A survey of extraction and emulation fidelity in Linux-based firmware rehosting
lin li, zhe han, Li Chen · 2025
As the explosive growth of IoT devices, effective analysis of their firmware has become an increasingly challenge. One of the key obstacles in analyzing embedded device firmware lies in the process of firmware rehosting—specifically, the suitable extraction and emulation of firmware for further analysis. In this paper, we focus on two critical aspects of Linux-based firmware rehosting: extraction fidelity and emulation fidelity. While significant advancements have been made in improving execution fidelity, existing rehosting techniques often overlook the importance of maintaining high extraction and emulation fidelity, both of which are crucial for accurately recreating the behavior of firmware services. In this paper, we propose novel strategies that improves extraction fidelity, building upon existing improvements to the FirmAE. Our evaluation, conducted on a dataset of 913 firmware images collected from three famous vendors and 28 real devices, shows that although both extraction and emulation fidelity are important, emulation fidelity poses greater challenges, particularly in peripheral access and NVRAM configuration. These findings provide valuable insights into the limitations and opportunities for advancing Linux-based firmware rehosting techniques, with implications for both security analysis and vulnerability detection in IoT devices.