USENIX Security2025Top-tier venue
From Constraints to Cracks: Constraint Semantic Inconsistencies as Vulnerability Beacons for Embedded Systems
Jiaxu Zhao, Yuekang Li, Yanyan Zou, Yang Xiao, Naijia Jiang, Yeting Li, Nanyu Zhong, Bingwei Peng, Kunpeng Jian, Wei Huo
Abstract
Embedded systems have a profound impact on our daily lives and work by powering IoT devices and network devices. Ensuring their security is therefore critical. To enhance security and robustness, embedded systems often utilize constraints to validate user inputs. Through an empirical study, we identified that these constraints can be categorized into distinct types and may exhibit semantic inconsistencies across different components. Notably, over 86% of embedded system vulnerabilities originate from such inconsistencies. However, existing static analysis techniques struggle to systematically and accurately identify these inconsistencies, resulting in high false positive rates and an inability to detect certain vulnerabilities effectively. This paper introduces NÜWA, a novel static analysis technique that leverages constraint semantic inconsistencies to detect vulnerabilities in embedded systems. NÜWA achieves scalable and precise vulnerability discovery by addressing the challenges of identifying constraint semantics across diverse implementations and accurately extracting them. We implemented NÜWA and evaluated it using known vulnerability datasets, including 31 vulnerabilities from 13 vendors, and compared its performance to five state-of-the-art (SOTA) tools. NÜWA identified 18, 22, 6, 17, and 19 more vulnerabilities than the respective SOTA tools. Further analysis demonstrates that NÜWA effectively extracts constraints with minimal false positives. To date, NÜWA has uncovered 152 previously unknown vulnerabilities which are all confirmed by the developers, and 88 were assigned with CVE IDs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 89756c42-461e-400a-b71f-dfa4a2ad84aeCited by top-tier papers2
- Through the Authentication Maze: Detecting Authentication Bypass Vulnerabilities in Firmware BinariesNanyu Zhong, Yuekang Li, Yanyan Zou, Jiaxu Zhao et al.NDSS 2026
- Firmenstein: Scaling Dynamic Analysis for Linux-Based Firmware Services via API-Centric Intervention Code SynthesisYanzhong Wang, Wenhui Zhang, Ruigang Liang, Kai Chen et al.USENIX Security 2026
Builds on20
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 428 citations
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo et al.NDSS 2018 · 311 citations
- FIRM-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process EmulationYaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song et al.USENIX Security 2019 · 279 citations
- Snipuzz: Black-box Fuzzing of IoT Firmware via Message Snippet InferenceXiaotao Feng, Ruoxi Sun, Xiaogang Zhu, Minhui Xue et al.CCS 2021 · 146 citations
- Karonte: Detecting Insecure Multi-binary Interactions in Embedded FirmwareNilo Redini, Aravind Machiry, Ruoyu Wang, Chad Spensky et al.S&P 2020 · 128 citations
Related papers
- Leveraging Semantic Relations in Code and Data to Enhance Taint Analysis of Embedded SystemsJiaxu Zhao, Yuekang Li, Yanyan Zou, Zhaohui Liang et al.USENIX Security 2024 · 16 citations
- Sharing More and Checking Less: Leveraging Common Input Keywords to Detect Bugs in Embedded SystemsLibo Chen, Yanhao Wang, Quanpu Cai, Yunfan Zhan et al.USENIX Security 2021 · 71 citations
- Detecting Vulnerabilities in Linux-Based Embedded Firmware with SSE-Based On-Demand Alias AnalysisKai Cheng, Yaowen Zheng, Tao Liu, Le Guan et al.ISSTA 2023 · 28 citations
- Greenhouse: Single-Service Rehosting of Linux-Based Firmware Binaries in User-Space EmulationHui Jun Tay, Kyle Zeng, Jayakrishna Menon Vadayath, Arvind S. Raj et al.USENIX Security 2023
- Determining the Unreachable: Constraint-Guided Reachability Analysis for Dependency VulnerabilitiesWenbu Feng, Xiaohong Li, Ruitao Feng, Yao Zhang et al.OOPSLA 2026 · 1 citation
