| [1] Microsoft. Security Signals[EB/OL]. 2021[2025-07-25]. https://www.microsoft.com/content/dam/microsoft/final/en-us/microsoft-brand/documents/MSFT-Security-Signals-Thought-Paper-V032421.pdf.
[2] Amnpardaz. The first rootkit discovered infecting HP iLO firmware[EB/OL]. 2021[2025-07-25]. https://threats.amnpardaz.com/en/wp-content/uploads/sites/5/2021/12/Implant.ARM_.iLOBleed.a-en.pdf.
[3] 姚倩,周慧英,东红林. 固件检测方法、装置、设备及存储介质:中国,CN115544515A [P]. 2022-12-30.
[4] Shoshitaishvili Y, Wang R, Hauser C, et al. Firmalice-automatic detection of authentication bypass vulnerabilities in binary firmware[EB/OL]. 2015[2025-07-25]. https://researchr.org/publication/Shoshitaishvili15/related.
[5] Miller B P, Fredriksen L, So B. An empirical study of the reliability of UNIX utilities[J]. Communications of the ACM, 1990, 33(12): 32-44.
[6] Zaddach J, Bruno L, Francillon A, et al. Avatar: A framework to support dynamic security analysis of embedded systems’ firmwares[EB/OL]. 2014[2025-07-25]. https://dev.ndss-symposium.org/wp-content/uploads/2017/09/02_3_slides.pdf.
[7] Chen D D, Woo M, Brumley D, et al. Towards automated dynamic analysis for linux-based embedded firmware[EB/OL]. 2016[2025-07-25]. https://github.com/firmadyne/firmadyne/blob/master/paper/paper.pdf.
[8] 戴昊,姜博文,尚思佳,等. 工控系统勒索软件研究综述[J]. 网络空间安全科学学报,2024, 2(5):17-31.
[9] Chen J, Diao W, Zhao Q, et al. IoTFuzzer: Discovering memory corruptions in IoT through App-based fuzzing[EB/OL]. 2018[2025-07-25]. https://zzm7000.github.io/teaching/2021springcse703/papers/ndss18-chen.pdf.
[10] 梅傲寒,谭毓安,常振轩,等. 一种面向开源BMC固件的内生模糊测试框架[J]. 信息安全研究,2025,11(7):611-618.
[11] Fioraldi A, Maier D, Zhang D, et al. LibAFL: A framework to build modular and reusable fuzzers[EB/OL]. 2022[2025-07-25]. https://dl.acm.org/doi/10.1145/3548606.3560602.
[12] Bellard F. QEMU, a fast and portable dynamic translator[EB/OL]. 2005[2025-07-25]. https://www.usenix.org/legacy/events/usenix05/tech/freenix/bellard.html.
[13] Zalewski M. Technical ”whitepaper” for afl-fuzz[EB/OL]. 2015[2025-08-05]. https://lcamtuf.coredump.cx/afl/technical_details.txt.
[14] Zhang G, Wang P, Yue T, et al. Mobfuzz: Adaptive multi-objective optimization in gray-box fuzzing[EB/OL]. 2022[2025-08-05]. https://www.ndss-symposium.org/ndss-paper/auto-draft-199/.
[15] Sharma S, Tanksalkar S R, Cherupattamoolayil S, et al. Fuzzing API error handling behaviors using coverage guided fault injection[EB/OL]. 2024[2025-08-30]. https://dl.acm.org/doi/10.1145/3634737.3637650.
[16] Askar A, Fleischer F, Kruegel C, et al. MALintent: Coverage guided intent fuzzing framework for Android[EB/OL]. 2025[2025-08-30]. https://www.ndss-symposium.org/ndss-paper/malintent-coverage-guided-intent-Fuzzing-framework-for-android/.
[17] Zalewski M. Fuzzing random programs without execve()[EB/OL]. 2014[2025-08-30]. https://lcamtuf.blogspot.com/2014/10/fuzzing-binaries-without-execve.html.
[18] Fioraldi A, Maier D, Ei?feldt H, et al. AFL++: Combining incremental steps of fuzzing research[EB/OL]. 2020[2025-08-30]. https://dlnext.acm.org/doi/abs/10.5555/3488877.3488887.
[19] Malmain R, Fioraldi A, Francillon A. LibAFL QEMU: A Library for Fuzzing-oriented Emulation[EB/OL]. 2024[2025-08-30]. https://www.eurecom.fr/en/publication/7610/copyright.
[20] Agency N S. Ghidra[EB/OL]. 2025[2025-08-30]. https://ghidra-sre.org/.
[21] Wu M,Jiang L, Xiang J, et al. One fuzzing strategy to rule them all[EB/OL]. 2022[2025-08-30]. https://ieeexplore.ieee.org/document/9794101.
[22] Google. OSS-Fuzz[EB/OL]. 2016[2025-09-01]. https://google.github.io/oss-fuzz/.. |