GDMA: Fully Automated DMA Rehosting via Iterative Type Overlays
Tobias Scharnowski, Simeon Hoffmann, Moritz Bley, Simon Wörner, Daniel Klischies, Felix Buchmann, Nils Ole Tippenhauer, Thorsten Holz, Marius Muench
摘要
Embedded systems are the critical interface between the physical and the digital world, where security breaches can lead to significant harm. In recent years, rehosting has proven to be an effective method for dynamic security testing of embedded systems. However, existing approaches largely ignore the automated rehosting of Direct Memory Access (DMA), a key mechanism for receiving untrusted data. The only fully automated DMA rehosting approach considers just one out of six common DMA mechanisms, leaving significant gaps in the security analysis of firmware.
In this work, we introduce GDMA, a comprehensive solution for fully automated DMA rehosting. GDMA successfully emulates all six DMA configuration mechanisms by analyzing emulation traces to identify the two critical DMA usage steps: DMA configuration and DMA buffer usage. More specifically, it first collects type information on MMIO registers that consistently behave like pointers. We organize this information in type trees, which capture relationships between MMIO registers and the memory regions they reference. GDMA then overlays and merges these trees to iteratively distill a DMA configuration. By applying this configuration in a generic DMA peripheral, GDMA enables effective testing of DMAdependent firmware. We evaluate GDMA on a total of 114 firmware images. Compared to the state of the art, GDMA is the first to successfully emulate all samples of the state-of-theart benchmark, reaching 3x the DMA mechanism coverage. We also introduce a fully reproducible data set to systematically evaluate DMA rehosting of all six mechanisms. GDMA successfully rehosts all of these, which is a factor of 6x compared to existing methods. Finally, we evaluate GDMA on various DMA-enabled firmware and discover 6 new bugs with 6 assigned CVEs following a coordinated disclosure.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Stop Starving or Stuffing Me: Boosting Firmware Fuzzing Efficiency with On-Demand Input DeliveryShandian Shen, Wei Zhou, Keming Zhao, Peng Liu 等S&P 2026 · 被引用 1 次
- FirmReBugger: A Benchmark Framework for Monolithic Firmware FuzzersMathew Duong, Michael Chesser, Guy Farrelly, Surya Nepal 等USENIX Security 2026
- Protocol-Aware Firmware Rehosting for Effective Fuzzing of Embedded Network StacksMoritz Bley, Tobias Scharnowski, Simon Wörner, Moritz Schloegel 等CCS 2025
- DyMA-Fuzz: Dynamic Direct Memory Access Abstraction for Re-hosted Monolithic Firmware FuzzingGuy Farrelly, Michael Chesser, Seyit Camtepe, Damith C. RanasingheICSE 2026
它引用的顶会 Paper33
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei 等CCS 2018 · 被引用 753 次
- FIRM-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process EmulationYaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song 等USENIX Security 2019 · 被引用 279 次
- CURE: A Security Architecture with CUstomizable and Resilient EnclavesRaad Bahmani, Ferdinand Brasser, Ghada Dessouky, Patrick Jauernig 等USENIX Security 2021 · 被引用 150 次
- PeriScope: An Effective Probing and Fuzzing Framework for the Hardware-OS BoundaryDokyung Song, Felicitas Hetzelt, Dipanjan Das, Chad Spensky 等NDSS 2019 · 被引用 114 次
- Thunderclap: Exploring Vulnerabilities in Operating System IOMMU Protection via DMA from Untrustworthy PeripheralsA. Theodore Markettos, Colin Rothwell, Brett F. Gutstein, Allison Pearce 等NDSS 2019 · 被引用 97 次
相关 Paper
- DICE: Automatic Emulation of DMA Input Channels for Dynamic Firmware AnalysisAlejandro Mera, Bo Feng, Long Lu, Engin KirdaS&P 2021 · 被引用 81 次
- Static Detection of Unsafe DMA Accesses in Device DriversJia-Ju Bai, Tuo Li, Kangjie Lu, Shi-Min HuUSENIX Security 2021 · 被引用 28 次
- Fuzzware: Using Precise MMIO Modeling for Effective Firmware FuzzingTobias Scharnowski, Nils Bars, Moritz Schloegel, Eric Gustafson 等USENIX Security 2022
- Khost: KVM-based Near Native MCU Firmware RehostingChunlin Wang, Yicheng Yang, Yuan Zhang, Haoyu Xiao 等USENIX Security 2026
- Greenhouse: Single-Service Rehosting of Linux-Based Firmware Binaries in User-Space EmulationHui Jun Tay, Kyle Zeng, Jayakrishna Menon Vadayath, Arvind S. Raj 等USENIX Security 2023
