Accelerating firmware vulnerability detection through directed reaching definition analysis
Kai Chen, Yufei Zhao, Jing Ming Guo, Zhimin Gu, Longxi Han · ICT Express · 2025
The Internet of Things (IoT) has transformed industries like smart grids and homes. However, firmware security is a growing concern due to vulnerabilities like command execution and buffer overflows. To address this, we propose ReachDFuzz, a directed fuzzing method using reaching-definition analysis. It targets risky library functions affected by external inputs and integrates static analysis for path pruning. Experiments show that ReachDFuzz outperforms FirmAFL in reducing invalid paths and detecting firmware vulnerabilities.