|
pp. 4027-4048
S&M4548 Report https://doi.org/10.18494/SAM5910 Published: July 27, 2026 Improvement for Embedded Firmware Emulation Applying FirmAE [PDF] Jong-Yih Kuo, Yu-Quan Wang, Ti-Feng Hsieh, and Chen-Hsuan Kuo (Received August 21, 2025; Accepted July 10, 2026) Keywords: dynamic analysis, embedded device, emulation, firmware
Firmware emulation is a key technique for enabling large-scale security analysis of IoT devices and sensing systems without requiring physical hardware. However, existing emulation frameworks often suffer from instability and low success rates owing to mismatches between real device execution environments and virtualized systems, particularly across heterogeneous firmware with different initialization and runtime dependencies. In this study, we investigate failure behaviors in FirmAE, a widely used IoT firmware emulation framework, and identify recurring issues in Boot, Kernel, Network, and nonvolatile random access memory (NVRAM) execution stages. On the basis of this analysis, we propose a set of rule-based improvement strategies that refine boot configurations, Quick Emulator (QEMU) execution parameters, network settings, and NVRAM handling mechanisms to improve emulation stability across diverse firmware types. The main limitation of existing approaches is their reliance on heuristic and incomplete device-specific handling, which reduces robustness when applied to unseen firmware. The proposed method addresses this issue by systematizing failure patterns into actionable repair rules, enabling more consistent emulation behavior. Although the proposed method improves emulation robustness, one limitation of this study is that part of the proposed repair process still depends on manual inspection of firmware logs and runtime behavior, which may limit scalability in fully automated large-scale deployment scenarios. Experimental results on real-world firmware images collected from multiple vendors and architectures demonstrate that the proposed approach improves emulation robustness and enhances the ability to successfully execute previously failing firmware instances, supporting more reliable IoT firmware security analysis.
Corresponding author: Jong-Yih Kuo![]() ![]() This work is licensed under a Creative Commons Attribution 4.0 International License. Cite this article Jong-Yih Kuo, Yu-Quan Wang, Ti-Feng Hsieh, and Chen-Hsuan Kuo, Improvement for Embedded Firmware Emulation Applying FirmAE, Sens. Mater., Vol. 38, No. 7, 2026, p. 4027-4048. |