Skip to content

QEMU Setup

QEMU Setup for IoT Emulation

QEMU (Quick Emulator) is a versatile tool for emulating hardware platforms, enabling firmware analysis, debugging, and testing of IoT devices without physical hardware. By replicating the target hardware environment, analysts can study firmware behavior, reverse-engineer binaries, and test security vulnerabilities in a controlled setting. This section covers configuring QEMU for IoT-specific use cases, including ARM-based embedded systems, RISC-V, MIPS, and peripheral emulation.


1. Installing QEMU

Install QEMU with support for ARM, RISC-V, MIPS, and other embedded architectures. On Linux, use your package manager:

# Debian/Ubuntu
sudo apt install qemu-system-arm qemu-system-riscv32 qemu-system-mips qemu-user-static

# macOS (via Homebrew)
brew install qemu

For Windows, use the official QEMU binaries or WSL2. No KVM-specific commands are required for Windows, as KVM is a Linux kernel feature.


2. Emulating IoT Hardware Platforms

QEMU supports a wide range of IoT-compatible targets, including ARM-based boards (e.g., Raspberry Pi, BeagleBone), RISC-V, and MIPS. Use the -machine flag to specify the board model and -cpu to define the processor architecture.

Example: Emulate a Raspberry Pi 3 (ARMv7)

qemu-system-arm -machine raspi3 -cpu cortex-a53 -kernel firmware.bin

Example: Emulate an STM32-based MCU (ARMv6)

# Verify available STM32 machine types with: qemu-system-arm -machine help
# Note: STM32-specific machine types may require custom definitions; use a generic ARM model as an alternative
qemu-system-arm -machine versatileab -cpu cortex-m4 -kernel firmware.bin

Example: Emulate RISC-V (commonly used in IoT)

qemu-system-riscv32 -machine virt -cpu rv32 -kernel firmware.bin

Example: Emulate MIPS (used in legacy IoT devices)

qemu-system-mips -machine malta -cpu 4KEc -kernel firmware.bin

For non-ARM targets (e.g., x86-based IoT devices), use qemu-system-x86_64 and adjust the -machine parameter accordingly. Example for x86-based IoT emulation:

qemu-system-x86_64 -machine q35 -cpu Core2duo -kernel firmware.bin

3. Networking and Serial Console Setup

IoT firmware often relies on network protocols (MQTT, CoAP) or serial communication. Configure QEMU to enable networking and serial console access:

Example: Networking with TAP Interface

sudo apt install uml-utilities
sudo tunctl -u $USER -t tap0
sudo ifconfig tap0 up
qemu-system-arm -net nic,model=virtio -net tap,ifname=tap0 -kernel firmware.bin

Example: Serial Console Access

qemu-system-arm -serial mon:stdio -kernel firmware.bin

This allows direct interaction with the emulated device's serial output.


4. Troubleshooting Common Issues

  • Missing Firmware Image: Ensure the firmware file is compatible with the target architecture (e.g., ARMEL vs. ARM64).
  • Incorrect Hardware Model: Verify the -machine parameter matches the target device's specifications. Use qemu-system-arm -machine help for available models.
  • Performance Bottlenecks: Disable KVM acceleration if the host CPU lacks virtualization support or if the guest OS is not compatible.

For debug output, add -d in_asm,cpu to trace execution:

qemu-system-arm -d in_asm,cpu -kernel firmware.bin

Key takeaways

  • Install QEMU with ARM/RISC-V/MIPS support and enable KVM acceleration for performance (Linux only).
  • Use -machine and -cpu flags to emulate specific IoT hardware platforms.
  • Configure networking (TAP interfaces) and serial consoles for protocol analysis.
  • Validate firmware compatibility and debug with QEMU's trace capabilities.