{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T00:10:33Z","timestamp":1778458233728,"version":"3.51.4"},"reference-count":67,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T00:00:00Z","timestamp":1778457600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T00:00:00Z","timestamp":1778457600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>\n                    Coverage-guided fuzzing has been widely applied to address zero-day vulnerabilities in general-purpose software and operating systems. This approach relies on instrumenting the target code at compile time. However, applying it to industrial systems remains challenging, due to proprietary and closed-source compiler toolchains and lack of access to source code.\n                    <jats:italic>FuzzBox<\/jats:italic>\n                    addresses these limitations by integrating emulation with fuzzing: it dynamically instruments code during execution in a virtualized environment, for the injection of fuzz inputs, failure detection, and coverage analysis, without requiring source code recompilation and hardware-specific dependencies. We show the effectiveness of\n                    <jats:italic>FuzzBox<\/jats:italic>\n                    through experiments in the context of a proprietary MILS (Multiple Independent Levels of Security) hypervisor for industrial applications. Additionally, we analyze the applicability of\n                    <jats:italic>FuzzBox<\/jats:italic>\n                    across commercial IoT firmware, showcasing its broad portability.\n                  <\/jats:p>","DOI":"10.1186\/s42400-025-00474-2","type":"journal-article","created":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T00:03:43Z","timestamp":1778457823000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Fuzzbox: blending fuzzing into emulation for binary-only embedded targets"],"prefix":"10.1186","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-7557-4973","authenticated-orcid":false,"given":"Carmine","family":"Cesarano","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1084-4824","authenticated-orcid":false,"given":"Roberto","family":"Natella","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,11]]},"reference":[{"issue":"3\u20134","key":"474_CR1","doi-asserted-by":"publisher","first-page":"239","DOI":"10.1504\/IJES.2006.014859","volume":"2","author":"J Alves-Foss","year":"2006","unstructured":"Alves-Foss J, Oman PW, Taylor C, Harrison WS (2006) The MILS architecture for high-assurance embedded systems. Int J Embedded Syst 2(3\u20134):239\u2013247","journal-title":"Int J Embedded Syst"},{"key":"474_CR2","doi-asserted-by":"crossref","unstructured":"Babi\u0107 D, Bucur S, Chen Y, Ivan\u010di\u0107 F, King T, Kusano M, Lemieux C, Szekeres L, Wang W (2019) FUDGE: Fuzz driver generation at scale. In: Proceedings of the 2019 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering","DOI":"10.1145\/3338906.3340456"},{"key":"474_CR3","unstructured":"Bellard F (2005) Qemu, a fast and portable dynamic translator. In: USENIX Annual Technical Conference, FREENIX Track. Califor-nia, USA"},{"key":"474_CR4","doi-asserted-by":"crossref","unstructured":"Chen J, Diao W, Zhao Q, Zuo C, Lin Z, Wang X, Lau WC, Sun M, Yang R, Zhang K (2018) Iotfuzzer: Discovering memory corruptions in iot through app-based fuzzing. In: NDSS","DOI":"10.14722\/ndss.2018.23159"},{"key":"474_CR5","doi-asserted-by":"crossref","unstructured":"Chen Y, Mu D, Xu J, Sun Z, Shen W, Xing X, Lu L, Mao B (2019) Ptrix: Efficient hardware-assisted fuzzing for cots binary. In: Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security","DOI":"10.1145\/3321705.3329828"},{"key":"474_CR6","unstructured":"Committee AEE (2005) ARINC 811: Commercial aircraft information security concepts of operation and process framework. Inc, Aeronautical Radio"},{"issue":"6","key":"474_CR7","doi-asserted-by":"publisher","first-page":"759","DOI":"10.3390\/electronics10060759","volume":"10","author":"E D\u00edaz","year":"2021","unstructured":"D\u00edaz E, Mateos R, Bueno EJ, Nieto R (2021) Enabling parallelized-qemu for hardware\/software co-simulation virtual platforms. Electronics 10(6):759","journal-title":"Electronics"},{"key":"474_CR8","doi-asserted-by":"crossref","unstructured":"Dinesh S, Burow N, Xu D, Payer M (2020) Retrowrite: Statically instrumenting cots binaries for fuzzing and sanitization. In: 2020 IEEE Symposium on Security and Privacy (SP). IEEE","DOI":"10.1109\/SP40000.2020.00009"},{"key":"474_CR9","unstructured":"Dlink - DCS-932L Firmware (2024) https:\/\/support.dlink.com.au\/download\/download.aspx?product=DCS-932L"},{"key":"474_CR10","doi-asserted-by":"crossref","unstructured":"Dolan-Gavitt B, Hulin P, Kirda E, Leek T, Mambretti A, Robertson W, Ulrich F, Whelan R (2016) Lava: Large-scale automated vulnerability addition. In: 2016 IEEE Symposium on Security and Privacy (SP). IEEE","DOI":"10.1109\/SP.2016.15"},{"key":"474_CR11","doi-asserted-by":"publisher","first-page":"102889","DOI":"10.1016\/j.cose.2022.102889","volume":"122","author":"X Du","year":"2022","unstructured":"Du X, Chen A, He B, Chen H, Zhang F, Chen Y (2022) AflIot: fuzzing on linux-based IoT device with binary-level instrumentation. Comput Secur 122:102889","journal-title":"Comput Secur"},{"issue":"1","key":"474_CR12","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1186\/s42400-022-00123-y","volume":"5","author":"M Eisele","year":"2022","unstructured":"Eisele M, Maugeri M, Shriwas R, Huth C, Bella G (2022) Embedded fuzzing: a review of challenges, tools, and solutions. Cybersecurity 5(1):18","journal-title":"Cybersecurity"},{"key":"474_CR13","doi-asserted-by":"crossref","unstructured":"Eisele M, Ebert D, Huth C, Zeller A (2023) Fuzzing embedded systems using debug interfaces. In: Proceedings of ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA 2023)","DOI":"10.1145\/3597926.3598115"},{"key":"474_CR14","doi-asserted-by":"crossref","unstructured":"Fasano A, Ballo T, Muench M, Leek T, Bulekov A, Dolan-Gavitt B, Egele M, Francillon A, Lu L, Gregory N, et al. (2021) Sok: Enabling security analyses of embedded systems via rehosting. In: Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security","DOI":"10.1145\/3433210.3453093"},{"key":"474_CR15","doi-asserted-by":"crossref","unstructured":"Feng X, Sun R, Zhu X, Xue M, Wen S, Liu D, Nepal S, Xiang Y (2021) Snipuzz: Black-box fuzzing of iot firmware via message snippet inference. In: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security","DOI":"10.1145\/3460120.3484543"},{"key":"474_CR16","doi-asserted-by":"crossref","unstructured":"Fioraldi A, Maier DC, Zhang D, Balzarotti D (2022) Libafl: A framework to build modular and reusable fuzzers. In: Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security","DOI":"10.1145\/3548606.3560602"},{"key":"474_CR17","unstructured":"Fioraldi A, Maier D, Ei\u00dffeldt H, Heuse M (2020) AFL++: Combining incremental steps of fuzzing research. In: 14th USENIX Workshop on Offensive Technologies (WOOT 20)"},{"key":"474_CR18","unstructured":"Fuzzable - Framework for Automating Fuzzable Target Discovery with Static Analysis (2023). https:\/\/github.com\/ex0dus-0x\/fuzzable"},{"issue":"11","key":"474_CR19","doi-asserted-by":"publisher","first-page":"3420","DOI":"10.1109\/TCAD.2020.3013046","volume":"39","author":"J Gao","year":"2020","unstructured":"Gao J, Xu Y, Jiang Y, Liu Z, Chang W, Jiao X, Sun J (2020) Em-fuzz: augmented firmware fuzzing via memory checking. IEEE Trans Comput Aided Des Integr Circuits Syst 39(11):3420\u20133432","journal-title":"IEEE Trans Comput Aided Des Integr Circuits Syst"},{"key":"474_CR20","unstructured":"Geng S, Li Y, Du Y, Xu J, Liu Y, Mao B (2020) An empirical study on benchmarks of artificial software vulnerabilities. arXiv preprint arXiv:2003.09561"},{"key":"474_CR21","unstructured":"GNU GCC (2023) https:\/\/gcc.gnu.org\/"},{"key":"474_CR22","unstructured":"google - Syzkaller (2015) https:\/\/github.com\/google\/syzkaller"},{"key":"474_CR23","unstructured":"Heuse, Marc - AFL-DynamoRIO (2018) https:\/\/github.com\/vanhauser-thc\/afl-dynamorio"},{"key":"474_CR24","unstructured":"Heuse, Marc - AFL-PIN (2020) https:\/\/github.com\/vanhauser-thc\/afl-pin"},{"key":"474_CR25","unstructured":"IBM - PowerPC register usage conventions (2023) https:\/\/www.ibm.com\/docs\/en\/aix\/7.2?topic=overview-register-usage-conventions"},{"key":"474_CR26","unstructured":"Islam MM, Muzahid A (2013) Characterizing real world bugs causing sequential consistency violations. In: Proceedings of the 5th USENIX Conference on Hot Topics in Parallelism. HotPar\u201913, p. 8. USENIX Association, USA"},{"key":"474_CR27","unstructured":"Isovic D, Fohler G (2000) Efficient scheduling of sporadic, aperiodic, and periodic tasks with complex constraints. In: Proceedings 21st IEEE Real-Time Systems Symposium. IEEE"},{"key":"474_CR28","unstructured":"Ispoglou K, Austin D, Mohan V, Payer M (2020) FuzzGen: Automatic fuzzer generation. In: 29th USENIX Security Symposium 20"},{"key":"474_CR29","doi-asserted-by":"crossref","unstructured":"Jeong B, Jang J, Yi H, Moon J, Kim J, Jeon I, Kim T, Shim W, Hwang YH (2023) UTopia: Automatic generation of fuzz driver using unit tests. In: 2023 IEEE Symposium on Security and Privacy (SP). IEEE","DOI":"10.1109\/SP46215.2023.10179394"},{"key":"474_CR30","unstructured":"Johnson E, Bland M, Zhu Y, Mason J, Checkoway S, Savage S, Levchenko K (2021) Jetset: Targeted firmware rehosting for embedded systems. In: 30th USENIX Security Symposium 21"},{"key":"474_CR31","unstructured":"json-parser (2022) https:\/\/github.com\/json-parser\/json-parser"},{"key":"474_CR32","doi-asserted-by":"publisher","first-page":"101627","DOI":"10.1109\/ACCESS.2021.3097807","volume":"9","author":"J Kim","year":"2021","unstructured":"Kim J, Yu J, Kim H, Rustamov F, Yun J (2021) Firm-cov: high-coverage greybox fuzzing for iot firmware via optimized process emulation. IEEE Access 9:101627\u2013101642","journal-title":"IEEE Access"},{"key":"474_CR33","doi-asserted-by":"crossref","unstructured":"Kim M, Kim D, Kim E, Kim S, Jang Y, Kim Y (2020) Firmae: Towards large-scale emulation of iot firmware for dynamic analysis. In: Proceedings of the 36th Annual Computer Security Applications Conference, pp 733\u2013745","DOI":"10.1145\/3427228.3427294"},{"key":"474_CR34","doi-asserted-by":"crossref","unstructured":"Klees G, Ruef A, Cooper B, Wei S, Hicks M (2018) Evaluating fuzz testing. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security","DOI":"10.1145\/3243734.3243804"},{"key":"474_CR35","doi-asserted-by":"crossref","unstructured":"Li W, Shi J, Li F, Lin J, Wang W, Guan L (2022) $$\\mu$$afl: non-intrusive feedback-driven fuzzing for microcontroller firmware. In: Proceedings of the 44th International Conference on Software Engineering","DOI":"10.1145\/3510003.3510208"},{"key":"474_CR36","doi-asserted-by":"crossref","unstructured":"Liu Q, Zhang C, Ma L, Jiang M, Zhou Y, Wu L, Shen W, Luo X, Liu Y, Ren K (2021) Firmguide: Boosting the capability of rehosting embedded linux kernels through model-guided kernel execution. In: 2021 36th IEEE\/ACM International Conference on Automated Software Engineering (ASE). IEEE","DOI":"10.1109\/ASE51524.2021.9678653"},{"key":"474_CR37","unstructured":"Maier D, Radtke B, Harren B (2019) Unicorefuzz: On the viability of emulation for kernelspace fuzzing. In: 13th USENIX Workshop on Offensive Technologies (WOOT 19)"},{"issue":"11","key":"474_CR38","doi-asserted-by":"publisher","first-page":"2312","DOI":"10.1109\/TSE.2019.2946563","volume":"47","author":"VJ Man\u00e8s","year":"2019","unstructured":"Man\u00e8s VJ, Han H, Han C, Cha SK, Egele M, Schwartz EJ, Woo M (2019) The art, science, and engineering of fuzzing: a survey. IEEE Trans Software Eng 47(11):2312\u20132331","journal-title":"IEEE Trans Software Eng"},{"key":"474_CR39","unstructured":"Netkachova K, M\u00fcller K, Paulitsch M, Bloomfield R (2015) Security-informed safety case approach to analysing mils systems. In: International Workshop on MILS: Architecture and Assurance for Secure Systems"},{"key":"474_CR40","unstructured":"Neugass H, Espin G, Nunoe H, Thomas R, Wilner D (1991) Vxworks: an interactive development environment and real-time kernel for gmicro. In: Eighth TRON Project Symposium. IEEE Computer Society"},{"issue":"6","key":"474_CR41","doi-asserted-by":"publisher","first-page":"5374","DOI":"10.1109\/TDSC.2024.3376129","volume":"21","author":"V Orbinato","year":"2024","unstructured":"Orbinato V, Feliciano MC, Cotroneo D, Natella R (2024) Laccolith: hypervisor-based adversary emulation with anti-detection. IEEE Trans Dependable Secure Comput 21(6):5374\u20135387","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"474_CR42","unstructured":"Owasp: ZAP (2024) https:\/\/www.zaproxy.org\/"},{"key":"474_CR43","doi-asserted-by":"crossref","unstructured":"Patrick-Evans J, Cavallaro L, Kinder J (2020) Probabilistic naming of functions in stripped binaries. In: Annual Computer Security Applications Conference","DOI":"10.1145\/3427228.3427265"},{"key":"474_CR44","doi-asserted-by":"crossref","unstructured":"Pham V-T, B\u00f6hme M, Roychoudhury A (2020) Aflnet: a greybox fuzzer for network protocols. In: 2020 IEEE 13th International Conference on Software Testing, Validation and Verification (ICST), IEEE","DOI":"10.1109\/ICST46399.2020.00062"},{"key":"474_CR45","unstructured":"Port Swigger - BurpSuite (2024) https:\/\/portswigger.net\/burp"},{"key":"474_CR46","unstructured":"QEMU AdaCore (2019) https:\/\/github.com\/AdaCore\/qemu\/blob\/qemu-stable-4.0.0\/hw\/ppc\/p2010rdb.c"},{"key":"474_CR47","unstructured":"QEMU Architectures Support (2023) https:\/\/wiki.qemu.org\/Documentation\/Platforms"},{"key":"474_CR48","unstructured":"QEMU TCG Plugins (2023) https:\/\/github.com\/qemu\/qemu\/blob\/master\/docs\/devel\/tcg-plugins.rst"},{"key":"474_CR49","unstructured":"Robert, Swiecki - Honggfuzz (2016) http:\/\/code.google.com\/p\/honggfuzz"},{"issue":"5","key":"474_CR50","doi-asserted-by":"publisher","first-page":"12","DOI":"10.1145\/1067627.806586","volume":"15","author":"JM Rushby","year":"1981","unstructured":"Rushby JM (1981) Design and verification of secure systems. ACM SIGOPS Oper Syst Rev 15(5):12\u201321","journal-title":"ACM SIGOPS Oper Syst Rev"},{"key":"474_CR51","unstructured":"Schumilo S, Aschermann C, Gawlik R, Schinzel S, Holz T (2017) kAFL: Hardware-Assisted feedback fuzzing for OS kernels. In: 26th USENIX Security Symposium (USENIX Security 17)"},{"key":"474_CR52","unstructured":"sendmail (2020) https:\/\/github.com\/mykter\/afl-training\/tree\/main\/challenges\/sendmail\/1305"},{"issue":"11","key":"474_CR53","doi-asserted-by":"publisher","first-page":"4563","DOI":"10.1109\/TCAD.2022.3198910","volume":"41","author":"Y Shen","year":"2022","unstructured":"Shen Y, Xu Y, Sun H, Liu J, Xu Z, Cui A, Shi H, Jiang Y (2022) Tardis: coverage-guided embedded operating system fuzzing. IEEE Trans Comput Aided Des Integr Circuits Syst 41(11):4563\u20134574","journal-title":"IEEE Trans Comput Aided Des Integr Circuits Syst"},{"key":"474_CR54","doi-asserted-by":"crossref","unstructured":"Srivastava P, Peng H, Li J, Okhravi H, Shrobe H, Payer M (2019) Firmfuzz: Automated IoT firmware introspection and analysis. In: Proceedings of the 2nd International ACM Workshop on Security and Privacy for the Internet-of-Things","DOI":"10.1145\/3338507.3358616"},{"key":"474_CR55","unstructured":"talos-vulndev - AFL-DynInst (2018) https:\/\/github.com\/talos-vulndev\/afl-dyninst"},{"key":"474_CR56","unstructured":"Tenda - AC15 Firmware (2024) https:\/\/www.tendacn.com\/it\/product\/download\/a15.html"},{"key":"474_CR57","unstructured":"The LLVM Compiler Infrastructure (2023) https:\/\/llvm.org\/"},{"key":"474_CR58","unstructured":"TinyExpr (2022) https:\/\/github.com\/codeplea\/tinyexpr"},{"key":"474_CR59","unstructured":"Trendnet - TEW-651BR Firmware (2024) https:\/\/www.trendnet.com\/support\/support-detail.asp?prod=190_TEW-651BR"},{"issue":"3","key":"474_CR60","doi-asserted-by":"publisher","first-page":"95","DOI":"10.1109\/LES.2018.2829777","volume":"10","author":"NG Tsoutsos","year":"2018","unstructured":"Tsoutsos NG, Maniatakos M (2018) Anatomy of memory corruption attacks and mitigations in embedded systems. IEEE Embed Syst Lett 10(3):95\u201398","journal-title":"IEEE Embed Syst Lett"},{"key":"474_CR61","unstructured":"Volatility (2016). https:\/\/www.volatilityfoundation.org\/"},{"key":"474_CR62","unstructured":"Wind River - VxWorks Workbench (2023) https:\/\/docs.windriver.com\/bundle\/Workbench_4_Getting_Started_OpenVersion_23_03\/page\/elx1502803804955.html"},{"key":"474_CR64","doi-asserted-by":"crossref","unstructured":"Yang X, Lei J, Xiong G-z (2009) Inter-partition Information Flow Control for High-Assurance Embedded Systems. In: 2009 WRI World Congress on Computer Science and Information Engineering. IEEE","DOI":"10.1109\/CSIE.2009.656"},{"issue":"7","key":"474_CR65","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3538644","volume":"55","author":"J Yun","year":"2022","unstructured":"Yun J, Rustamov F, Kim J, Shin Y (2022) Fuzzing of embedded systems: a survey. ACM Comput Surv 55(7):1\u201333","journal-title":"ACM Comput Surv"},{"key":"474_CR67","unstructured":"Zeller A, Gopinath R, B\u00f6hme M, Fraser G, Holler C (2019) The fuzzing book. CISPA+ Saarland University"},{"key":"474_CR68","unstructured":"Zheng Y, Davanian A, Yin H, Song C, Zhu H, Sun L (2019) FIRM-AFL: High-Throughput greybox fuzzing of IoT firmware via augmented process emulation. In: 28th USENIX Security Symposium (USENIX Security 19), pp. 1099\u20131114"},{"key":"474_CR69","doi-asserted-by":"crossref","unstructured":"Zheng Y, Li Y, Zhang C, Zhu H, Liu Y, Sun L (2022) Efficient greybox fuzzing of applications in Linux-based IoT devices via enhanced user-mode emulation. In: Proceedings of the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis","DOI":"10.1145\/3533767.3534414"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00474-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-025-00474-2","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00474-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T00:03:51Z","timestamp":1778457831000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-025-00474-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,11]]},"references-count":67,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["474"],"URL":"https:\/\/doi.org\/10.1186\/s42400-025-00474-2","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,11]]},"assertion":[{"value":"30 January 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 September 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 May 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Not applicable.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval and consent to participate"}},{"value":"The authors declare that they have no conflict of interest.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"66"}}