei Zhou, Lan Zhang, Le Guan, Peng Liu et al.CCS 2022 · 18 citations
- Jetset: Targeted Firmware Rehosting for Embedded SystemsEvan Johnson, Maxwell Bland, Yifei Zhu, Joshua Mason et al.USENIX Security 2021 · 76 citations
- P2IM: Scalable and Hardware-independent Firmware Testing via Automatic Peripheral Interface ModelingBo Feng, Alejandro Mera, Long LuUSENIX Security 2020
- FFXE: Dynamic Control Flow Graph Recovery for Embedded Firmware BinariesRyan Tsang, Asmita, Doreen Joseph, Soheil Salehi et al.USENIX Security 2024 · 8 citations
