Emulation-Based Fuzzing of Encrypted Firmware

Zhiyu Xu, Yong Ding, Liwei Tian, Suping Liu · Electronics · 2025

Internet of Things (IoT) devices are frequent targets of cyber attacks, and firmware emulation is essential for enabling automated techniques like fuzzing to uncover vulnerabilities. However, the growing use of encryption in firmware poses significant challenges for building accurate emulated environments. To overcome this, we present EncryptAFL, the first IoT fuzzer specifically tailored for devices with encrypted firmware. In contrast to existing methods that primarily focus on peripheral emulation, EncryptAFL places greater emphasis on automating the decryption process. We evaluate EncryptAFL using real-world firmware and known vulnerabilities, demonstrating its effectiveness in both emulation and vulnerability detection.

Read the paper · More papers on PaperTik