FirmGuide: Boosting the Capability of Rehosting Embedded Linux Kernels through Model-Guided Kernel Execution
Qiang Liu, Cen Zhang, Lin Ma, Muhui Jiang, Yajin Zhou, Lei Wu, Wenbo Shen, Xiapu Luo, Yang Liu, Kui Ren
摘要
Linux kernel is widely used in embedded systems. To understand practical threats to the Linux kernel, we need to perform dynamic analysis with a full-system emulator, e.g., QEMU. However, due to hardware fragmentation, e.g., various types of peripherals, most embedded systems are not currently supported by QEMU. Though some progress has been made on rehosting firmware, it mainly focuses on user space programs or simple real-time operating systems.The goal of this work is to boost the capability of rehosting the embedded Linux kernels in QEMU. By doing so, dynamic analysis systems can be firstly applied on embedded Linux kernels by leveraging off-the-shelf tools upon QEMU. Accordingly, we proposed a new technique called model-guided kernel execution. It combines the peripheral abstractions in the Linux kernel and kernel-peripheral interactions to semi-automatically generate peripheral models that are then used to synthesize new QEMU virtual machines to start the dynamic analysis.We have implemented a prototype called FirmGuide. It generates 9 peripheral models with full functionality and 64 with minimum functionality covering 26 SoCs. Our evaluation with 6,188 firmware images shows that it can successfully rehost more than 95% of Linux kernels in 2 architectures and 22 versions. None of them can be rehosted in the vanilla QEMU. The result of the LTP benchmark shows the reliability and robustness of the rehosted Linux kernels. We further conduct two security applications, i.e., vulnerability analysis and fuzzing, on the rehosted Linux kernels to demonstrate the usage scenarios.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper7
- Fuzzing BusyBox: Leveraging LLM and Crash Reuse for Embedded Bug UnearthingAsmita, Yaroslav Oliinyk, Michael Scott, Ryan Tsang 等USENIX Security 2024 · 被引用 56 次
- MetaEmu: An Architecture Agnostic Rehosting Framework for Automotive FirmwareZitai Chen, Sam L. Thomas, Flavio D. GarciaCCS 2022 · 被引用 9 次
- A Friend's Eye is A Good Mirror: Synthesizing MCU Peripheral Models from Peripheral DriversChongqing Lei, Zhen Ling, Yue Zhang, Yan Yang 等USENIX Security 2024 · 被引用 8 次
- Pandawan: Quantifying Progress in Linux-based Firmware RehostingIoannis Angelakopoulos, Gianluca Stringhini, Manuel EgeleUSENIX Security 2024 · 被引用 5 次
- FlexEmu: Towards Flexible MCU Peripheral EmulationChongqing Lei, Zhen Ling, Xiangyu Xu, Shaofeng Li 等CCS 2025 · 被引用 1 次
相关 Paper
- ECMO: Peripheral Transplantation to Rehost Embedded Linux KernelsMuhui Jiang, Lin Ma, Yajin Zhou, Qiang Liu 等CCS 2021 · 被引用 11 次
- LEMIX: Enabling Testing of Embedded Applications as Linux ApplicationsSai Ritvik Tanksalkar, Siddharth Muralee, Srihari Danduri, Paschal C. Amusuo 等USENIX Security 2025
- Jetset: Targeted Firmware Rehosting for Embedded SystemsEvan Johnson, Maxwell Bland, Yifei Zhu, Joshua Mason 等USENIX Security 2021 · 被引用 76 次
- User-Space Dependency-Aware Rehosting for Linux-Based Firmware BinariesChuan Qin, Cen Zhang, Yaowen Zheng, Puzhuo Liu 等NDSS 2026 · 被引用 2 次
- Forming Faster Firmware FuzzersLukas Seidel, Dominik Christian Maier, Marius MuenchUSENIX Security 2023
