Lune

USENIX Security2026顶会

Firmenstein: Scaling Dynamic Analysis for Linux-Based Firmware Services via API-Centric Intervention Code Synthesis

Yanzhong Wang, Wenhui Zhang, Ruigang Liang, Kai Chen, Yi Yang, Zhiyu Zhang, Junyan Jiang

2026年份

摘要

The rapid proliferation of Linux-based IoT devices necessitates rigorous security analysis. To achieve scalable, hardware-free analysis, firmware rehosting has become essential for constructing faithful emulated environments. However, existing approaches rely on inflexible heuristics to perform semantic-agnostic interventions, failing to generalize to diverse targets and leaving many firmware samples unanalyzable. In this paper, we propose FIRMENSTEIN, a novel API-centric framework that unifies the complex and cumbersome rehosting process into a systematic program analysis and synthesis task. Specifically, we introduce an agentic cross-program analysis built upon the API Dependency Graph to automatically diagnose rehosting roadblocks. Guided by these diagnostics, FIRMENSTEIN further introduces a roadblock-driven workflow to synthesize high-fidelity intervention code that resolves environmental dependencies, thereby enabling successful firmware execution. Evaluation on an LFwC-based dataset demonstrates that FIRMENSTEIN enables 2.5×, 3.1×, and 2.1× more firmware samples to reach interact states than the state-of-the-art rehosting tools Greenhouse, FirmAE, and Penguin, respectively. Even with incomplete rehosting, FIRMENSTEIN executes 29% more basic blocks than Greenhouse. Furthermore, FIRMENSTEIN executes 5.2% more basic blocks than Greenhouse in interactive testing, validates 29 out of 31 known N-day vulnerabilities, and facilitates the discovery of 43 previously unknown vulnerabilities, with 19 CVE IDs assigned to date.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext 55137ad8-ec72-4206-9fbd-85196cbe64e4

它引用的顶会 Paper35

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖