RTCON: Context-Adaptive Function-Level Fuzzing for RTOS Kernels
Eunkyu Lee, Junyoung Park, Insu Yun
Abstract
—Real-Time Operating System (RTOS) is widely used in embedded systems with its various subsystems such as Blue-tooth and Wi-Fi. As its functionalities grow, its attack surface also expands, exposing it to more security threats. To address this, dynamic testing techniques like fuzzing have been widely applied to embedded systems. However, for RTOS, these techniques struggle to effectively test deeply located functions within the kernel due to their complexity. In this paper, we present RTC ON , a context-adaptive function-level fuzzer for RTOS kernels. RTC ON performs function-level fuzzing on any target functions within the RTOS kernel by adaptively generating function contexts during fuzzing. Additionally, RTC ON employs Multi-layer Classification to classify crashes by confidence levels, helping analysts focus on high-confidence crashes. We implemented the prototype of RTC ON and evaluated it on four popular RTOS kernels: Zephyr, RIOT, FreeRTOS, and ThreadX. As a result, RTC ON discovered 27 bugs, including 25 new bugs. We reported all of them to maintainers and received 14 CVEs. RTC ON also demonstrated its effectiveness in crash classification, achieving a 92.7% precision for high-confidence crashes, compared to a 5.8% precision for low-confidence crashes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d3dc5f0b-0f4b-41c5-9798-88f0f5576aeaBuilds on22
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 428 citations
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo et al.NDSS 2018 · 311 citations
Related papers
- SFuzz: Slice-based Fuzzing for Real-Time Operating SystemsLibo Chen, Quanpu Cai, Zhenbang Ma, Yanhao Wang et al.CCS 2022 · 16 citations
- The Cost of Performance: Breaking ThreadX with Kernel Object Masquerading AttacksXinhui Shao, Zhen Ling, Yue Zhang, Huaiyu Yan et al.USENIX Security 2025
- DROIDFUZZ: Proprietary Driver Fuzzing for Embedded Android DevicesJianzhong Liu, Yuheng Shen, Yifei Chu, Qiang Zhang et al.DAC 2025
- Effectively Sanitizing Embedded Operating SystemsJianzhong Liu, Yuheng Shen, Yiru Xu, Hao Sun et al.DAC 2024 · 7 citations
- LEMIX: Enabling Testing of Embedded Applications as Linux ApplicationsSai Ritvik Tanksalkar, Siddharth Muralee, Srihari Danduri, Paschal C. Amusuo et al.USENIX Security 2025
