USENIX Security2024Top-tier venue
FFXE: Dynamic Control Flow Graph Recovery for Embedded Firmware Binaries
Ryan Tsang, Asmita, Doreen Joseph, Soheil Salehi, Prasant Mohapatra, Houman Homayoun
Abstract
Control Flow Graphs (CFG) play a significant role as an intermediary analysis in many advanced static and dynamic software analysis techniques. As firmware security and validation for embedded systems becomes a greater concern, accurate CFGs for embedded firmware binaries are crucial for adapting many valuable software analysis techniques to firmware, which can enable more thorough functionality and security analysis. In this work, we present a portable new dynamic CFG recovery technique based on dynamic forced execution that allows us to resolve indirect branches to registered callback functions, which are dependent on asynchronous changes to volatile memory. Our implementation, the Forced Firmware Execution Engine (FFXE), written in Python using the Unicorn emulation framework, is able to identify 100% of known callback functions in our test set of 36 firmware images, something none of the other techniques we tested against were able to do reliably. Using our results and observations, we compare our engine to 4 other CFG recovery techniques and provide both our thoughts on how this work might enhance other tools, and how it might be further developed. With our contributions, we hope to help enable the application of traditionally software-focused security analysis techniques to the hardware interactions that are integral to embedded system firmware.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a34a71c6-521e-4cf2-9339-cf85debf4d00Cited by top-tier papers1
Ask how each one uses itBuilds on5
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- FirmXRay: Detecting Bluetooth Link Layer Vulnerabilities From Bare-Metal FirmwareHaohuang Wen, Zhiqiang Lin, Yinqian ZhangCCS 2020 · 47 citations
- PMP: Cost-effective Forced Execution with Probabilistic Memory Pre-planningWei You, Zhuo Zhang, Yonghwi Kwon, Yousra Aafer et al.S&P 2020 · 29 citations
- Ground Truth for Binary Disassembly is Not EasyChengbin Pang, Tiantai Zhang, Ruotong Yu, Bing Mao et al.USENIX Security 2022
- Refining Indirect Call Targets at the Binary LevelSun Hyoung Kim, Cong Sun, Dongrui Zeng, Gang TanNDSS 2021
Related papers
- Semantics-Guided Control-Flow Reconstruction for Firmware Binaries via Static AnalysisFengjuan Gao, Qingjie Zhu, Yi Zhang, Yu Wang et al.FSE 2026
- FirmSolo: Enabling dynamic analysis of binary Linux-based IoT kernel modulesIoannis Angelakopoulos, Gianluca Stringhini, Manuel EgeleUSENIX Security 2023
- Inception: System-Wide Security Testing of Real-World Embedded Systems SoftwareNassim Corteggiani, Giovanni Camurati, Aurélien FrancillonUSENIX Security 2018 · 117 citations
- FirmGuide: Boosting the Capability of Rehosting Embedded Linux Kernels through Model-Guided Kernel ExecutionQiang Liu, Cen Zhang, Lin Ma, Muhui Jiang et al.ASE 2021 · 10 citations
- CO3: Concolic Co-execution for FirmwareChangming Liu, Alejandro Mera, Engin Kirda, Meng Xu et al.USENIX Security 2024 · 7 citations
