USENIX Security2023Top-tier venue
Forming Faster Firmware Fuzzers
Lukas Seidel, Dominik Christian Maier, Marius Muench
Abstract
A recent trend for assessing the security of an embedded system's firmware is rehosting, the art of running the firmware in a virtualized environment, rather than on the original hardware platform. One significant use case for firmware rehosting is fuzzing to dynamically uncover security vulnerabilities. However, state-of-the-art implementations suffer from high emulator-induced overhead, leading to less-than-optimal execution speeds. Instead of emulation, we propose near-native rehosting: running embedded firmware as a Linux userspace process on a high-performance system that shares the instruction set family with the targeted device. We implement this approach with SAFIREFUZZ, a throughput-optimized rehosting and fuzzing framework for ARM Cortex-M firmware. SAFIREFUZZ takes monolithic binary-only firmware images and uses high-level emulation (HLE) and dynamic binary rewriting to run them on far more powerful hardware with low overhead. By replicating experiments of HALucinator, the state-of-the-art HLE-based rehosting system for binary firmware, we show that SAFIREFUZZ can provide a 690x throughput increase on average during 24-hour fuzzing campaigns while covering up to 30% more basic blocks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ab93dddf-0694-49a5-8055-f49b26891a56Cited by top-tier papers14
- SoK: Prudent Evaluation Practices for FuzzingMoritz Schloegel, Nils Bars, Nico Schiller, Lukas Bernhard et al.S&P 2024 · 69 citations
- SHiFT: Semi-hosted Fuzz Testing for Embedded ApplicationsAlejandro Mera, Changming Liu, Ruimin Sun, Engin Kirda et al.USENIX Security 2024 · 15 citations
- MultiFuzz: A Multi-Stream Fuzzer For Testing Monolithic FirmwareMichael Chesser, Surya Nepal, Damith C. RanasingheUSENIX Security 2024 · 13 citations
- User-Space Dependency-Aware Rehosting for Linux-Based Firmware BinariesChuan Qin, Cen Zhang, Yaowen Zheng, Puzhuo Liu et al.NDSS 2026 · 2 citations
- FlexEmu: Towards Flexible MCU Peripheral EmulationChongqing Lei, Zhen Ling, Xiangyu Xu, Shaofeng Li et al.CCS 2025 · 1 citation
Builds on19
- FIRM-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process EmulationYaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song et al.USENIX Security 2019 · 279 citations
- What You Corrupt Is Not What You Crash: Challenges in Fuzzing Embedded DevicesMarius Muench, Jan Stijohann, Frank Kargl, Aurélien Francillon et al.NDSS 2018 · 202 citations
- RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and SanitizationSushant Dinesh, Nathan Burow, Dongyan Xu, Mathias PayerS&P 2020 · 187 citations
- Automatic Firmware Emulation through Invalidity-guided Knowledge InferenceWei Zhou, Le Guan, Peng Liu, Yuqing ZhangUSENIX Security 2021 · 76 citations
- Jetset: Targeted Firmware Rehosting for Embedded SystemsEvan Johnson, Maxwell Bland, Yifei Zhu, Joshua Mason et al.USENIX Security 2021 · 76 citations
Related papers
- Khost: KVM-based Near Native MCU Firmware RehostingChunlin Wang, Yicheng Yang, Yuan Zhang, Haoyu Xiao et al.USENIX Security 2026
- HALucinator: Firmware Re-hosting Through Abstraction Layer EmulationAbraham A. Clements, Eric Gustafson, Tobias Scharnowski, Paul Grosen et al.USENIX Security 2020
- LEMIX: Enabling Testing of Embedded Applications as Linux ApplicationsSai Ritvik Tanksalkar, Siddharth Muralee, Srihari Danduri, Paschal C. Amusuo et al.USENIX Security 2025
- Fuzzware: Using Precise MMIO Modeling for Effective Firmware FuzzingTobias Scharnowski, Nils Bars, Moritz Schloegel, Eric Gustafson et al.USENIX Security 2022
- Greenhouse: Single-Service Rehosting of Linux-Based Firmware Binaries in User-Space EmulationHui Jun Tay, Kyle Zeng, Jayakrishna Menon Vadayath, Arvind S. Raj et al.USENIX Security 2023
