Automation of Firmware Analysis and Government Standard Reporting

This workshop introduces an early-stage web-based firmware analysis tool designed to make firmware security assessment more accessible to students, researchers, and security practitioners. Many organisations do not routinely include firmware analysis in their security workflows, even though firmware may contain insecure services, exposed credentials, weak configuration, unsafe permissions, or other security-relevant artefacts. The tool allows users to upload a firmware image and receive structured findings generated through automated static analysis, including extraction results, suspicious network indicators, authentication artefacts, permission issues, and transport security indicators.

The workshop will demonstrate how low-level firmware evidence can be converted into clearer security findings, including severity information, contextual explanations, and NIST-aligned reporting to support governance and remediation discussions. Participants will be guided through example firmware analysis outputs and invited to critique the clarity, usefulness, and accuracy of the results. The session is intended to be practical and discussion-based, focusing on improving the tool’s usability, reporting structure, and relevance to real firmware security workflows. Feedback gathered during the workshop will inform the next stage of development and evaluation.


Attendees will see a live demonstration of the firmware analysis prototype, including security findings and severity ratings mapped to relevant NIST framework categories. The session will offer examples and discussions on the tool's usefulness, accuracy, and actionability. Participants do not need any prior knowledge of firmware reverse engineering, though a basic understanding of cybersecurity would aid in interpreting the tools' outputs. Feedback from both technical and non-technical attendees will inform future improvements to the prototype, including its interface, reporting structure, and relevance to practical firmware security workflows.

The speaker's profile picture
Paul Underhill

Paul Underhill is an IT professional and Senior Lecturer at the University of Chester. His research interests include cybersecurity, firmware and digital forensics. He is currently completing a PhD focused on automation of firmware analysis and NIST-aligned reporting to support clearer identification, prioritisation, and understanding of firmware security issues.