Firmenstein: Scaling Dynamic Analysis for Linux-Based Firmware Services via API-Centric Intervention Code Synthesis
Yanzhong Wang, Wenhui Zhang, Ruigang Liang, Kai Chen, Yi Yang, Zhiyu Zhang, Junyan Jiang
摘要
The rapid proliferation of Linux-based IoT devices necessitates rigorous security analysis. To achieve scalable, hardware-free analysis, firmware rehosting has become essential for constructing faithful emulated environments. However, existing approaches rely on inflexible heuristics to perform semantic-agnostic interventions, failing to generalize to diverse targets and leaving many firmware samples unanalyzable. In this paper, we propose FIRMENSTEIN, a novel API-centric framework that unifies the complex and cumbersome rehosting process into a systematic program analysis and synthesis task. Specifically, we introduce an agentic cross-program analysis built upon the API Dependency Graph to automatically diagnose rehosting roadblocks. Guided by these diagnostics, FIRMENSTEIN further introduces a roadblock-driven workflow to synthesize high-fidelity intervention code that resolves environmental dependencies, thereby enabling successful firmware execution. Evaluation on an LFwC-based dataset demonstrates that FIRMENSTEIN enables 2.5×, 3.1×, and 2.1× more firmware samples to reach interact states than the state-of-the-art rehosting tools Greenhouse, FirmAE, and Penguin, respectively. Even with incomplete rehosting, FIRMENSTEIN executes 29% more basic blocks than Greenhouse. Furthermore, FIRMENSTEIN executes 5.2% more basic blocks than Greenhouse in interactive testing, validates 29 out of 31 known N-day vulnerabilities, and facilitates the discovery of 43 previously unknown vulnerabilities, with 19 CVE IDs assigned to date.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper35
- SWE-agent: Agent-Computer Interfaces Enable Automated Software EngineeringJohn Yang, Carlos E. Jimenez, Alexander Wettig, Kilian Lieret 等NeurIPS 2024 · 被引用 2,059 次
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 被引用 428 次
- FIRM-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process EmulationYaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song 等USENIX Security 2019 · 被引用 279 次
- Plan-and-Solve Prompting: Improving Zero-Shot Chain-of-Thought Reasoning by Large Language ModelsLei Wang, Wanyu Xu, Yihuai Lan, Zhiqiang Hu 等ACL 2023 · 被引用 249 次
- Snipuzz: Black-box Fuzzing of IoT Firmware via Message Snippet InferenceXiaotao Feng, Ruoxi Sun, Xiaogang Zhu, Minhui Xue 等CCS 2021 · 被引用 146 次
相关 Paper
- User-Space Dependency-Aware Rehosting for Linux-Based Firmware BinariesChuan Qin, Cen Zhang, Yaowen Zheng, Puzhuo Liu 等NDSS 2026 · 被引用 2 次
- Greenhouse: Single-Service Rehosting of Linux-Based Firmware Binaries in User-Space EmulationHui Jun Tay, Kyle Zeng, Jayakrishna Menon Vadayath, Arvind S. Raj 等USENIX Security 2023
- FirmAgent: Leveraging Fuzzing to Assist LLM Agents with IoT Firmware Vulnerability DiscoveryJiangan Ji, Chao Zhang, Shuitao Gan, Lin Jian 等NDSS 2026 · 被引用 12 次
- Pandawan: Quantifying Progress in Linux-based Firmware RehostingIoannis Angelakopoulos, Gianluca Stringhini, Manuel EgeleUSENIX Security 2024 · 被引用 5 次
- SHiFT: Semi-hosted Fuzz Testing for Embedded ApplicationsAlejandro Mera, Changming Liu, Ruimin Sun, Engin Kirda 等USENIX Security 2024 · 被引用 15 次
