{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T16:14:47Z","timestamp":1783008887592,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":88,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,5,24]],"date-time":"2021-05-24T00:00:00Z","timestamp":1621814400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N00014-15-1-2180, N00014-19- 1-2364"],"award-info":[{"award-number":["N00014-15-1-2180, N00014-19- 1-2364"]}],"id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1916398,CNS-1942793"],"award-info":[{"award-number":["CNS-1916398,CNS-1942793"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"name":"NWO","award":["628.001.030, InterSect"],"award-info":[{"award-number":["628.001.030, InterSect"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,5,24]]},"DOI":"10.1145\/3433210.3453093","type":"proceedings-article","created":{"date-parts":[[2021,6,4]],"date-time":"2021-06-04T15:26:39Z","timestamp":1622820399000},"page":"687-701","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":47,"title":["SoK: Enabling Security Analyses of Embedded Systems via Rehosting"],"prefix":"10.1145","author":[{"given":"Andrew","family":"Fasano","sequence":"first","affiliation":[{"name":"Massachusetts Institute of Technology &amp; Northeastern University, Boston, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tiemoko","family":"Ballo","sequence":"additional","affiliation":[{"name":"Massachusetts Institute of Technology, Lexington, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marius","family":"Muench","sequence":"additional","affiliation":[{"name":"Vrije Universiteit Amsterdam, Amsterdam, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tim","family":"Leek","sequence":"additional","affiliation":[{"name":"Massachusetts Institute of Technology, Lexington, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Alexander","family":"Bulekov","sequence":"additional","affiliation":[{"name":"Boston University, Boston, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Brendan","family":"Dolan-Gavitt","sequence":"additional","affiliation":[{"name":"New York University, New York, NY, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Manuel","family":"Egele","sequence":"additional","affiliation":[{"name":"Boston University, Boston, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Aur\u00e9lien","family":"Francillon","sequence":"additional","affiliation":[{"name":"EURECOM, Biot, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Long","family":"Lu","sequence":"additional","affiliation":[{"name":"Northeastern University, Boston, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nick","family":"Gregory","sequence":"additional","affiliation":[{"name":"New York University, New York, NY, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Davide","family":"Balzarotti","sequence":"additional","affiliation":[{"name":"EURECOM, Biot, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"William","family":"Robertson","sequence":"additional","affiliation":[{"name":"Northeastern University, Boston, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,6,4]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"USENIX Security","author":"Antonakakis M.","year":"2017","unstructured":"M. Antonakakis , T. April , M. Bailey , M. Bernhard , E. Bursztein , J. Cochran , Z. Durumeric , J. A. Halderman , L. Invernizzi , M. Kallitsis , D. Kumar , C. Lever , Z. Ma , J. Mason , D. Menscher , C. Seaman , N. Sullivan , K. Thomas , and Y. Zhou . Understanding the mirai botnet . In USENIX Security , 2017 . M. Antonakakis, T. April, M. Bailey, M. Bernhard, E. Bursztein, J. Cochran, Z. Durumeric, J. A. Halderman, L. Invernizzi, M. Kallitsis, D. Kumar, C. Lever, Z. Ma, J. Mason, D. Menscher, C. Seaman, N. Sullivan, K. Thomas, and Y. Zhou. Understanding the mirai botnet. In USENIX Security, 2017."},{"key":"e_1_3_2_2_2_1","unstructured":"ARM. System view description. https:\/\/www.keil.com\/pack\/doc\/CMSIS\/SVD\/html\/index.html.  ARM. System view description. https:\/\/www.keil.com\/pack\/doc\/CMSIS\/SVD\/html\/index.html."},{"key":"e_1_3_2_2_3_1","volume-title":"Broadpwn: Remotely compromising android and ios via a bug in the broadcom wi-fi chipset","author":"Artenstein N.","year":"2017","unstructured":"N. Artenstein . Broadpwn: Remotely compromising android and ios via a bug in the broadcom wi-fi chipset , 2017 . N. Artenstein. Broadpwn: Remotely compromising android and ios via a bug in the broadcom wi-fi chipset, 2017."},{"key":"e_1_3_2_2_4_1","volume-title":"USENIX Annual Technical Conference, FREENIX Track","author":"Bellard F.","year":"2005","unstructured":"F. Bellard . Qemu, a fast and portable dynamic translator . In USENIX Annual Technical Conference, FREENIX Track , 2005 . F. Bellard. Qemu, a fast and portable dynamic translator. In USENIX Annual Technical Conference, FREENIX Track, 2005."},{"key":"e_1_3_2_2_5_1","unstructured":"N. Brown. Device trees i: Are we having fun yet? https:\/\/lwn.net\/Articles\/572692\/.  N. Brown. Device trees i: Are we having fun yet? https:\/\/lwn.net\/Articles\/572692\/."},{"key":"e_1_3_2_2_6_1","first-page":"37","author":"Burgio P.","year":"2016","unstructured":"P. Burgio , C. Alvarez , E. Ayguad\u00e9 , A. Filgueras , D. Jimenez-Gonzalez , X. Martorell , N. Navarro , and R. Giorgi . Simulating next-generation cyber-physical computing platforms. Ada User Journal , 37 , 2016 . P. Burgio, C. Alvarez, E. Ayguad\u00e9, A. Filgueras, D. Jimenez-Gonzalez, X. Martorell, N. Navarro, and R. Giorgi. Simulating next-generation cyber-physical computing platforms. Ada User Journal, 37, 2016.","journal-title":"Simulating next-generation cyber-physical computing platforms. Ada User Journal"},{"key":"e_1_3_2_2_7_1","volume-title":"OSDI","author":"Cadar C.","year":"2008","unstructured":"C. Cadar , D. Dunbar , D. R. Engler , : Unassisted and automatic generation of high-coverage tests for complex systems programs . In OSDI , 2008 . C. Cadar, D. Dunbar, D. R. Engler, et al. Klee: Unassisted and automatic generation of high-coverage tests for complex systems programs. In OSDI, 2008."},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427280"},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.4271\/2003-01-1049"},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23415"},{"key":"e_1_3_2_2_11_1","volume-title":"Dtaint: detecting the taint-style vulnerability in embedded device firmware","author":"Cheng K.","year":"2018","unstructured":"K. Cheng , Q. Li , L. Wang , Q. Chen , Y. Zheng , L. Sun , and Z. Liang . Dtaint: detecting the taint-style vulnerability in embedded device firmware . In IEEE\/IFIP DSN , 2018 . K. Cheng, Q. Li, L. Wang, Q. Chen, Y. Zheng, L. Sun, and Z. Liang. Dtaint: detecting the taint-style vulnerability in embedded device firmware. In IEEE\/IFIP DSN, 2018."},{"key":"e_1_3_2_2_12_1","unstructured":"V. Chipounov and G. Candea. Reverse engineering of binary device drivers with revnic. In ACM EUROSYS.  V. Chipounov and G. Candea. Reverse engineering of binary device drivers with revnic. In ACM EUROSYS."},{"key":"e_1_3_2_2_13_1","author":"Chipounov V.","year":"2011","unstructured":"V. Chipounov , V. Kuznetsov , and G. Candea . S2E: A platform for in-vivo multi-path analysis of software systems. In ACM SIGARCH Computer Architecture News , 2011 . V. Chipounov, V. Kuznetsov, and G. Candea. S2E: A platform for in-vivo multi-path analysis of software systems. In ACM SIGARCH Computer Architecture News, 2011.","journal-title":"In ACM SIGARCH Computer Architecture News"},{"key":"e_1_3_2_2_14_1","volume-title":"NDSS","author":"Chua Z. L.","year":"2019","unstructured":"Z. L. Chua , Y. Wang , T. Baluta , P. Saxena , Z. Liang , and P. Su . One engine to serve'em all: Inferring taint rules without architectural semantics . In NDSS , 2019 . Z. L. Chua, Y. Wang, T. Baluta, P. Saxena, Z. Liang, and P. Su. One engine to serve'em all: Inferring taint rules without architectural semantics. In NDSS, 2019."},{"key":"e_1_3_2_2_15_1","volume-title":"USENIX Security","author":"Clements A.","year":"2020","unstructured":"A. Clements , E. Gustafson , T. Scharnowski , P. Grosen , D. Fritz , : Firmware re-hosting through abstraction layer emulation . In USENIX Security , 2020 . A. Clements, E. Gustafson, T. Scharnowski, P. Grosen, D. Fritz, et al. HALucinator: Firmware re-hosting through abstraction layer emulation. In USENIX Security, 2020."},{"key":"e_1_3_2_2_16_1","volume-title":"BAR","author":"Clements A. A.","year":"2021","unstructured":"A. A. Clements , L. Carpenter , W. A. Moeglein , and C. Wright . Is your firmware real or re-hosted? a case study in re-hosting vxworks control system firmware . In BAR , 2021 . A. A. Clements, L. Carpenter, W. A. Moeglein, and C. Wright. Is your firmware real or re-hosted? a case study in re-hosting vxworks control system firmware. In BAR, 2021."},{"key":"e_1_3_2_2_17_1","unstructured":"Comsecuris. Luaqemu. https:\/\/github.com\/comsecuris\/luaqemu.  Comsecuris. Luaqemu. https:\/\/github.com\/comsecuris\/luaqemu."},{"key":"e_1_3_2_2_18_1","volume-title":"USENIX Security","author":"Corteggiani N.","year":"2018","unstructured":"N. Corteggiani , G. Camurati , and A. Francillon . Inception: system-wide security testing of real-world embedded systems software . In USENIX Security , 2018 . N. Corteggiani, G. Camurati, and A. Francillon. Inception: system-wide security testing of real-world embedded systems software. In USENIX Security, 2018."},{"key":"e_1_3_2_2_19_1","volume-title":"USENIX Security","author":"Costin A.","year":"2014","unstructured":"A. Costin , J. Zaddach , A. Francillon , and D. Balzarotti . A large-scale analysis of the security of embedded firmwares . In USENIX Security , 2014 . A. Costin, J. Zaddach, A. Francillon, and D. Balzarotti. A large-scale analysis of the security of embedded firmwares. In USENIX Security, 2014."},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2897845.2897900"},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/VLSI-SoC.2014.7004154"},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3173162.3177157"},{"key":"e_1_3_2_2_23_1","volume-title":"USENIX Security","author":"Davidson D.","year":"2013","unstructured":"D. Davidson , B. Moench , T. Ristenpart , and S. Jha . Fie on firmware: Finding vulnerabilities in embedded systems using symbolic execution . In USENIX Security , 2013 . D. Davidson, B. Moench, T. Ristenpart, and S. Jha. Fie on firmware: Finding vulnerabilities in embedded systems using symbolic execution. In USENIX Security, 2013."},{"key":"e_1_3_2_2_24_1","volume-title":"Device tree specification v0.2. https:\/\/www.devicetree.org\/specifications\/","year":"2017","unstructured":"Devicetree.org. Device tree specification v0.2. https:\/\/www.devicetree.org\/specifications\/ , 2017 . Devicetree.org. Device tree specification v0.2. https:\/\/www.devicetree.org\/specifications\/, 2017."},{"key":"e_1_3_2_2_25_1","volume-title":"ReCon 2014 Conference","author":"Dinaburg A.","year":"2014","unstructured":"A. Dinaburg and A. Ruef . Mcsema: Static translation of x86 instructions to llvm . In ReCon 2014 Conference , Montreal, Canada , 2014 . A. Dinaburg and A. Ruef. Mcsema: Static translation of x86 instructions to llvm. In ReCon 2014 Conference, Montreal, Canada, 2014."},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.11"},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/996821.996823"},{"key":"e_1_3_2_2_28_1","volume-title":"https:\/\/fail0verflow.com\/blog\/2012\/unprogramming-intro\/","year":"2012","unstructured":"fail0verflow. Unprogramming: Intro . https:\/\/fail0verflow.com\/blog\/2012\/unprogramming-intro\/ , 2012 . fail0verflow. Unprogramming: Intro. https:\/\/fail0verflow.com\/blog\/2012\/unprogramming-intro\/, 2012."},{"key":"e_1_3_2_2_29_1","volume-title":"USENIX Security","author":"Feng B.","year":"2020","unstructured":"B. Feng , A. Mera , and L. Lu . P2im: Scalable and hardware-independent firmware testing via automatic peripheral interface modeling . In USENIX Security , 2020 . B. Feng, A. Mera, and L. Lu. P2im: Scalable and hardware-independent firmware testing via automatic peripheral interface modeling. In USENIX Security, 2020."},{"key":"e_1_3_2_2_30_1","volume-title":"Accessing pci express configuration registers using intel chipsets. Intel White Paper, (321090)","author":"Fleming S.","year":"2008","unstructured":"S. Fleming . Accessing pci express configuration registers using intel chipsets. Intel White Paper, (321090) , 2008 . S. Fleming. Accessing pci express configuration registers using intel chipsets. Intel White Paper, (321090), 2008."},{"key":"e_1_3_2_2_31_1","volume-title":"Advanced configuration and powerinterface specification v6.2. https:\/\/uefi.org\/sites\/default\/files\/resources\/ACPI_6_2.pdf","author":"Forum U. E. F. I.","year":"2017","unstructured":"U. E. F. I. Forum . Advanced configuration and powerinterface specification v6.2. https:\/\/uefi.org\/sites\/default\/files\/resources\/ACPI_6_2.pdf , 2017 . U. E. F. I. Forum. Advanced configuration and powerinterface specification v6.2. https:\/\/uefi.org\/sites\/default\/files\/resources\/ACPI_6_2.pdf, 2017."},{"key":"e_1_3_2_2_32_1","volume-title":"https:\/\/www.ftdichip.com\/Support\/Documents\/TechnicalNotes\/TN_113_Simplified Description of USB Device Enumeration.pdf","author":"FTDI.","year":"2009","unstructured":"FTDI. Simplified description of usb device enumeration. https:\/\/www.ftdichip.com\/Support\/Documents\/TechnicalNotes\/TN_113_Simplified Description of USB Device Enumeration.pdf , 2009 . FTDI. Simplified description of usb device enumeration. https:\/\/www.ftdichip.com\/Support\/Documents\/TechnicalNotes\/TN_113_Simplified Description of USB Device Enumeration.pdf, 2009."},{"key":"e_1_3_2_2_33_1","unstructured":"Ghidra. SLEIGH - A Language for Rapid Processor Specification.  Ghidra. SLEIGH - A Language for Rapid Processor Specification."},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/2254064.2254116"},{"key":"e_1_3_2_2_35_1","volume-title":"Firmcorn: Vulnerability-oriented fuzzing of iot firmware via optimized virtual execution","author":"Gui Z.","year":"2020","unstructured":"Z. Gui , H. Shu , F. Kang , and X. Xiong . Firmcorn: Vulnerability-oriented fuzzing of iot firmware via optimized virtual execution . IEEE Access , 2020 . Z. Gui, H. Shu, F. Kang, and X. Xiong. Firmcorn: Vulnerability-oriented fuzzing of iot firmware via optimized virtual execution. IEEE Access, 2020."},{"key":"e_1_3_2_2_36_1","volume-title":"RAID","author":"Gustafson E.","year":"2019","unstructured":"E. Gustafson , M. Muench , C. Spensky , N. Redini , A. Machiry , Y. Fratantonio , D. Balzarotti , A. Francillon , Y. R. Choe , C. Kruegel , Toward the analysis of embedded firmware through automated re-hosting . In RAID , 2019 . E. Gustafson, M. Muench, C. Spensky, N. Redini, A. Machiry, Y. Fratantonio, D. Balzarotti, A. Francillon, Y. R. Choe, C. Kruegel, et al. Toward the analysis of embedded firmware through automated re-hosting. In RAID, 2019."},{"key":"e_1_3_2_2_37_1","volume-title":"USENIX Security","author":"Harrison L.","year":"2020","unstructured":"L. Harrison , H. Vijayakumar , R. Padhye , K. Sen , and M. Grace . Partemu: Enabling dynamic analysis of real-world trustzone software using emulation . In USENIX Security , 2020 . L. Harrison, H. Vijayakumar, R. Padhye, K. Sen, and M. Grace. Partemu: Enabling dynamic analysis of real-world trustzone software using emulation. In USENIX Security, 2020."},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134050"},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2908080.2908121"},{"key":"e_1_3_2_2_40_1","volume-title":"Std 1364: IEEE Standard for Verilog Hardware Description Language","author":"IEEE Computer Society","year":"1995","unstructured":"IEEE Computer Society . Std 1364: IEEE Standard for Verilog Hardware Description Language . 1995 . IEEE Computer Society. Std 1364: IEEE Standard for Verilog Hardware Description Language. 1995."},{"key":"e_1_3_2_2_41_1","volume-title":"Stm-based introspection. Technical report","author":"Jung M. J.","year":"2017","unstructured":"M. J. Jung and T. Ballo . Stm-based introspection. Technical report , Sandia National Lab.(SNL-NM), Albuquerque, NM (United States) , 2017 . M. J. Jung and T. Ballo. Stm-based introspection. Technical report, Sandia National Lab.(SNL-NM), Albuquerque, NM (United States), 2017."},{"key":"e_1_3_2_2_42_1","volume-title":"SECURWARE","author":"Kammerstetter M.","year":"2016","unstructured":"M. Kammerstetter , D. Burian , and W. Kastner . Embedded security testing with peripheral device caching and runtime program state approximation . In SECURWARE , 2016 . M. Kammerstetter, D. Burian, and W. Kastner. Embedded security testing with peripheral device caching and runtime program state approximation. In SECURWARE, 2016."},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/2590296.2590301"},{"key":"e_1_3_2_2_44_1","unstructured":"P.-H. Kamp. The crypto-cs-seti challenge: An un-programming challenge. http:\/\/web.archive.org\/web\/20160304030848\/http:\/\/queue.acm.org\/unprogramming.cfm 2012.  P.-H. Kamp. The crypto-cs-seti challenge: An un-programming challenge. http:\/\/web.archive.org\/web\/20160304030848\/http:\/\/queue.acm.org\/unprogramming.cfm 2012."},{"key":"e_1_3_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3230833.3230867"},{"key":"e_1_3_2_2_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427294"},{"key":"e_1_3_2_2_47_1","volume-title":"Usenix WOOT","author":"Koscher K.","year":"2015","unstructured":"K. Koscher , T. Kohno , and D. Molnar . SURROGATES: Enabling near-real-time dynamic analyses of embedded systems . In Usenix WOOT , 2015 . K. Koscher, T. Kohno, and D. Molnar. SURROGATES: Enabling near-real-time dynamic analyses of embedded systems. In Usenix WOOT, 2015."},{"key":"e_1_3_2_2_48_1","volume-title":"Linux Journal","author":"Lawton K. P.","year":"1996","unstructured":"K. P. Lawton . Bochs : A portable pc emulator for unix\/x . Linux Journal , 1996 . K. P. Lawton. Bochs: A portable pc emulator for unix\/x. Linux Journal, 1996."},{"key":"e_1_3_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/1878961.1879007"},{"key":"e_1_3_2_2_50_1","volume-title":"NDSS","author":"Li W.","year":"2021","unstructured":"W. Li , L. Guan , J. Lin , J. Shi , and F. Li . From library portability to para-rehosting:natively executing microcontroller softwareon commodity hardware . In NDSS , 2021 . W. Li, L. Guan, J. Lin, J. Shi, and F. Li. From library portability to para-rehosting:natively executing microcontroller softwareon commodity hardware. In NDSS, 2021."},{"key":"e_1_3_2_2_51_1","unstructured":"G. Likely. Linux and the device tree: The linux usage model for device tree data.  G. Likely. Linux and the device tree: The linux usage model for device tree data."},{"key":"e_1_3_2_2_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/3342195.3387556"},{"key":"e_1_3_2_2_53_1","volume-title":"http:\/\/www.ovpworld.org\/","author":"Ltd I. S.","year":"2019","unstructured":"I. S. Ltd . Openvirtualplatforms. http:\/\/www.ovpworld.org\/ , 2019 . I. S. Ltd. Openvirtualplatforms. http:\/\/www.ovpworld.org\/, 2019."},{"key":"e_1_3_2_2_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3395351.3399360"},{"key":"e_1_3_2_2_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2011.2124466"},{"key":"e_1_3_2_2_56_1","volume-title":"Embedded and cyber-physical systems in a nutshell","author":"Marwedel P.","year":"2010","unstructured":"P. Marwedel . Embedded and cyber-physical systems in a nutshell . DAC.COM Knowledge Center Article , 2010 . P. Marwedel. Embedded and cyber-physical systems in a nutshell. DAC.COM Knowledge Center Article, 2010."},{"key":"e_1_3_2_2_57_1","volume-title":"DICE: Automatic emulation of dma input channels for dynamic firmware analysis. To appear at IEEE SP","author":"Mera A.","year":"2021","unstructured":"A. Mera , B. Feng , L. Lu , E. Kirda , and W. Robertson . DICE: Automatic emulation of dma input channels for dynamic firmware analysis. To appear at IEEE SP , 2021 . A. Mera, B. Feng, L. Lu, E. Kirda, and W. Robertson. DICE: Automatic emulation of dma input channels for dynamic firmware analysis. To appear at IEEE SP, 2021."},{"key":"e_1_3_2_2_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISIE.2007.4374971"},{"key":"e_1_3_2_2_59_1","volume-title":"BAR","author":"Muench M.","year":"2018","unstructured":"M. Muench , D. Nisi , A. Francillon , and D. Balzarotti . Avatar\u00b2: A Multi-target Orchestration Platform . In BAR , 2018 . M. Muench, D. Nisi, A. Francillon, and D. Balzarotti. Avatar\u00b2: A Multi-target Orchestration Platform. In BAR, 2018."},{"key":"e_1_3_2_2_60_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23166"},{"key":"e_1_3_2_2_61_1","volume-title":"USENIX WOOT","author":"Obermaier J.","year":"2017","unstructured":"J. Obermaier and S. Tatschner . Shedding too much light on a microcontroller's firmware protection . In USENIX WOOT , 2017 . J. Obermaier and S. Tatschner. Shedding too much light on a microcontroller's firmware protection. In USENIX WOOT, 2017."},{"key":"e_1_3_2_2_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSS.2001.957916"},{"key":"e_1_3_2_2_63_1","volume-title":"USENIX Security","author":"Peng F.","year":"2014","unstructured":"F. Peng , Z. Deng , X. Zhang , D. Xu , Z. Lin , and Z. Su . X-force: force-executing binary programs for security applications . In USENIX Security , 2014 . F. Peng, Z. Deng, X. Zhang, D. Xu, Z. Lin, and Z. Su. X-force: force-executing binary programs for security applications. In USENIX Security, 2014."},{"key":"e_1_3_2_2_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/2755563"},{"key":"e_1_3_2_2_65_1","volume-title":"BlackHat USA","author":"Quynh N. A.","year":"2015","unstructured":"N. A. Quynh and D. H. Vu . Unicorn: Next generation cpu emulator framework . BlackHat USA , 2015 . N. A. Quynh and D. H. Vu. Unicorn: Next generation cpu emulator framework. BlackHat USA, 2015."},{"key":"e_1_3_2_2_66_1","author":"Ramsey N.","year":"1997","unstructured":"N. Ramsey and M. F. Fernandez . Specifying representations of machine instructions. Transactions on Programming Languages and Systems , 1997 . N. Ramsey and M. F. Fernandez. Specifying representations of machine instructions. Transactions on Programming Languages and Systems, 1997.","journal-title":"Specifying representations of machine instructions. Transactions on Programming Languages and Systems"},{"key":"e_1_3_2_2_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00036"},{"key":"e_1_3_2_2_68_1","volume-title":"USENIX OSDI","author":"Renzelmann M. J.","year":"2012","unstructured":"M. J. Renzelmann , A. Kadav , and M. M. Swift . Symdrive: testing drivers without devices . In USENIX OSDI , 2012 . M. J. Renzelmann, A. Kadav, and M. M. Swift. Symdrive: testing drivers without devices. In USENIX OSDI, 2012."},{"key":"e_1_3_2_2_69_1","volume-title":"USENIX Security","author":"Ruge J.","year":"2020","unstructured":"J. Ruge , J. Classen , F. Gringoli , and M. Hollick . Frankenstein: Advanced wireless fuzzing to exploit new bluetooth escalation targets . In USENIX Security , 2020 . J. Ruge, J. Classen, F. Gringoli, and M. Hollick. Frankenstein: Advanced wireless fuzzing to exploit new bluetooth escalation targets. In USENIX Security, 2020."},{"key":"e_1_3_2_2_70_1","volume-title":"SSTIC","author":"Saudel F.","year":"2015","unstructured":"F. Saudel and J. Salwan . Triton: A dynamic symbolic execution framework . In SSTIC , 2015 . F. Saudel and J. Salwan. Triton: A dynamic symbolic execution framework. In SSTIC, 2015."},{"key":"e_1_3_2_2_71_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.26"},{"key":"e_1_3_2_2_72_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23294"},{"key":"e_1_3_2_2_73_1","volume-title":"USENIX WOOT","author":"Shwartz O.","year":"2017","unstructured":"O. Shwartz , A. Cohen , A. Shabtai , and Y. Oren . Shattered trust: When replacement smartphone components attack . In USENIX WOOT , 2017 . O. Shwartz, A. Cohen, A. Shabtai, and Y. Oren. Shattered trust: When replacement smartphone components attack. In USENIX WOOT, 2017."},{"key":"e_1_3_2_2_74_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23176"},{"key":"e_1_3_2_2_75_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-37300-8_2"},{"key":"e_1_3_2_2_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/FMCAD.2015.7542266"},{"key":"e_1_3_2_2_77_1","volume-title":"USENIX Security","author":"Talebi S. M. S.","year":"2018","unstructured":"S. M. S. Talebi , H. Tavakoli , H. Zhang , Z. Zhang , : Facilitating dynamic analysis of device drivers of mobile systems . In USENIX Security , 2018 . S. M. S. Talebi, H. Tavakoli, H. Zhang, Z. Zhang, et al. Charm: Facilitating dynamic analysis of device drivers of mobile systems. In USENIX Security, 2018."},{"key":"e_1_3_2_2_78_1","unstructured":"O. Thomas. Integrated circuit reverse engineering and code dumping 2019.  O. Thomas. Integrated circuit reverse engineering and code dumping 2019."},{"key":"e_1_3_2_2_79_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04138-9_26"},{"key":"e_1_3_2_2_80_1","volume-title":"Breaking all the things-a systematic survey of firmware extraction techniques for iot devices","author":"Vasile S.","year":"2018","unstructured":"S. Vasile , D. Oswald , and T. Chothia . Breaking all the things-a systematic survey of firmware extraction techniques for iot devices . In Springer CARDIS , 2018 . S. Vasile, D. Oswald, and T. Chothia. Breaking all the things-a systematic survey of firmware extraction techniques for iot devices. In Springer CARDIS, 2018."},{"key":"e_1_3_2_2_81_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23225"},{"key":"e_1_3_2_2_82_1","volume-title":"https:\/\/hardwear.io\/document\/rtos-exploit-mitigation-blues-hardwear-io.pdf","author":"Wetzels J.","year":"2017","unstructured":"J. Wetzels . The rtos exploit mitigation blues. https:\/\/hardwear.io\/document\/rtos-exploit-mitigation-blues-hardwear-io.pdf , 2017 . J. Wetzels. The rtos exploit mitigation blues. https:\/\/hardwear.io\/document\/rtos-exploit-mitigation-blues-hardwear-io.pdf, 2017."},{"key":"e_1_3_2_2_83_1","doi-asserted-by":"publisher","DOI":"10.1145\/3423167"},{"key":"e_1_3_2_2_84_1","doi-asserted-by":"publisher","DOI":"10.1109\/MELCON.2010.5475901"},{"key":"e_1_3_2_2_85_1","doi-asserted-by":"publisher","DOI":"10.1109\/ITNEC.2019.8729362"},{"key":"e_1_3_2_2_86_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23229"},{"key":"e_1_3_2_2_87_1","volume-title":"The equivalence problem for computational models: decidable and undecidable cases","author":"Zakharov V. A.","year":"2001","unstructured":"V. A. Zakharov . The equivalence problem for computational models: decidable and undecidable cases . In Springer MCU , 2001 . V. A. Zakharov. The equivalence problem for computational models: decidable and undecidable cases. In Springer MCU, 2001."},{"key":"e_1_3_2_2_88_1","volume-title":"USENIX Security","author":"Zheng Y.","year":"2019","unstructured":"Y. Zheng , A. Davanian , H. Yin , C. Song , H. Zhu , and L. Sun . Firm-afl: High-throughput greybox fuzzing of iot firmware via augmented process emulation . In USENIX Security , 2019 . Y. Zheng, A. Davanian, H. Yin, C. Song, H. Zhu, and L. Sun. Firm-afl: High-throughput greybox fuzzing of iot firmware via augmented process emulation. In USENIX Security, 2019."}],"event":{"name":"ASIA CCS '21: ACM Asia Conference on Computer and Communications Security","location":"Virtual Event Hong Kong","acronym":"ASIA CCS '21","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3433210.3453093","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/abs\/10.1145\/3433210.3453093","content-type":"text\/html","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3433210.3453093","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3433210.3453093","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:48:12Z","timestamp":1750193292000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3433210.3453093"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,5,24]]},"references-count":88,"alternative-id":["10.1145\/3433210.3453093","10.1145\/3433210"],"URL":"https:\/\/doi.org\/10.1145\/3433210.3453093","relation":{},"subject":[],"published":{"date-parts":[[2021,5,24]]},"assertion":[{"value":"2021-06-04","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}