AI 中文总结
针对现有固件重宿主技术无法可靠建模外设语义的问题,提出反应式外设建模RPM并实现于Bluezz,在18个BLE固件目标上平均基本块覆盖率达现有方法2.6倍以上,发现5个连接后才显现的新漏洞,且RPM可推广至其他嵌入式固件。
AI 中文摘要
重宿主技术可实现对固件的紧密控制与内省,用于固件测试,但现有方法大多无法触及更深层的应用状态,也无法驱动嵌入式协议栈超越早期初始化阶段。这一局限反映了当前重宿主技术的一个更广泛弱点:它们无法可靠地对复杂的外设语义与依赖关系进行建模。具体而言,现有工作通常依赖对外设行为的被动近似,且忽略了三个关键方面:(i)中断、MMIO(内存映射I/O)与DMA(直接内存访问)之间的相互作用;(ii)外设内部的隐式状态转换;(iii)多个外设之间的交互。为应对这一挑战,我们提出了反应式外设建模(Reactive Peripheral Modeling,RPM),这一抽象将硬件外设建模为反应式且有状态的系统。RPM通过事件-条件-动作语义来捕捉外设行为,能够可靠地表示中断、MMIO与DMA调度、隐式状态转换以及跨外设交互。我们在Bluezz中实现了RPM,用于BLE(蓝牙低功耗)固件的重宿主与模糊测试,并表明反应式建模对于触及深层协议状态是必要的。我们在代表性的BLE栈上评估了Bluezz,包括NimBLE、Zephyr以及闭源商业栈Nordic SoftDevice。在18个目标上,Bluezz实现的平均基本块覆盖率是现有最先进重宿主方法的2.6倍以上。与大多局限于广播和扫描逻辑的现有方法不同,Bluezz可可靠地驱动已连接的BLE状态,并发现了5个仅在连接建立后才显现的此前未知漏洞。最后,我们表明RPM不仅适用于BLE,还可推广到运行在不同MCU(微控制器单元)上的其他嵌入式固件。
英文摘要
Rehosting enables tight control and introspection for firmware testing, but existing approaches largely fail to reach deeper application states and cannot drive embedded protocol stacks beyond early-stage initialization. This limitation reflects a broader weakness in current rehosting techniques: their inability to faithfully model complex peripheral semantics and dependencies. In particular, existing work typically relies on passive approximations of peripheral behavior and overlooks three key aspects: (i) the interplay among interrupts, MMIO, and DMA; (ii) implicit state transitions within peripherals; and (iii) interactions across multiple peripherals. To address this challenge, we propose Reactive Peripheral Modeling (RPM), an abstraction that models hardware peripherals as reactive and stateful systems. RPM captures peripheral behavior using event-condition-action semantics, enabling faithful representation of interrupt, MMIO, and DMA scheduling, implicit state transitions, and cross-peripheral interactions. We implement RPM in Bluezz for BLE firmware rehosting and fuzzing, and show that reactive modeling is necessary to reach deep protocol states. We evaluate Bluezz on representative BLE stacks, including NimBLE, Zephyr, and Nordic SoftDevice, a closed-source commercial stack. Across 18 targets, Bluezz achieves an average basic-block coverage more than 2.6 times that of prior state-of-the-art rehosting approaches. Unlike prior approaches, which remain largely confined to advertising and scanning logic, Bluezz reliably exercises connected BLE states and uncovers five previously unknown vulnerabilities that manifest only after connection establishment. Finally, we show that RPM generalizes beyond BLE to other embedded firmware running on different MCUs.
CommentsAn earlier version of this work was submitted to IEEE S&P 2025 and ACM CCS 2026