Skip to content
Preprint

BullsEye: Directed Firmware Fuzzing

Aug 2026 · 0 citations · 64 references
Computer Science

TL;DR

BULLSEYE is presented, the first DGF framework to schedule closed-source Linux-based firmware fuzzing by basic-block-level distance to user-specified targets, and introduces novel DGF heuristics that address limitations of traditional approaches.

Abstract

The widespread adoption of Internet of Things (IoT) devices has expanded the digital attack surface, making firmware analysis critical for modern software security. A key security concern stems from the frequent reuse of third-party software components, a practice that often introduces known vulnerabilities into firmware images. Whether a given image actually exposes such a flaw is an open question, and public proof-of concept exploits make answering it urgent. Directed Greybox Fuzzing (DGF), a technique that enables targeted exploration of specific binary locations, offers a promising solution for detecting such vulnerabilities. However, DGF has reached firmware only at function granularity, too coarse to aim at the vulnerable block itself. This article presents BULLSEYE, the first DGF framework to schedule closed-source Linux-based firmware fuzzing by basic-block-level distance to user-specified targets. Our methodology combines static and dynamic analysis to enable DGF in the constrained firmware domain, focusing on vulnerabilities in reused third-party components. We introduce novel DGF heuristics that address limitations of traditional approaches. We compare BULLSEYE against four greybox-fuzzing baselines sharing its execution back-end, including reimplementations of AFLGO and WINDRANGER, and against GREENHOUSE, a state-of-the-art firmware re-hosting framework. On 40 vulnerability sites across 32 firmware images, BULLSEYE reproduces every target within budget, against 35 for the strongest of the four baselines, and reduces Time-to-Exposure by a geometric mean of 9.5x to 72.5x over them; against GREENHOUSE, on the 18 targets its pipeline supports, BULLSEYE is faster by a geometric mean of 9.8x.

View source

Similar papers

Review Open access Aug 2026

Firmware Reverse Engineering: A Comprehensive Review and Directions

This review synthesises 118 works published from 2014 to 2026 covering the full firmware reverse engineering pipeline and identifies ten structural gaps, including the absence of unified evaluation benchmarks, fragmented peripheral modelling, the scalability–fidelity trade-off in re-hosting, and insufficient grounding...

Aditya Katpara, S. Sankaran · 0 citations
Preprint Aug 2026

Statistical Analysis of Executability and Program Equivalence in Decompilation for IoT Vulnerability Detection

Internet of Things (IoT) devices handle sensitive privacy-related information such as user audio, video, and authentication data, making it essential to detect vulnerabilities in their firmware. Decompilation, a key detection technique, has recently attracted attention because Large Language Models (LLMs) enable high r...

Minami Yoda, Jia-Long Li, Yasuyuki Tahara et al. · 0 citations
Preprint Sep 2026

POZZER: A Power Side Channel-guided Fuzzer for Black-Box Embedded Systems

Firmware fuzzing is an effective technique for discovering vulnerabilities in embedded systems. However, existing coverage-guided firmware fuzzers typically obtain feedback through firmware instrumentation, hardware debug interfaces, or firmware rehosting, which requires access to the firmware source code or binary ima...

Pouya Narimani, Kseniia Rogova, Addison Crump et al. · 0 citations
Open access Aug 2026

Cloud in the crosshairs: exposing vulnerabilities in web-based management interfaces of open-source IaaS platforms

This study conducts a large-scale empirical security analysis of the web-based management interfaces of ten widely used open-source Infrastructure-as-a-Service (IaaS) platforms, identifying 16 vulnerabilities spanning nine classes, including high-severity flaws that enable account takeover.

Alexandros Perrakis, Efstratios Chatzoglou, Vyron Kampourakis et al. · 0 citations
2026

Cross-Architecture Software Vulnerability Analysis in Binary Code

Software security has been a long-standing and prominent topic in both industry and academia. However, with the increasing deployment of smart devices across various architectures, there is now a significant demand for cross-architecture software. For instance, the Heartbleed vulnerability (CVE-2014-0160), classified a...

Shigang Liu, Di Cao, Chao Chen et al. · 0 citations
Aug 2026

SNIPTEST: Fuzzing Multi-Level Code Slices for Validating Vulnerabilities

SNIPTEST is an execution-based warning triage framework that generates and fuzzes compiled code slices centered around static-analysis warnings that employs a layer-by-layer slicing strategy, incrementally expanding context around the target location to validate potential vulnerabilities with increasing precision.

Aniruddhan Murali, Noble Saji Mathews, Mahmoud Alfadel et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.