{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T17:57:42Z","timestamp":1783619862904,"version":"3.55.0"},"reference-count":86,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2022,9,2]],"date-time":"2022-09-02T00:00:00Z","timestamp":1662076800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,9,2]],"date-time":"2022-09-02T00:00:00Z","timestamp":1662076800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Fuzzing has become one of the best-established methods to uncover software bugs. Meanwhile, the market of embedded systems, which binds the software execution tightly to the very hardware architecture, has grown at a steady pace, and that pace is anticipated to become yet more sustained in the near future. Embedded systems also benefit from fuzzing, but the innumerable existing architectures and hardware peripherals complicate the development of general and usable approaches, hence a plethora of tools have recently appeared. Here comes a stringent need for a systematic review in the area of fuzzing approaches for embedded systems, which we term \u201cembedded fuzzing\u201d for brevity. The inclusion criteria chosen in this article are semi-objective in their coverage of the most relevant publication venues as well as of our personal judgement. The review rests on a formal definition we develop to represent the realm of embedded fuzzing. It continues by discussing the approaches that satisfy the inclusion criteria, then defines the relevant elements of comparison and groups the approaches according to how the execution environment is served to the system under test. The resulting review produces a table with 42 entries, which in turn supports discussion suggesting vast room for future research due to the limitations noted.<\/jats:p>","DOI":"10.1186\/s42400-022-00123-y","type":"journal-article","created":{"date-parts":[[2022,9,2]],"date-time":"2022-09-02T02:02:37Z","timestamp":1662084157000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":37,"title":["Embedded fuzzing: a review of challenges, tools, and solutions"],"prefix":"10.1186","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6249-2077","authenticated-orcid":false,"given":"Max","family":"Eisele","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marcello","family":"Maugeri","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rachna","family":"Shriwas","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christopher","family":"Huth","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Giampaolo","family":"Bella","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,9,2]]},"reference":[{"key":"123_CR1","unstructured":"2014 Cyber grand challenge. http:\/\/archive.darpa.mil\/cybergrandchallenge\/about.html. Accessed 13 Nov 2020"},{"key":"123_CR2","unstructured":"Aafer Y, You W, Sun Y, Shi Y, Zhang X, Yin H (2021) Android smarttvs vulnerability discovery via log-guided fuzzing. In: 30th {USENIX} security symposium ({USENIX} Security 21)"},{"key":"123_CR3","doi-asserted-by":"publisher","unstructured":"Ai C, Dong W, Gao Z (2020) A novel concolic execution approach on embedded device. In: Proceedings of the 2020 4th international conference on cryptography, security and privacy. ICCSP 2020. Association for Computing Machinery, New York, NY, USA, pp 47\u201352. https:\/\/doi.org\/10.1145\/3377644.3377654","DOI":"10.1145\/3377644.3377654"},{"key":"123_CR4","unstructured":"Alsop T (2019) Global Embedded Computing Market Revenue from 2018 to 2027 (in Billion U.S. Dollars) The Insight Partners. Accessed 9 March 2021"},{"key":"123_CR5","doi-asserted-by":"crossref","unstructured":"Boehme M, Cadar C, Roychoudhury A (2020) Fuzzing: Challenges and reflections. IEEE Software","DOI":"10.1109\/MS.2020.3016773"},{"key":"123_CR6","doi-asserted-by":"crossref","unstructured":"Bogad K, Huber M (2019) Harzer roller: Linker-based instrumentation for enhanced embedded security testing. In: Proceedings of the 3rd reversing and offensive-oriented trends symposium, pp 1\u20139","DOI":"10.1145\/3375894.3375897"},{"issue":"2","key":"123_CR7","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3210309","volume":"27","author":"M B\u00f6hme","year":"2018","unstructured":"B\u00f6hme M (2018) Stads: Software testing as species discovery. ACM Trans Softw Eng Methodol (TOSEM) 27(2):1\u201352","journal-title":"ACM Trans Softw Eng Methodol (TOSEM)"},{"key":"123_CR8","doi-asserted-by":"crossref","unstructured":"B\u00f6rsig M, Nitzsche S, Eisele M, Gr\u00f6ll R, Becker J, Baumgart I (2020) Fuzzing framework for esp32 microcontrollers. In: 2020 IEEE international workshop on information forensics and security (WIFS). IEEE, pp 1\u20136","DOI":"10.1109\/WIFS49906.2020.9360889"},{"key":"123_CR9","unstructured":"Cadar C, Dunbar D, Engler DR et al (2008) Klee: unassisted and automatic generation of high-coverage tests for complex systems programs. In: OSDI, vol 8, pp 209\u2013224"},{"key":"123_CR10","doi-asserted-by":"crossref","unstructured":"Chen DD, Woo M, Brumley D, Egele M (2016) Towards automated dynamic analysis for linux-based embedded firmware. In: NDSS, vol 16, pp 1\u201316","DOI":"10.14722\/ndss.2016.23415"},{"key":"123_CR11","doi-asserted-by":"crossref","unstructured":"Chen J, Diao W, Zhao Q, Zuo C, Lin Z, Wang X, Lau WC, Sun M, Yang R, Zhang K (2018) Iotfuzzer: Discovering memory corruptions in iot through app-based fuzzing. In: NDSS","DOI":"10.14722\/ndss.2018.23159"},{"key":"123_CR12","unstructured":"Chen Y, Jiang Y, Ma F, Liang J, Wang M, Zhou C, Jiao X, Su Z (2019) Enfuzz: Ensemble fuzzing with seed synchronization among diverse fuzzers. In: 28th {USENIX} security symposium ({USENIX} Security 19), pp 1967\u20131983"},{"key":"123_CR13","unstructured":"Clements AA, Gustafson E, Scharnowski T, Grosen P, Fritz D, Kruegel C, Vigna G, Bagchi S, Payer M (2020) Halucinator: Firmware re-hosting through abstraction layer emulation. In: 29th USENIX security symposium (USENIX Sec), pp 1\u201318"},{"key":"123_CR14","unstructured":"Corteggiani N, Camurati G, Francillon A (2018) Inception: System-wide security testing of real-world embedded systems software. In: 27th {USENIX} security symposium ({USENIX} security 18), pp 309\u2013326"},{"key":"123_CR15","unstructured":"Davidson D, Moench B, Ristenpart T, Jha S (2013) FIE on firmware: Finding vulnerabilities in embedded systems using symbolic execution. In: 22nd USENIX Security Symposium (USENIX Security 13), pp. 463\u2013478. USENIX Association, Washington, D.C. https:\/\/www.usenix.org\/conference\/usenixsecurity13\/technical-sessions\/paper\/davidson"},{"key":"123_CR16","unstructured":"Delshadtehrani L, Canakci S, Zhou B, Eldridge S, Joshi A, Egele M (2020) Phmon: a programmable hardware monitor and its security use cases. In: 29th {USENIX} security symposium ({USENIX} Security 20), pp 807\u2013824"},{"key":"123_CR17","doi-asserted-by":"publisher","unstructured":"Dolan-Gavitt B, Hodosh J, Hulin P, Leek T, Whelan R (2015). Repeatable reverse engineering with panda. In: Proceedings of the 5th Program Protection and Reverse Engineering Workshop. PPREW-5. Association for Computing Machinery, New York, NY, USA. https:\/\/doi.org\/10.1145\/2843859.2843867","DOI":"10.1145\/2843859.2843867"},{"key":"123_CR18","doi-asserted-by":"publisher","unstructured":"Dolan-Gavitt B, Hulin P, Kirda E, Leek T, Mambretti A, Robertson W, Ulrich F, Whelan, R (2016) Lava: Large-scale automated vulnerability addition. In: 2016 IEEE symposium on security and privacy (SP), pp 110\u2013121. https:\/\/doi.org\/10.1109\/SP.2016.15","DOI":"10.1109\/SP.2016.15"},{"key":"123_CR19","doi-asserted-by":"crossref","unstructured":"Fan R, Pan J, Huang, S (2020) Arm-afl: Coverage-guided fuzzing framework for arm-based IoT devices. In: International conference on applied cryptography and network security. Springer, pp 239\u2013254","DOI":"10.1007\/978-3-030-61638-0_14"},{"key":"123_CR20","doi-asserted-by":"crossref","unstructured":"Fasano A, Ballo T, Muench M, Leek T, Bulekov A, Dolan-Gavitt B, Egele M, Francillon A, Lu L, Gregory N et al (2021) Sok: Enabling security analyses of embedded systems via rehosting. In: Proceedings of the 2021 ACM Asia conference on computer and communications security, pp 687\u2013701","DOI":"10.1145\/3433210.3453093"},{"key":"123_CR21","unstructured":"Feng B, Mera A, Lu L (2020) P2im: Scalable and hardware-independent firmware testing via automatic peripheral interface modeling. In: 29th {USENIX} security symposium ({USENIX} security 20), pp 1237\u20131254"},{"key":"123_CR22","doi-asserted-by":"crossref","unstructured":"Feng X, Sun R, Zhu X, Xue M, Wen S, Liu D, Nepal S, Xiang Y (2021) Snipuzz: Black-box fuzzing of iot firmware via message snippet inference. arXiv preprint arXiv:2105.05445","DOI":"10.1145\/3460120.3484543"},{"key":"123_CR23","unstructured":"Fioraldi A, Maier D, Ei\u00dffeldt H, Heuse M (2020) Afl++: Combining incremental steps of fuzzing research. In: 14th {USENIX} Workshop on Offensive Technologies ({WOOT} 20)"},{"key":"123_CR24","unstructured":"FRIDA Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers. https:\/\/frida.re\/. Accessed 4 Nov 2020"},{"key":"123_CR25","unstructured":"Garc\u00eda CP, ul Hassan S, Tuveri N, Gridin I, Aldaya AC, Brumley BB (2020) Certified side channels. In: 29th {USENIX} security symposium ({USENIX} security 20), pp 2021\u20132038"},{"key":"123_CR26","unstructured":"Group S-SCSW (2011) IEEE 1666-2011 - IEEE Standard for Standard SystemC Language Reference Manual. https:\/\/standards.ieee.org\/standard\/1666-2011.html"},{"key":"123_CR27","unstructured":"Guedou (2017) Using Miasm to fuzz binaries with AFL. https:\/\/guedou.github.io\/talks\/2017_BeeRump\/slides.pdf"},{"key":"123_CR28","doi-asserted-by":"publisher","first-page":"29826","DOI":"10.1109\/ACCESS.2020.2973043","volume":"8","author":"Z Gui","year":"2020","unstructured":"Gui Z, Shu H, Kang F, Xiong X (2020) Firmcorn: Vulnerability-oriented fuzzing of iot firmware via optimized virtual execution. IEEE Access 8:29826\u201329841","journal-title":"IEEE Access"},{"key":"123_CR29","unstructured":"Gustafson E, Muench M, Spensky C, Redini N, Machiry A, Fratantonio Y, Balzarotti D, Francillon A, Choe YR, Kruegel C et al. (2019) Toward the analysis of embedded firmware through automated re-hosting. In: 22nd international symposium on research in attacks, intrusions and defenses ({RAID} 2019), pp 135\u2013150"},{"key":"123_CR30","unstructured":"Harrison L, Vijayakumar H, Padhye R, Sen K, Grace M (2020) {PARTEMU}: Enabling dynamic analysis of real-world trustzone software using emulation. In: 29th {USENIX} security symposium ({USENIX} Security 20), pp 789\u2013806"},{"key":"123_CR31","doi-asserted-by":"crossref","unstructured":"He S, Emmi M, Ciocarlie G (2020) ct-fuzz: Fuzzing for timing leaks. In: 2020 IEEE 13th international conference on software testing, validation and verification (ICST). IEEE, pp 466\u2013471","DOI":"10.1109\/ICST46399.2020.00063"},{"key":"123_CR32","doi-asserted-by":"crossref","unstructured":"Herdt V, Gro\u00dfe D, Le HM, Drechsler R (2019) Early concolic testing of embedded binaries with virtual prototypes: a risc-v case study*. In: 2019 56th ACM\/IEEE design automation conference (DAC), pp 1\u20136","DOI":"10.1145\/3316781.3317807"},{"key":"123_CR33","doi-asserted-by":"crossref","unstructured":"Herdt V, Gro\u00dfe D, Wloka J, G\u00fcneysu T, Drechsler R (2020) Verification of embedded binaries using coverage-guided fuzzing with systemc-based virtual prototypes. In: Proceedings of the 2020 on Great Lakes symposium on VLSI, pp 101\u2013106","DOI":"10.1145\/3386263.3406899"},{"key":"123_CR34","unstructured":"Hertz J, Newsham T (2021) TriforceAFL. https:\/\/github.com\/nccgroup\/TriforceAFL. Accessed 9 Feb 2021"},{"key":"123_CR35","unstructured":"Information technology\u2014Security techniques\u2014Information security management systems. Standard, International Organization for Standardization, Geneva, CH (2013)"},{"key":"123_CR36","unstructured":"Johnson E, Bland M, Zhu Y, Mason J, Checkoway S, Savage S, Levchenko, K (2021) Jetset: Targeted firmware rehosting for embedded systems. In: 30th {USENIX} security symposium ({USENIX} security 21)"},{"key":"123_CR37","doi-asserted-by":"crossref","unstructured":"Kammerstetter M, Platzer C, Kastner W (2014) Prospect: peripheral proxying supported embedded code testing. In: Proceedings of the 9th ACM symposium on information, computer and communications security, pp 329\u2013340","DOI":"10.1145\/2590296.2590301"},{"key":"123_CR38","unstructured":"Kim T, Kim CH, Rhee J, Fei F, Tu Z, Walkup G, Zhang X, Deng X, Xu D (2019) Rvfuzzer: finding input validation bugs in robotic vehicles through control-guided testing. In: 28th {USENIX} security symposium ({USENIX} security 19), pp 425\u2013442"},{"key":"123_CR39","doi-asserted-by":"crossref","unstructured":"Kim M, Kim D, Kim E, Kim S, Jang Y, Kim Y (2020) Firmae: Towards large-scale emulation of iot firmware for dynamic analysis. In: Annual computer security applications conference 2020. ACM","DOI":"10.1145\/3427228.3427294"},{"issue":"7","key":"123_CR40","doi-asserted-by":"publisher","first-page":"385","DOI":"10.1145\/360248.360252","volume":"19","author":"JC King","year":"1976","unstructured":"King JC (1976) Symbolic execution and program testing. Commun ACM 19(7):385\u2013394","journal-title":"Commun ACM"},{"key":"123_CR41","doi-asserted-by":"crossref","unstructured":"Klees G, Ruef A, Cooper B, Wei S, Hicks M (2018) Evaluating fuzz testing. In: Proceedings of the 2018 ACM SIGSAC conference on computer and communications security, pp 2123\u20132138","DOI":"10.1145\/3243734.3243804"},{"key":"123_CR42","unstructured":"Koscher K, Kohno T, Molnar D (2015) $${SURROGATES}$$: Enabling near-real-time dynamic analyses of embedded systems. In: 9th {USENIX} workshop on offensive technologies ({WOOT} 15)"},{"key":"123_CR43","doi-asserted-by":"crossref","unstructured":"Laeufer K, Koenig J, Kim D, Bachrach J, Sen K (2018) Rfuzz: coverage-directed fuzz testing of RTL on FPGAs. In: 2018 IEEE\/ACM international conference on computer-aided design (ICCAD). IEEE, pp 1\u20138","DOI":"10.1145\/3240765.3240842"},{"key":"123_CR44","unstructured":"Lauterbach: Lauterbach Development Tools. https:\/\/www.lauterbach.com. Accessed 22 Nov 2021"},{"key":"123_CR45","unstructured":"LLVM: libFuzzer\u2013a library for coverage-guided fuzz testing. https:\/\/llvm.org\/docs\/LibFuzzer.html. Accessed 22 Nov 2021"},{"key":"123_CR46","doi-asserted-by":"crossref","unstructured":"Maier D, Seidel L, Park S (2020) Basesafe: baseband sanitized fuzzing through emulation. In: Proceedings of the 13th ACM conference on security and privacy in wireless and mobile networks, pp 122\u2013132","DOI":"10.1145\/3395351.3399360"},{"key":"123_CR47","doi-asserted-by":"crossref","unstructured":"Mera A, Feng B, Lu L, Kirda E, Robertson W (2020) Dice: Automatic emulation of DMA input channels for dynamic firmware analysis. arXiv preprint arXiv:2007.01502","DOI":"10.1109\/SP40001.2021.00018"},{"key":"123_CR48","doi-asserted-by":"crossref","unstructured":"Muench M, Nisi D, Francillon A, Balzarotti D (2018) Avatar2: a multi-target orchestration platform. In: BAR 2018, workshop on binary analysis research, Colocated with NDSS Symposium, 18 February 2018, San Diego, USA, San Diego, \u00c9TATS-UNIS. http:\/\/www.eurecom.fr\/publication\/5437","DOI":"10.14722\/bar.2018.23017"},{"key":"123_CR49","doi-asserted-by":"crossref","unstructured":"Muench M, Stijohann J, Kargl F, Francillon A, Balzarotti D (2018) What you corrupt is not what you crash: Challenges in fuzzing embedded devices. In: NDSS","DOI":"10.14722\/ndss.2018.23166"},{"key":"123_CR50","unstructured":"Natella R (2021) Stateafl: Greybox fuzzing for stateful network servers. arXiv preprint arXiv:2110.06253"},{"key":"123_CR51","unstructured":"Nguyen AQ, Dang HV (2015) Unicorn: Next generation CPU emulator framework. In: Proceedings of the 2015 Blackhat USA conference"},{"key":"123_CR52","doi-asserted-by":"crossref","unstructured":"Nilizadeh S, Noller Y, Pasareanu CS (2019). Diffuzz: differential fuzzing for side-channel analysis. In: 2019 IEEE\/ACM 41st international conference on software engineering (ICSE). IEEE, pp 176\u2013187","DOI":"10.1109\/ICSE.2019.00034"},{"key":"123_CR53","unstructured":"Noergaard T (2012) Embedded systems architecture 2nd edition, a comprehensive guide for engineers and programmers"},{"key":"123_CR54","doi-asserted-by":"crossref","unstructured":"Noller Y, P\u0103s\u0103reanu CS, B\u00f6hme M, Sun Y, Nguyen HL, Grunske L (2020). Hydiff: Hybrid differential software analysis. In: 2020 IEEE\/ACM 42nd international conference on software engineering (ICSE). IEEE, pp 1273\u20131285","DOI":"10.1145\/3377811.3380363"},{"key":"123_CR55","doi-asserted-by":"crossref","unstructured":"Oh J, Kim S, Jeong E, Moon S-M (2015) Os-less dynamic binary instrumentation for embedded firmware. In: 2015 IEEE symposium in low-power and high-speed chips (COOL CHIPS XVIII). IEEE, pp 1\u20133","DOI":"10.1109\/CoolChips.2015.7158659"},{"key":"123_CR56","unstructured":"Pereyda J (2017) boofuzz: Network protocol fuzzing for humans. Accessed 17 Feb"},{"key":"123_CR57","doi-asserted-by":"crossref","unstructured":"Pham V-T, B\u00f6hme M, Roychoudhury A (2020) Aflnet: a greybox fuzzer for network protocols. In: 2020 IEEE 13th international conference on software testing, validation and verification (ICST). IEEE, pp 460\u2013465","DOI":"10.1109\/ICST46399.2020.00062"},{"key":"123_CR58","unstructured":"Poeplau S, Francillon A (2020) Symbolic execution with symcc: Don\u2019t interpret, compile! In: 29th {USENIX} security symposium ({USENIX} Security 20), pp 181\u2013198"},{"key":"123_CR59","doi-asserted-by":"crossref","unstructured":"Redini N, Continella A, Das D, De Pasquale G, Spahn N, Machiry A, Bianchi A, Kruegel C, Vigna, G (2021) Diane: Identifying fuzzing triggers in apps to generate under-constrained inputs for IoT devices. In: 42nd IEEE symposium on security and privacy 2021","DOI":"10.1109\/SP40001.2021.00066"},{"key":"123_CR60","unstructured":"Road vehicles\u2014Cybersecurity engineering. Standard, International Organization for Standardization, Geneva, CH (2021)"},{"key":"123_CR61","unstructured":"Road vehicles\u2014Functional safety. Standard, International Organization for Standardization, Geneva, CH (2018)"},{"key":"123_CR62","unstructured":"Ruge J, Classen J, Gringoli F, Hollick M (2020) Frankenstein: Advanced wireless fuzzing to exploit new bluetooth escalation targets. In: 29th {USENIX} security symposium ({USENIX} Security 20), pp 19\u201336"},{"key":"123_CR63","unstructured":"Scharnowski T, Bars N, Schloegel M, Gustafson E, Muench M, Vigna G, Kruegel C, Holz T, Abbasi A Fuzzware: Using precise mmio modeling for effective firmware fuzzing"},{"key":"123_CR64","unstructured":"Google Scholar Top 20 Computer Security & Cryptography Conferences. https:\/\/scholar.google.com\/citations?view_op=top_venues&vq=eng_computersecuritycryptography. Accessed 2 Dec 2021"},{"key":"123_CR65","doi-asserted-by":"crossref","unstructured":"Schumilo S, Aschermann C, Jemmett A, Abbasi A, Holz T (2021) Nyx-net: Network fuzzing with incremental snapshots. arXiv preprint arXiv:2111.03013","DOI":"10.1145\/3492321.3519591"},{"key":"123_CR66","unstructured":"Secure product development lifecycle requirements. Standard, International Electrotechnical Commission, Geneva, CH (2018)"},{"key":"123_CR67","unstructured":"Security and resilience\u2014Business continuity management systems. Standard, International Organization for Standardization, Geneva, CH (2019)"},{"key":"123_CR68","unstructured":"Segger: Segger Debug & Trace Probes. https:\/\/www.segger.com\/products\/debug-trace-probes\/. Accessed 22 Nov 2021"},{"key":"123_CR69","unstructured":"Serebryany K (2017) Oss-fuzz-google\u2019s continuous fuzzing service for open source software"},{"key":"123_CR70","unstructured":"Software and systems engineering\u2014Software testing. Standard, International Organization for Standardization, Geneva, CH (2013)"},{"key":"123_CR71","doi-asserted-by":"crossref","unstructured":"Song D, Hetzelt F, Das D, Spensky C, Na Y, Volckaert S, Vigna G, Kruegel C, Seifert J-P, Franz M (2019) Periscope: an effective probing and fuzzing framework for the hardware-OS boundary. In: NDSS","DOI":"10.14722\/ndss.2019.23176"},{"key":"123_CR72","doi-asserted-by":"crossref","unstructured":"Spensky C, Machiry A, Redini N, Unger C, Foster G, Blasband E, Okhravi H, Kruegel C, Vigna G (2021) Conware: automated modeling of hardware peripherals. In: Proceedings of the 2021 ACM Asia conference on computer and communications security, pp 95\u2013109","DOI":"10.1145\/3433210.3437532"},{"key":"123_CR73","doi-asserted-by":"crossref","unstructured":"Sperl P, B\u00f6ttinger K (2019) Side-channel aware fuzzing. In: European symposium on research in computer security. Springer, pp 259\u2013278","DOI":"10.1007\/978-3-030-29959-0_13"},{"key":"123_CR74","doi-asserted-by":"crossref","unstructured":"Srivastava P, Peng H, Li J, Okhravi H, Shrobe H, Payer M (2019) Firmfuzz: automated iot firmware introspection and analysis. In: Proceedings of the 2nd international ACM workshop on security and privacy for the Internet-of-Things, pp 15\u201321","DOI":"10.1145\/3338507.3358616"},{"key":"123_CR75","unstructured":"Swiecki R honggfuzz - Security oriented software fuzzer. https:\/\/honggfuzz.dev\/. Accessed 22 Nov 2021"},{"key":"123_CR76","unstructured":"Systems and software engineering\u2014Software life cycle processes. Standard, International Organization for Standardization, Geneva, CH (2017)"},{"key":"123_CR77","unstructured":"Talebi SMS, Tavakoli H, Zhang H, Zhang Z, Sani AA, Qian Z (2018) Charm: Facilitating dynamic analysis of device drivers of mobile systems. In: 27th {USENIX} security symposium ({USENIX} security 18), pp 291\u2013307"},{"key":"123_CR78","unstructured":"Trippel T, Shin KG, Chernyakhovsky A, Kelly G, Rizzo D, Hicks M (2021) Fuzzing hardware like software. arXiv preprint arXiv:2102.02308"},{"key":"123_CR79","unstructured":"Tychalas D, Benkraouda H, Maniatakos M (2021) Icsfuzz: Manipulating i\/os and repurposing binary code to enable instrumented fuzzing in $${ICS}$$ control applications. In: 30th {USENIX} Security Symposium ({USENIX} Security 21)"},{"key":"123_CR80","unstructured":"Voss N, Fuzzing the Unfuzzable. https:\/\/hackernoon.com\/afl-unicorn-part-2-fuzzing-the-unfuzzable-bea8de3540a5. Accessed 25 Feb 2021"},{"issue":"1","key":"123_CR81","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3423167","volume":"54","author":"C Wright","year":"2021","unstructured":"Wright C, Moeglein WA, Bagchi S, Kulkarni M, Clements AA (2021) Challenges in firmware re-hosting, emulation, and analysis. ACM Comput Surv (CSUR) 54(1):1\u201336","journal-title":"ACM Comput Surv (CSUR)"},{"key":"123_CR82","unstructured":"Yun I, Lee S, Xu M, Jang Y, Kim T (2018) Qsym: a practical concolic execution engine tailored for hybrid fuzzing. In: 27th USENIX security symposium (security 2018). Distinguished Paper Award Winner. https:\/\/www.microsoft.com\/en-us\/research\/publication\/qsym-a-practical-concolic-execution-engine-tailored-for-hybrid-fuzzing\/"},{"key":"123_CR83","doi-asserted-by":"crossref","unstructured":"Yu B, Wang P, Yue T, Tang Y (2019) Poster: Fuzzing IoT firmware via multi-stage message generation. In: Proceedings of the 2019 ACM SIGSAC conference on computer and communications security, pp 2525\u20132527","DOI":"10.1145\/3319535.3363247"},{"key":"123_CR84","doi-asserted-by":"crossref","unstructured":"Zaddach J, Bruno L, Francillon A, Balzarotti D et al (2014) Avatar: A framework to support dynamic security analysis of embedded systems\u2019 firmwares. In: NDSS 23, pp 1\u201316","DOI":"10.14722\/ndss.2014.23229"},{"key":"123_CR85","unstructured":"Zheng Y, Davanian A, Yin H, Song C, Zhu H, Sun L (2019) Firm-afl: high-throughput greybox fuzzing of iot firmware via augmented process emulation. In: 28th {USENIX} security symposium ({USENIX} security 19), pp 1099\u20131114"},{"key":"123_CR86","unstructured":"Zhou W, Guan L, Liu P, Zhang Y (2021) Automatic firmware emulation through invalidity-guided knowledge inference. In: 30th {USENIX} security symposium ({USENIX} Security 21)"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-022-00123-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-022-00123-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-022-00123-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,9,2]],"date-time":"2022-09-02T02:03:54Z","timestamp":1662084234000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-022-00123-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,9,2]]},"references-count":86,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2022,12]]}},"alternative-id":["123"],"URL":"https:\/\/doi.org\/10.1186\/s42400-022-00123-y","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,9,2]]},"assertion":[{"value":"21 April 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 March 2022","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 September 2022","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"18"}}