Netinfo Security ›› 2026, Vol. 26 ›› Issue (7): 1087-1100.doi: 10.3969/j.issn.1671-1122.2026.07.007
Previous Articles Next Articles
Yao Wuhuang, Wang Jiapeng, Chen Kangbing, Zheng Zhihan, Tan Yu’an(
)
Received:2026-04-29
Online:2026-07-10
Published:2026-09-03
Contact:
Tan Yu’an
E-mail:tan2008@bit.edu.cn
CLC Number:
Yao Wuhuang, Wang Jiapeng, Chen Kangbing, Zheng Zhihan, Tan Yu’an. An LLM-assisted firmware memory leak analysis based on instruction translation instrumentation[J]. Netinfo Security, 2026, 26(7): 1087-1100.
Add to citation manager EndNote|Ris|BibTeX
URL: http://netinfo-security.org/EN/10.3969/j.issn.1671-1122.2026.07.007
| 指令/类别 | 改变PC行为 | 状态变化 | 说明 |
|---|---|---|---|
| ADD(Thumb T2), MOV(Thumb T) | 半字节对齐跳转 | 不变 | 忽略最低位, 跳转到对齐地址 |
| B,BL,CBNZ,CBZ | 指定地址跳转 | 不变 | 指令定义保证 对齐 |
| BLX(立即数) | 跳转到立即数 地址 | 切换ARM/Thumb状态 | 地址对齐由指令保证 |
| BLX(寄存器),BX,BXJ | 跳转到寄存器值 | 根据最低位 切换 | LSB=1切Thumb LSB=0切ARM32 |
| LDR(目标寄存器为PC) | 跳转到内存中 取出的地址 | 根据最低位 切换 | 常用于函数返回 |
| POP/LDM(含PC) | 跳转到栈或寄存器列表中的地址 | 根据最低位 切换 | 常见于函数返回 |
| ADD, MOV,ADR等ARM 数据处理指令(Rd=PC,无 S位) | 跳转到计算结果 | 不变 | 仅在ARM32状态下生效 |
| 组件 | 配置 |
|---|---|
| 宿主机操作系统 | Ubuntu 24.04.1 LTS (64-bit) |
| QEMU版本 | 5.2.0 |
| 交叉编译工具链 | gcc-linaro-4.9-2016.02-x86_64_arm-linux-gnueabi |
| AFL++版本 | 4.32 |
| QASan版本 | AFL++内置QASan(自定义修改) |
| IDA pro版本 | 7.5.201028 Windows x64 (32-bit address size) |
| 宿主机CPU | Intel 11th Gen Core i5-11400 |
| 宿主机内存 | 24 GB DDR3 |
| 宿主机磁盘 | 512 GB NVMe SSD |
| 目标平台架构 | ARMv7(ARM32) |
| 方法 | 目标缺陷 | 核心机制 | 检测能力/性能特征 | 与本文关系 |
|---|---|---|---|---|
| ASan | OOB/UAF | 编译期红区+影子内存 | 运行开销较低,但依赖源码与符号信息 | 源码级基线,难直接应用于闭源固件 |
| QASan | 堆OOB/UAF | QEMU TCG插桩+影子内存/红区 | 无需改写二进制,但主要面向堆内存错误,调用上下文恢复能力有限 | 本文方法所依赖的底层运行时环境 |
| DFirmSan | Silent-MC/内存破坏 | 敏感函数预分析+DBC +不可信 数据跟踪 | 在18个真实固件中协助发现117个 已知CVE,额外开销2.69%~16.43%,误报率低于0.35% | 代表“选择性监控降开销”路线,但不面向泄漏 |
| QMSan | UUM | 机会主义多层检测+按需 精确复检 | 发现44个新的UUM错误;其运行开销为QEMU的1.51倍;实验过程中未观察到误报或漏报 | 代表“多层验证降开销”路线,但不关注泄漏生命周期 |
| 本文方法 | 内存泄漏 | ARM-FRA+LD_PRELOAD生命周期跟踪+CoT根因 研判 | Juliet准确率92.16%;在7种真实BMC固件中发现5个真实漏洞;额外物理内存开销约5.7 MB | — |
| [1] | 梁晓兵, 孔令达, 刘岩, 等. 轻量级嵌入式软件动态二进制插桩算法[J]. 信息网络安全, 2021, 21(4): 89-95. |
| [2] | Yang Shanquan, Gao Yansong, Kuang B, et al. DFirmSan: a lightweight dynamic memory sanitizer for linux-based firmware[J]. Computers & Security, 2025, 155: Article 104467. |
| [3] | Seward J, Nethercote N. Using valgrind to detect undefined value errors with bit-precision[C]// 2005 USENIX Annual Technical Conference. Berkeley: USENIX, 2005: 17-30. |
| [4] | 汪小林, 王振林, 孙逸峰, 等. 利用虚拟化平台进行内存泄露探测[J]. 计算机学报, 2010, 33(3): 463-472. |
| [5] | 梅傲寒, 谭毓安, 常振轩, 等. 一种面向开源BMC固件的内生模糊测试框架[J]. 信息安全研究, 2025, 11(7): 611-618. |
| [6] | 常振轩, 郑之涵, 梅傲寒, 等. 一种面向固件网络应用的高效灰盒模糊测试方法[J]. 信息网络安全, 2025, 25(4): 654-663. |
| [7] | Song D, Lettner J, Rajasekaran P, et al. SOK: sanitizing for security[C]// 2019 Symposium on Security and Privacy. New York: IEEE, 2019: 1275-1295. |
| [8] | Bellard F. QEMU, a fast and portable dynamic translator[C]// 2005 USENIX Annual Technical Conference. Berkeley: USENIX, 2005: 41-46. |
| [9] | Marini M, D’elia D C, Payer M, et al. QMSan: efficiently detecting uninitialized memory errors during fuzzing[C]// 2025 Network and Distributed System Security Symposium. San Diego: Internet Society, 2025: 1-17 |
| [10] | Asmita, Oliinyk Y, Scott M, et al. Fuzzing busybox: leveraging LLM and crash reuse for embedded bug unearthing[C]// The 33rd USENIX Security Symposium. Berkeley: USENIX, 2024: 883-900. |
| [11] | 计江安, 井靖, 王奕森, 等. 嵌入式固件模糊测试研究综述[J]. 小型微型计算机系统, 2024, 45(5): 1173-1180. |
| [12] | 孙琪明, 侯刚, 靳文杰, 等. 嵌入式软件模糊测试研究综述[J]. 计算机科学, 2025, 52(7): 13-25. |
| [13] | 王琴应, 许嘉诚, 李宇薇, 等. 智能模糊测试综述:问题探索和方法分类[J]. 计算机学报, 2024, 47(9): 2059-2083. |
| [14] | 李岩, 杨文章, 张翼, 等. 基于大语言模型的模糊测试研究综述[J]. 软件学报, 2025, 36(6): 2404-2431. |
| [15] |
习宁, 周晓琳, 孙聪, 等. 支持物理交互的无人机飞控系统安全测试方法[J]. 电子学报, 2025, 53(3): 765-781.
doi: 10.12263/DZXB.20240890 |
| [16] | Bond M D, Mckinley K S. Tolerating memory leaks[C]// The 23rd ACM SIGPLAN Conference on Object-Oriented Programming Systems Languages and Applications. New York: ACM, 2008: 109-126. |
| [17] | Qin Feng, Lu Shan, Zhou Yuanyuan. SafeMem: exploiting ECC-memory for detecting memory leaks and memory corruption during production runs[C]// The 11th International Symposium on High-Performance Computer Architecture. New York: IEEE, 2005: 291-302. |
| [18] | Serebryany K, Bruening D, Potapenko A, et al. AddressSanitizer: a fast address sanity checker[C]// 2012 USENIX Annual Technical Conference. Berkeley: USENIX Association, 2012: 309-318. |
| [19] | Fioraldi A, D’elia D C, Querzoni L. Fuzzing binaries for memory safety errors with qasan[C]// 2020 IEEE Secure Development. New York: IEEE, 2020: 23-30. |
| [20] | Wei J, Wang Xuezhi, Schuumans D, et al. Chain-of-thought prompting elicits reasoning in large language models[C]// Advances in Neural Information Processing Systems 35 (2022). New York: Curran Associates, 2022: 24824-24837. |
| [21] | ARM. ARM architecture reference manual for a-profile architecture[EB/OL]. (2024-11-30)[2026-04-03]. https://developer.arm.com/documentation/ddi0487/la/?lang=en. |
| [1] | Yang Qiaoyang, Fan Ximing, Jia Peng. LLM-based semantic-aware fuzz driver generation [J]. Netinfo Security, 2026, 26(7): 1128-1148. |
| [2] | SUN Yu, ZHANG Xuanrui, LIU Xinyu. Advances in Advanced Persistent Threat Detection and Provenance Research [J]. Netinfo Security, 2026, 26(6): 833-853. |
| [3] | MIAO Bo, YUAN Deyu, ZHANG Teng, YANG Yi, HUANG Zan. Chain-of-Thought Poisoning Based Retrieval-Augmented Generation Backdoor Attack [J]. Netinfo Security, 2026, 26(6): 977-998. |
| [4] | CUI Jinhua, DONG Liang, YANG Xin. A Survey of Privacy-Preserving Techniques for Large Language Model Inference [J]. Netinfo Security, 2026, 26(4): 503-520. |
| [5] | LI Yan, YANG Wenzhang, XUE Yinxing. Cross-Language Compiler Fuzzing Based on LLM Translation and Differential Testing [J]. Netinfo Security, 2026, 26(4): 591-604. |
| [6] | HU Mianning, LI Xin, LI Mingfeng, YUAN Deyu. Research on Multi-Strategy Enhanced Chinese Network Threat Intelligence Entity Extraction Based on Large Language Model [J]. Netinfo Security, 2026, 26(4): 615-625. |
| [7] | YUAN Ming, ZOU Qilin, YUAN Wenqi, WANG Qun. A Survey on Prompt Injection Attacks and Defenses in Large Language Models [J]. Netinfo Security, 2026, 26(3): 341-354. |
| [8] | GU Zhaojun, LI Li, SUI He. A Payload Generation Method for SQL Injection Vulnerability Detection Based on Large Language Models [J]. Netinfo Security, 2026, 26(2): 274-290. |
| [9] | ZHANG Guanghua, LI Guoyu, WANG He, LI Heng, WU Shaoguang. High-Confidence Vulnerability Detection in IoT Firmware Based on Taint Flow Analysis [J]. Netinfo Security, 2026, 26(2): 325-337. |
| [10] | TONG Xin, JIAO Qiang, WANG Jingya, YUAN Deyu, JIN Bo. A Survey on the Trustworthiness of Large Language Models in the Public Security Domain: Risks, Countermeasures, and Challenges [J]. Netinfo Security, 2026, 26(1): 24-37. |
| [11] | HU Yucui, GAO Haotian, ZHANG Jie, YU Hang, YANG Bin, FAN Xuejian. Automated Exploitation of Vulnerabilities in Vehicle Network Security [J]. Netinfo Security, 2025, 25(9): 1348-1356. |
| [12] | LIU Hui, ZHU Zhengdao, WANG Songhe, WU Yongcheng, HUANG Linquan. Jailbreak Detection for Large Language Model Based on Deep Semantic Mining [J]. Netinfo Security, 2025, 25(9): 1377-1384. |
| [13] | WANG Lei, CHEN Jiongyi, WANG Jian, FENG Yuan. Intelligent Reverse Analysis Method of Firmware Program Interaction Relationships Based on Taint Analysis and Textual Semantics [J]. Netinfo Security, 2025, 25(9): 1385-1396. |
| [14] | ZHANG Yanyi, RUAN Shuhua, ZHENG Tao. Research on REST API Design Security Testing [J]. Netinfo Security, 2025, 25(8): 1313-1325. |
| [15] | CHEN Ping, LUO Mingyu. Research on Large Model Analysis Methods for Kernel Race Vulnerabilities in Cloud-Edge-Device Scenarios [J]. Netinfo Security, 2025, 25(7): 1007-1020. |
| Viewed | ||||||
|
Full text |
|
|||||
|
Abstract |
|
|||||