HouseFuzz: Service-Aware Grey-Box Fuzzing for Vulnerability Detection in Linux-Based Firmware
Haoyu Xiao, Ziqi Wei, Jiarun Dai, Bowen Li, Yuan Zhang, Min Yang
Abstract
To date, grey-box fuzzing has become an essential technique to detect vulnerabilities implied in Linux-based firmware. However, existing fuzzing approaches commonly encounter three overlooked obstacles stemming from firmware service characteristics, which largely hinder the effectiveness and efficiency of vulnerability identification. Firstly, the multi-process nature of firmware services is oversimplified during both the emulation and the fuzzing procedures, limiting the scope of firmware testing. Furthermore, firmware services usually incorporate customized service protocols, which feature rich and stringent semantic constraints, causing unique challenges for input generation. To address these obstacles, this paper proposes a service-aware grey-box fuzzing tool HouseFuzz. During the firmware emulation, HouseFuzz carefully traverses the system initialization procedure for identifying those network-facing and daemon processes overlooked by existing approaches. After that, during the fuzzing procedure, HouseFuzz features a multi-process fuzzing framework, enabling the comprehensive inspection of firmware services activated via multiple processes. Furthermore, HouseFuzz leverages both offline and online firmware service analysis to capture the token-level semantic constraints of customized service protocols, based on which HouseFuzz can effectively generate high-quality test cases. In evaluation, compared to SoTA grey-box firmware fuzzing approaches, HouseFuzz identified 76% more network services, achieved 24.8% more code coverage, and detected 175% more 0-day vulnerabilities on the same firmware dataset.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e8f941a5-4c89-437e-8691-bc79e2565dd7Cited by top-tier papers5
- Bond: Constraint-Directed Fuzzing for Automated Validation of Taint Analysis Results in Linux-based IoT FirmwareJiaqian Peng, Puzhuo Liu, Kai Cheng, Zhaoteng Yan et al.USENIX Security 2026
- PANGOLIN: Fuzzing Multilingual IoT Firmware with LLM-Driven Code AnalysisZhipeng Jia, Xiaokang Yin, Shuitao Gan, Chao Zhang et al.USENIX Security 2026
- Through the Authentication Maze: Detecting Authentication Bypass Vulnerabilities in Firmware BinariesNanyu Zhong, Yuekang Li, Yanyan Zou, Jiaxu Zhao et al.NDSS 2026
- Firmenstein: Scaling Dynamic Analysis for Linux-Based Firmware Services via API-Centric Intervention Code SynthesisYanzhong Wang, Wenhui Zhang, Ruigang Liang, Kai Chen et al.USENIX Security 2026
- Merlin: An Efficient Adaptive Cache Eviction Algorithm via Fine-Grained CharacterizationLiujia Li, Jinhao Guo, Yi Fan, Jianyu Wu et al.OSDI 2026
Builds on30
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard et al.USENIX Security 2017 · 2,003 citations
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 428 citations
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik et al.NDSS 2019 · 413 citations
- Skyfire: Data-Driven Seed Generation for FuzzingJunjie Wang, Bihuan Chen, Lei Wei, Yang LiuS&P 2017 · 382 citations
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo et al.NDSS 2018 · 311 citations
Related papers
- FIRM-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process EmulationYaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song et al.USENIX Security 2019 · 279 citations
- Greenhouse: Single-Service Rehosting of Linux-Based Firmware Binaries in User-Space EmulationHui Jun Tay, Kyle Zeng, Jayakrishna Menon Vadayath, Arvind S. Raj et al.USENIX Security 2023
- AidFuzzer: Adaptive Interrupt-Driven Firmware Fuzzing via Run-Time State RecognitionJianqiang Wang, Qinying Wang, Tobias Scharnowski, Li Shi et al.USENIX Security 2025
- Stop Starving or Stuffing Me: Boosting Firmware Fuzzing Efficiency with On-Demand Input DeliveryShandian Shen, Wei Zhou, Keming Zhao, Peng Liu et al.S&P 2026 · 1 citation
- Fuzzware: Using Precise MMIO Modeling for Effective Firmware FuzzingTobias Scharnowski, Nils Bars, Moritz Schloegel, Eric Gustafson et al.USENIX Security 2022
