
in iot through app-based fuzzing. In Network and Dis-
tributed System Security Symposium.
Chesser, M., Nepal, S., and Ranasinghe, D. C. (2023). Ici-
cle: A re-designed emulator for grey-box firmware
fuzzing. In Proceedings of the 32nd ACM SIG-
SOFT International Symposium on Software Testing
and Analysis, ISSTA 2023, page 76–88, New York,
NY, USA. Association for Computing Machinery.
Connectivity Standards Alliance (2023a). Matter Applica-
tion Cluster Specification 1.2.
Connectivity Standards Alliance (2023b). Matter Core
Specification 1.2.
Costin, A., Zaddach, J., Francillon, A., and Balzarotti, D.
(2014). A Large-Scale analysis of the security of em-
bedded firmwares. In 23rd USENIX Security Sym-
posium (USENIX Security 14), pages 95–110, San
Diego, CA. USENIX Association.
Costin, A., Zarras, A., and Francillon, A. (2016). Auto-
mated dynamic firmware analysis at scale: A case
study on embedded web interfaces. In Proceedings
of the 11th ACM on Asia Conference on Computer
and Communications Security, ASIA CCS ’16, page
437–448, New York, NY, USA. Association for Com-
puting Machinery.
Daniele, C., Andarzian, S. B., and Poll, E. (2023). Fuzzers
for stateful systems: Survey and research directions.
arXiv preprint arXiv:2301.02490.
Dworkin, M. (2007). Recommendation for block cipher
modes of operation: The ccm mode for authentication
and confidentiality. Technical report, National Insti-
tute of Standards and Technology.
Eceiza, M., Flores, J. L., and Iturbe, M. (2021). Fuzzing
the internet of things: A review on the techniques and
challenges for efficient vulnerability discovery in em-
bedded systems. IEEE Internet of Things Journal,
8(13):10390–10411.
Eisele, M., Ebert, D., Huth, C., and Zeller, A. (2023).
Fuzzing embedded systems using debug interfaces. In
Proceedings of the 32nd ACM SIGSOFT International
Symposium on Software Testing and Analysis, ISSTA
2023, page 1031–1042, New York, NY, USA. Associ-
ation for Computing Machinery.
Eisele, M., Maugeri, M., Shriwas, R., Huth, C., and Bella,
G. (2022). Embedded fuzzing: a review of challenges,
tools, and solutions. Cybersecurity, 5(1):18.
Feng, X., Sun, R., Zhu, X., Xue, M., Wen, S., Liu, D.,
Nepal, S., and Xiang, Y. (2021). Snipuzz: Black-box
fuzzing of iot firmware via message snippet inference.
In Proceedings of the 2021 ACM SIGSAC Conference
on Computer and Communications Security, CCS ’21,
page 337–350, New York, NY, USA. Association for
Computing Machinery.
Kim, M., Kim, D., Kim, E., Kim, S., Jang, Y., and Kim,
Y. (2020). Firmae: Towards large-scale emulation of
iot firmware for dynamic analysis. In Annual Com-
puter Security Applications Conference, ACSAC ’20,
page 733–745, New York, NY, USA. Association for
Computing Machinery.
Ma, X., Zeng, Q., Chi, H., and Luo, L. (2023). No more
companion apps hacking but one dongle: Hub-based
blackbox fuzzing of iot firmware. In Proceedings
of the 21st Annual International Conference on Mo-
bile Systems, Applications and Services, MobiSys ’23,
page 205–218, New York, NY, USA. Association for
Computing Machinery.
Redini, N., Continella, A., Das, D., De Pasquale, G., Spahn,
N., Machiry, A., Bianchi, A., Kruegel, C., and Vigna,
G. (2021). Diane: Identifying fuzzing triggers in apps
to generate under-constrained inputs for iot devices. In
2021 IEEE Symposium on Security and Privacy (SP),
pages 484–500.
Srivastava, P., Peng, H., Li, J., Okhravi, H., Shrobe, H., and
Payer, M. (2019). Firmfuzz: Automated iot firmware
introspection and analysis. In Proceedings of the 2nd
International ACM Workshop on Security and Privacy
for the Internet-of-Things, IoT S&P’19, page 15–21,
New York, NY, USA. Association for Computing Ma-
chinery.
World Economic Forum (2022). The market for smart home
devices is expected to boom over the next 5 years.
Wright, C., Moeglein, W. A., Bagchi, S., Kulkarni, M., and
Clements, A. A. (2021). Challenges in firmware re-
hosting, emulation, and analysis. ACM Comput. Surv.,
54(1).
Xu, Z., Huang, W., Fan, W., and Cheng, Y. (2022). Fiot-
fuzzer: Response-based black-box fuzzing for iot de-
vices. In 2022 IEEE/ACIS 22nd International Con-
ference on Computer and Information Science (ICIS),
pages 239–244.
Fuzzing Matter(s): A White Paper for Fuzzing the Matter Protocol
451