Jul 2026· Sensors and materials· Vol 38, pp. 4027· 0 citations· 2 references
TL;DR
Experimental results on real-world firmware images collected from multiple vendors and architectures demonstrate that the proposed approach improves emulation robustness and enhances the ability to successfully execute previously failing firmware instances, supporting more reliable IoT firmware security analysis.
Abstract
Firmware emulation is a key technique for enabling large-scale security analysis of IoT devices and sensing systems without requiring physical hardware. However, existing emulation frameworks often suffer from instability and low success rates owing to mismatches between real device execution environments and virtualized systems, particularly across heterogeneous firmware with different initialization and runtime dependencies. In this study, we investigate failure behaviors in FirmAE, a widely used IoT firmware emulation framework, and identify recurring issues in Boot, Kernel, Network, and nonvolatile random access memory (NVRAM) execution stages. On the basis of this analysis, we propose a set of rule-based improvement strategies that refine boot configurations, Quick Emulator (QEMU) execution parameters, network settings, and NVRAM handling mechanisms to improve emulation stability across diverse firmware types. The main limitation of existing approaches is their reliance on heuristic and incomplete device-specific handling, which reduces robustness when applied to unseen firmware. The proposed method addresses this issue by systematizing failure patterns into actionable repair rules, enabling more consistent emulation behavior. Although the proposed method improves emulation robustness, one limitation of this study is that part of the proposed repair process still depends on manual inspection of firmware logs and runtime behavior, which may limit scalability in fully automated large-scale deployment scenarios. Experimental results on real-world firmware images collected from multiple vendors and architectures demonstrate that the proposed approach improves emulation robustness and enhances the ability to successfully execute previously failing firmware instances, supporting more reliable IoT firmware security analysis
This review synthesises 118 works published from 2014 to 2026 covering the full firmware reverse engineering pipeline and identifies ten structural gaps, including the absence of unified evaluation benchmarks, fragmented peripheral modelling, the scalability–fidelity trade-off in re-hosting, and insufficient grounding...
Aditya Katpara, S. Sankaran· Electronics· 0 citations
Smart sensor devices increasingly require remote firmware updates to deploy new functionality, security patches and algorithmic improvements without interrupting services. Runtime firmware updates remain a significant challenge in embedded sensing systems, particularly in real-time and high-availability applications wh...
B. Neves, Victor D. N. Santos, José Eduardo G. Oliveira et al.· Italian National Conference...· 0 citations
A framework built on top of Zephyr RTOS that enables secure multitenancy on MCUs that leverages PMP-based hardware memory protection for tenant isolation, dynamically loadable applications via Zephyr’s LLEXT subsystem with mTLS-authenticated connection for post-deployment reconfigurability, and a condition-based publis...
Elad Lahav, Julien Gourgue, C. Pelsser et al.· 2 citations
The prolific deployment of embedded systems across critical infrastructure has made hardware security a pressing concern. For example, inexpensive microcontrollers, such as the STM32 series, are frequently deployed with cryptographic firmware that is vulnerable to Side-Channel Attack (SCA), such as Correlation Power An...
Sartaj Jamal Chowdhury, Ahmed Nabil Hammad, John Dragos et al.· Midwest Symposium on Circuit...· 0 citations
In Industrial Internet of Things (IIoT) environments, the security requirements of edge nodes change dynamically, whereas conventional cryptographic deployment relies on static configurations that require firmware upgrades or system reboots for algorithm updates, severely limiting flexibility and maintainability. To ad...
Lei Zhang, Tianyu Luo, Huiyi Zhao et al.· Electronics· 0 citations
BULLSEYE is presented, the first DGF framework to schedule closed-source Linux-based firmware fuzzing by basic-block-level distance to user-specified targets, and introduces novel DGF heuristics that address limitations of traditional approaches.
Lorenzo Ralli, Emilio Coppa· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.