Skip to content
Open access

Improvement for Embedded Firmware Emulation Applying FirmAE

Jul 2026 · Sensors and materials · Vol 38, pp. 4027 · 0 citations · 2 references

TL;DR

Experimental results on real-world firmware images collected from multiple vendors and architectures demonstrate that the proposed approach improves emulation robustness and enhances the ability to successfully execute previously failing firmware instances, supporting more reliable IoT firmware security analysis.

Abstract

Firmware emulation is a key technique for enabling large-scale security analysis of IoT devices and sensing systems without requiring physical hardware. However, existing emulation frameworks often suffer from instability and low success rates owing to mismatches between real device execution environments and virtualized systems, particularly across heterogeneous firmware with different initialization and runtime dependencies. In this study, we investigate failure behaviors in FirmAE, a widely used IoT firmware emulation framework, and identify recurring issues in Boot, Kernel, Network, and nonvolatile random access memory (NVRAM) execution stages. On the basis of this analysis, we propose a set of rule-based improvement strategies that refine boot configurations, Quick Emulator (QEMU) execution parameters, network settings, and NVRAM handling mechanisms to improve emulation stability across diverse firmware types. The main limitation of existing approaches is their reliance on heuristic and incomplete device-specific handling, which reduces robustness when applied to unseen firmware. The proposed method addresses this issue by systematizing failure patterns into actionable repair rules, enabling more consistent emulation behavior. Although the proposed method improves emulation robustness, one limitation of this study is that part of the proposed repair process still depends on manual inspection of firmware logs and runtime behavior, which may limit scalability in fully automated large-scale deployment scenarios. Experimental results on real-world firmware images collected from multiple vendors and architectures demonstrate that the proposed approach improves emulation robustness and enhances the ability to successfully execute previously failing firmware instances, supporting more reliable IoT firmware security analysis

Read PDF

Similar papers

Review Open access Aug 2026

Firmware Reverse Engineering: A Comprehensive Review and Directions

This review synthesises 118 works published from 2014 to 2026 covering the full firmware reverse engineering pipeline and identifies ten structural gaps, including the absence of unified evaluation benchmarks, fragmented peripheral modelling, the scalability–fidelity trade-off in re-hosting, and insufficient grounding...

Aditya Katpara, S. Sankaran · 0 citations
Open access Sep 2026

Runtime Firmware Update for 32-Bit Microcontrollers with Instruction Cache Under Concurrent Task Execution

Smart sensor devices increasingly require remote firmware updates to deploy new functionality, security patches and algorithmic improvements without interrupting services. Runtime firmware updates remain a significant challenge in embedded sensing systems, particularly in real-time and high-availability applications wh...

B. Neves, Victor D. N. Santos, José Eduardo G. Oliveira et al. · 0 citations

Operating Systems Platforms for Embedded Real-Time Applications

A framework built on top of Zephyr RTOS that enables secure multitenancy on MCUs that leverages PMP-based hardware memory protection for tenant isolation, dynamically loadable applications via Zephyr’s LLEXT subsystem with mTLS-authenticated connection for post-deployment reconfigurability, and a condition-based publis...

Elad Lahav, Julien Gourgue, C. Pelsser et al. · 2 citations
Aug 2026

A Post-Compilation Side-Channel Attack Countermeasure Framework for STM32

The prolific deployment of embedded systems across critical infrastructure has made hardware security a pressing concern. For example, inexpensive microcontrollers, such as the STM32 series, are frequently deployed with cryptographic firmware that is vulnerable to Side-Channel Attack (SCA), such as Correlation Power An...

Sartaj Jamal Chowdhury, Ahmed Nabil Hammad, John Dragos et al. · 0 citations
Open access Jul 2026

Software-Defined Runtime Reconfiguration of Cryptographic Service Chains for IIoT Edge Nodes

In Industrial Internet of Things (IIoT) environments, the security requirements of edge nodes change dynamically, whereas conventional cryptographic deployment relies on static configurations that require firmware upgrades or system reboots for algorithm updates, severely limiting flexibility and maintainability. To ad...

Lei Zhang, Tianyu Luo, Huiyi Zhao et al. · 0 citations
Preprint Aug 2026

BullsEye: Directed Firmware Fuzzing

BULLSEYE is presented, the first DGF framework to schedule closed-source Linux-based firmware fuzzing by basic-block-level distance to user-specified targets, and introduces novel DGF heuristics that address limitations of traditional approaches.

Lorenzo Ralli, Emilio Coppa · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.