4 papers · 1 filter
Reactive Peripheral Modeling for Faithful Firmware Rehosting
Qinying Wang, Florian Hofhammer, Eduard Vlad +4
Rehosting enables tight control and introspection for firmware testing, but existing approaches largely fail to reach deeper application states and cannot drive embedded protocol s…
"Operator, can you hear me?" A Faithful Line into the UNISOC Baseband
Eduard Vlad, Philipp Mao, Marcel Busch +2
Baseband processors are reachable over the radio at all times. Their most security-relevant logic runs deep inside protocol state machines: the control-plane handlers that gate reg…
TÄMU: Emulating Trusted Applications at the (GlobalPlatform)-API Layer
Philipp Mao, Li Shi, Marcel Busch +1
Mobile devices rely on Trusted Execution Environments (TEEs) to execute security-critical code and protect sensitive assets. This security-critical code is modularized in component…
EmbedFuzz: High Speed Fuzzing Through Transplantation
Florian Hofhammer, Qinying Wang, Atri Bhattacharyya +5
Dynamic analysis and especially fuzzing are challenging tasks for embedded firmware running on modern low-end Microcontroller Units (MCUs) due to performance overheads from instruc…