SHiFT: Semi-hosted Fuzz Testing for Embedded Applications
Alejandro Mera, Changming Liu, Ruimin Sun, Engin Kirda, Long Lu
摘要
Modern microcontrollers (MCU)s are ubiquitous on critical embedded applications in the IoT era. Therefore, securing MCU firmware is fundamental. To analyze MCU firmware security, existing works mostly adopt re-hosting based techniques. These techniques transplant firmware to an engineered platform and require tailored hardware or emulation of different parts of the MCU. As a result, security practitioners have observed low-fidelity, false positives, and reduced compatibility with real and complex hardware. This paper presents SHiFT, a framework that leverages the industry semihosting philosophy to provide a brandnew method that analyzes firmware natively in MCUs. This novel method provides high fidelity, reduces false positives, and grants compatibility with complex peripherals, asynchronous events, real-time operations, and direct memory access (DMA). We verified compatibility of SHiFT with thirteen popular embedded architectures, and fully evaluated prototypes for ARMv7-M, ARMv8-M and Xtensa architectures. Our evaluation shows that SHiFT can detect a wide range of firmware faults with instrumentation running natively in the MCU. In terms of performance, SHiFT is up to two orders of magnitude faster (i.e., ×100) than software-based emulation, and even comparable to fuzz testing native applications in a workstation. Thanks to SHiFT's unique characteristics, we discovered five previously unknown vulnerabilities, including a zero-day on the popular FreeRTOS kernel, with no false positives. Our prototypes and source code are publicly available at https://github.com/RiS3-Lab/SHiFT .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- CO3: Concolic Co-execution for FirmwareChangming Liu, Alejandro Mera, Engin Kirda, Meng Xu 等USENIX Security 2024 · 被引用 7 次
- Structure-Aware, Diagnosis-Guided ECU Firmware FuzzingQicai Chen, Kun Hu, Sichen Gong, Bihuan Chen 等ISSTA 2025 · 被引用 2 次
- FlexEmu: Towards Flexible MCU Peripheral EmulationChongqing Lei, Zhen Ling, Xiangyu Xu, Shaofeng Li 等CCS 2025 · 被引用 1 次
- Stop Starving or Stuffing Me: Boosting Firmware Fuzzing Efficiency with On-Demand Input DeliveryShandian Shen, Wei Zhou, Keming Zhao, Peng Liu 等S&P 2026 · 被引用 1 次
- RTCON: Context-Adaptive Function-Level Fuzzing for RTOS KernelsEunkyu Lee, Junyoung Park, Insu YunNDSS 2026 · 被引用 1 次
它引用的顶会 Paper16
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 被引用 428 次
- FIRM-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process EmulationYaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song 等USENIX Security 2019 · 被引用 279 次
- What You Corrupt Is Not What You Crash: Challenges in Fuzzing Embedded DevicesMarius Muench, Jan Stijohann, Frank Kargl, Aurélien Francillon 等NDSS 2018 · 被引用 202 次
- Inception: System-Wide Security Testing of Real-World Embedded Systems SoftwareNassim Corteggiani, Giovanni Camurati, Aurélien FrancillonUSENIX Security 2018 · 被引用 117 次
- FirmUSB: Vetting USB Device Firmware using Domain Informed Symbolic ExecutionGrant Hernandez, Farhaan Fowze, Dave (Jing) Tian, Tuba Yavuz 等CCS 2017 · 被引用 98 次
相关 Paper
- From Library Portability to Para-rehosting: Natively Executing Microcontroller Software on Commodity HardwareWenqiang Li, Le Guan, Jingqiang Lin, Jiameng Shi 等NDSS 2021
- Khost: KVM-based Near Native MCU Firmware RehostingChunlin Wang, Yicheng Yang, Yuan Zhang, Haoyu Xiao 等USENIX Security 2026
- Greenhouse: Single-Service Rehosting of Linux-Based Firmware Binaries in User-Space EmulationHui Jun Tay, Kyle Zeng, Jayakrishna Menon Vadayath, Arvind S. Raj 等USENIX Security 2023
- Forming Faster Firmware FuzzersLukas Seidel, Dominik Christian Maier, Marius MuenchUSENIX Security 2023
- LEMIX: Enabling Testing of Embedded Applications as Linux ApplicationsSai Ritvik Tanksalkar, Siddharth Muralee, Srihari Danduri, Paschal C. Amusuo 等USENIX Security 2025
