{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,27]],"date-time":"2026-06-27T15:42:19Z","timestamp":1782574939216,"version":"3.54.5"},"reference-count":156,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"13","license":[{"start":{"date-parts":[[2021,7,1]],"date-time":"2021-07-01T00:00:00Z","timestamp":1625097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"Ayudas Cervera para Centros Tecnol\u00f3gicos Grant of the Spanish Centre for the Development of Industrial Technology","award":["EGIDA CER-20191012"],"award-info":[{"award-number":["EGIDA CER-20191012"]}]},{"name":"Intelligent Systems for Industrial Systems, financed by the Department of Education, Linguistic Policy and Culture of the Basque Government"},{"name":"Department of Economic Development, Sustainability and Environment of the Basque Government through the Bikaintek program","award":["20-AF-W2-2019-00006"],"award-info":[{"award-number":["20-AF-W2-2019-00006"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Internet Things J."],"published-print":{"date-parts":[[2021,7,1]]},"DOI":"10.1109\/jiot.2021.3056179","type":"journal-article","created":{"date-parts":[[2021,2,3]],"date-time":"2021-02-03T07:14:01Z","timestamp":1612336441000},"page":"10390-10411","source":"Crossref","is-referenced-by-count":63,"title":["Fuzzing the Internet of Things: A Review on the Techniques and Challenges for Efficient Vulnerability Discovery in Embedded Systems"],"prefix":"10.1109","volume":"8","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7755-2848","authenticated-orcid":false,"given":"Maialen","family":"Eceiza","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5555-9712","authenticated-orcid":false,"given":"Jose Luis","family":"Flores","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9641-5646","authenticated-orcid":false,"given":"Mikel","family":"Iturbe","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref39","year":"2020","journal-title":"Busybox"},{"key":"ref38","author":"main","year":"2010","journal-title":"Real-Time and General-Purpose Operating Systems Unite via Virtualization"},{"key":"ref33","year":"2017","journal-title":"User Manual STM32F429ZI"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/PST.2015.7232966"},{"key":"ref31","author":"minerva","year":"2015","journal-title":"Towards a Definition of the Internet of Things (IoT)"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2019.2925918"},{"key":"ref37","author":"shibu","year":"2009","journal-title":"Introduction to Embedded Systems"},{"key":"ref36","author":"vasseur","year":"2010","journal-title":"Interconnecting Smart Objects with IP The next Internet"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1016\/S1474-6670(17)30189-1"},{"key":"ref34","year":"2019","journal-title":"Raspberry Pi 4 Model B"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/HPCSim.2014.6903734"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.11591\/ijins.v2i5.3115"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2017.2683200"},{"key":"ref20","year":"2018","journal-title":"Security for Industrial Automation and Control System-Part 4-1 Secure Product Development Lifecycle Requirements"},{"key":"ref22","author":"amini","year":"2002","journal-title":"Fuzzing Frameworks"},{"key":"ref21","year":"2019","journal-title":"Security for Industrial Automation and Control System-Part 4-2 Technical Security Requirements for IACS Components"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.02.002"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2018.8330260"},{"key":"ref101","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363225"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-04897-0_12"},{"key":"ref100","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00069"},{"key":"ref25","author":"mulliner","year":"2009","journal-title":"Fuzzing the Phone in Your Phone"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/1379022.1375607"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.21236\/ADA610472"},{"key":"ref154","year":"2020","journal-title":"ZigBee"},{"key":"ref153","year":"2020","journal-title":"About LoRaWAN&#x00AE; | LoRa Alliance&#x00AE;"},{"key":"ref156","doi-asserted-by":"publisher","DOI":"10.1109\/ISCO.2016.7727079"},{"key":"ref155","first-page":"1","article-title":"Security survey of the IoT wireless protocols","author":"krej?\u00ed","year":"2017","journal-title":"Proceedings of Telecommunications Forum (TELFOR)"},{"key":"ref150","author":"huey","year":"2020","journal-title":"DynamoRIO\/dynamorio"},{"key":"ref152","author":"townsend","year":"2014","journal-title":"Chapter 1 Introduction Getting Started With Bluetooth Low Energy"},{"key":"ref151","author":"zhou","year":"2020","journal-title":"Dyninst"},{"key":"ref146","year":"2020","journal-title":"DataFlowSanitizer Design Document-Clang 12 Documentation"},{"key":"ref147","author":"team","year":"2020","journal-title":"LeakSanitizer-clang 12 Documentation"},{"key":"ref148","doi-asserted-by":"publisher","DOI":"10.1145\/1250734.1250746"},{"key":"ref149","author":"levi","year":"2020","journal-title":"Pin - A dynamic binary instrumentation tool"},{"key":"ref59","year":"2020","journal-title":"Peach Community Edition"},{"key":"ref58","author":"amini","year":"2012","journal-title":"OpenRCE"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00046"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/MINES.2012.202"},{"key":"ref55","author":"saavedra","year":"2019","journal-title":"A Review of Machine Learning Applications in Fuzzing"},{"key":"ref54","year":"2020","journal-title":"AFL"},{"key":"ref53","first-page":"820","article-title":"Dowser: A guided fuzzer to find buffer overflow vulnerabilities","volume":"31","author":"istvan","year":"2018","journal-title":"Journal of Intellectual Disability Research"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/2090147.2094081"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/s10617-008-9027-x"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/RTEICT.2016.7807959"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2018.2817685"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/WIRELESSVITAE.2011.5940923"},{"key":"ref5","year":"2019","journal-title":"IoT under fire Kaspersky detects more than 100 million attacks onsmart devices in H1 2019 Kaspersky"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ICGS3.2019.8688214"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.23"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2017.201"},{"key":"ref9","author":"greenberg","year":"2015","journal-title":"Hackers remotely kill a jeep on the highway&#x2014;with me in it"},{"key":"ref46","first-page":"381","article-title":"$\\mu$\nSBS: Static binary sanitization of bare-metal embedded devices for fault observability","author":"salehi","year":"2020","journal-title":"Proc 23rd Int Symp Res Attacks Intrusions Defenses (RAID)"},{"key":"ref45","author":"kindervag","year":"2010","journal-title":"Build Security Into Your Network&#x2019;s DNA The Zero Trust Network Architecture"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-24403-2_3"},{"key":"ref47","author":"li","year":"2019","journal-title":"V-fuzz Vulnerability-oriented evolutionary fuzzing"},{"key":"ref42","author":"systems","year":"2020","journal-title":"Vxworks"},{"key":"ref41","year":"2020","journal-title":"FreeRTOS&#x2014;Market Leading RTOS (Real Time Operating System) for Embedded Systems With Internet of Things Extensions"},{"key":"ref44","first-page":"417","article-title":"Security of IoT systems: Design challenges and opportunities","volume":"2015","author":"xu","year":"2015","journal-title":"2014 IEEE\/ACM Int Conf Computer-Aided Design (ICCAD)"},{"key":"ref43","author":"decker","year":"2020","journal-title":"TinyOS"},{"key":"ref127","year":"2020","journal-title":"SSL Library mbed TLS \/ PolarSSL"},{"key":"ref126","author":"meade","year":"2012","journal-title":"Juliet Test Suite v1 1 for C\/C++ User Guide"},{"key":"ref125","author":"adams","year":"2020","journal-title":"JasPer"},{"key":"ref124","year":"2020","journal-title":"TCPDUMP\/LIBPCAP public repository"},{"key":"ref73","author":"wang","year":"2019","journal-title":"A systematic review of fuzzing based on machine learning techniques"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.50"},{"key":"ref129","author":"pipping","year":"2020","journal-title":"Libexpat\/libexpat"},{"key":"ref71","year":"2020","journal-title":"Vulnerabilities"},{"key":"ref128","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978411"},{"key":"ref70","first-page":"820","article-title":"Dowsing for overflows: A guided fuzzer to find buffer boundary violations","volume":"31","author":"haller","year":"2018","journal-title":"Journal of Intellectual Disability Research"},{"key":"ref76","author":"fell","year":"2017","journal-title":"A Review of Fuzzing Tools and Methods"},{"key":"ref130","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.15"},{"key":"ref77","first-page":"209","article-title":"KLEE: Unassisted and automatic generation of high-coverage tests for complex systems programs","volume":"8","author":"cadar","year":"2008","journal-title":"Proc 8th USENIX Conf Oper Syst Design Implement"},{"key":"ref74","author":"ognawala","year":"2017","journal-title":"An exploratory survey of hybrid testing techniques involving symbolic execution and fuzzing"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/TENCON.2017.8227972"},{"key":"ref133","author":"ceresa","year":"2015","journal-title":"QuickFuzz"},{"key":"ref134","author":"molnar","year":"2009","journal-title":"SmartFuzz"},{"key":"ref131","author":"b\u00f6hme","year":"2020","journal-title":"Aflgo"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23404"},{"key":"ref132","author":"ghassemi","year":"2016","journal-title":"Drill"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243804"},{"key":"ref136","author":"hajnoczi","year":"2019","journal-title":"Fuzzing QEMU Device Emulation QEMU"},{"key":"ref135","year":"2020","journal-title":"Vusec\/vuzzer"},{"key":"ref138","year":"2020","journal-title":"AFLplus\/unicornAFL"},{"key":"ref137","author":"beckus","year":"2012","journal-title":"Beckus\/qemu_stm32"},{"key":"ref60","first-page":"167","article-title":"kaFL: Hardware-assisted feedback fuzzing for os kernels","author":"schumilo","year":"2017","journal-title":"Proc Usenix Security Symp"},{"key":"ref139","author":"gustafson","year":"2020","journal-title":"Hal-fuzz"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/ICSTW.2011.9"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2019.00093"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2017.8115618"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23159"},{"key":"ref140","first-page":"7","article-title":"SURROGATES: Enabling near-real-time dynamic analyses of embedded systems","author":"koscher","year":"2015","journal-title":"Proc 9th USENIX Workshop Offensive Technol"},{"key":"ref65","first-page":"67","article-title":"Dynamic test generation to find integer bugs in x86 binary linux programs","author":"molnar","year":"2009","journal-title":"Proc 18th Conf USENIX Security Symp"},{"key":"ref141","year":"2020","journal-title":"Sanitizers"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134020"},{"key":"ref142","year":"2020","journal-title":"Address Sanitizer"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1145\/2093548.2093564"},{"key":"ref143","year":"2020","journal-title":"Thread sanitizer"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/EnT.2019.00011"},{"key":"ref144","year":"2020","journal-title":"Memory Sanitizer"},{"key":"ref2","year":"2019","journal-title":"IoT number of connected devices worldwide 2012&#x2013;2025"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/ICPC.2019.00044"},{"key":"ref145","year":"2020","journal-title":"Undefined Behavior Sanitizer (UBS)"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2016.2615180"},{"key":"ref109","first-page":"1967","article-title":"EnFuzz: Ensemble fuzzing with seed synchronization among diverse fuzzers","author":"chen","year":"2019","journal-title":"Proc 28th USENIX Conf Security Symp"},{"key":"ref95","doi-asserted-by":"publisher","DOI":"10.3390\/computers7010003"},{"key":"ref108","year":"2020","journal-title":"Libfuzzer and AFL"},{"key":"ref94","doi-asserted-by":"publisher","DOI":"10.1201\/9781315218281"},{"key":"ref107","first-page":"19","article-title":"Frankenstein: Advanced wireless fuzzing to exploit new Bluetooth escalation targets","author":"ruge","year":"2020","journal-title":"Proc 29th USENIX Security Symp"},{"key":"ref93","author":"aki","year":"2020","journal-title":"Radamsa"},{"key":"ref106","first-page":"463","article-title":"FIE on firmware: Finding vulnerabilities in embedded systems using symbolic execution","author":"davidson","year":"2013","journal-title":"Proc 22nd USENIX Security Symp"},{"key":"ref92","year":"2020","journal-title":"Honggfuzz"},{"key":"ref105","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053038"},{"key":"ref91","year":"2020","journal-title":"Angora Fuzzer"},{"key":"ref104","doi-asserted-by":"publisher","DOI":"10.3390\/s19153362"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3106295"},{"key":"ref103","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2009.5070546"},{"key":"ref102","first-page":"1","article-title":"Browser fuzzing by scheduled mutation and generation of document object models","volume":"2015","author":"lin","year":"2016","journal-title":"Security Technology (ICCST) 2015 International Carnahan Conference on"},{"key":"ref111","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3275525"},{"key":"ref112","year":"2020","journal-title":"Peach fuzzer platform"},{"key":"ref110","doi-asserted-by":"publisher","DOI":"10.1145\/2970276.2970316"},{"key":"ref98","first-page":"21","article-title":"Embedded security testing with peripheral device caching and runtime program state approximation","author":"kammerstetter","year":"2016","journal-title":"Proc SECURWARE"},{"key":"ref99","doi-asserted-by":"publisher","DOI":"10.1145\/1176760.1176793"},{"key":"ref96","author":"costin","year":"2015","journal-title":"Automated dynamic firmware analysis at scale A case study on embedded Web interfaces"},{"key":"ref97","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23415"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2019.2910750"},{"key":"ref11","author":"manes","year":"2018","journal-title":"Fuzzing Art science and engineering"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2011.48"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/96267.96279"},{"key":"ref14","author":"sutton","year":"2007","journal-title":"Fuzzing Brute Force Vulnerability Discovery"},{"key":"ref15","doi-asserted-by":"crossref","first-page":"6","DOI":"10.1186\/s42400-018-0002-y","article-title":"Fuzzing: A survey","volume":"1","author":"zhao","year":"2018","journal-title":"Cybersecurity"},{"key":"ref118","author":"warren","year":"2016","journal-title":"Using Sulley to Protocol Fuzz for Linux Software"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2018.2834476"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23368"},{"key":"ref117","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00080"},{"key":"ref17","article-title":"Fuzzing: The state of the art","author":"mcnally","year":"2012"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1145\/3293882.3330579"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23166"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1145\/2699026.2699098"},{"key":"ref119","year":"2015","journal-title":"Google\/syzkaller"},{"key":"ref19","year":"2011","journal-title":"Requirements for Embedded Device Security Assurance (EDSA) Certification"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516736"},{"key":"ref114","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23371"},{"key":"ref113","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2017.09.018"},{"key":"ref116","first-page":"1","article-title":"Automated whitebox fuzz testing","author":"godefroid","year":"2008","journal-title":"Proc Symp Network and Distributed System Security"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00056"},{"key":"ref115","doi-asserted-by":"publisher","DOI":"10.1145\/1950365.1950396"},{"key":"ref120","doi-asserted-by":"publisher","DOI":"10.1088\/1742-6596\/1176\/2\/022013"},{"key":"ref89","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2017.2785841"},{"key":"ref121","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.37"},{"key":"ref122","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2014.45"},{"key":"ref123","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.15"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1023\/A:1006529012972"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-93025-1"},{"key":"ref87","first-page":"1475","article-title":"Improving function coverage with munch: A hybrid fuzzing and directed symbolic execution approach","author":"ognawala","year":"2017","journal-title":"Proc SAC"},{"key":"ref88","author":"b\u00f6hme","year":"2020","journal-title":"Aflfast"}],"container-title":["IEEE Internet of Things Journal"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6488907\/9462546\/09344712.pdf?arnumber=9344712","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,12,17]],"date-time":"2021-12-17T19:56:51Z","timestamp":1639771011000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9344712\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,7,1]]},"references-count":156,"journal-issue":{"issue":"13"},"URL":"https:\/\/doi.org\/10.1109\/jiot.2021.3056179","relation":{},"ISSN":["2327-4662","2372-2541"],"issn-type":[{"value":"2327-4662","type":"electronic"},{"value":"2372-2541","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,7,1]]}}}