USENIX Security2023Top-tier venue
BASECOMP: A Comparative Analysis for Integrity Protection in Cellular Baseband Software
Eunsoo Kim, Minwoo Baek, CheolJun Park, Dongkwan Kim, Yongdae Kim, Insu Yun
Abstract
Baseband software is an important component in cellular communication. Unfortunately, it is almost impossible to implement baseband software correctly due to the complexity and the large volume of cellular specifications. As a result, dynamic testing has been widely used to discover implementation bugs in them. However, this approach suffers from the reachability problem, resulting in many missed bugs. Recently, BaseSpec proposed a static approach for analyzing baseband. However, BaseSpec requires heavy manual analysis and is limited to message decoding, failing to support integrity protection, the most critical step in mobile communication. In this paper, we propose a novel, semi-automated approach, BASECOMP, for analyzing integrity protection. To tame the complexity of baseband firmware, BASECOMP utilizes probabilistic inference to identify the integrity protection function. In particular, BASECOMP builds a factor graph from the firmware based on specifications and discovers the most probable function for integrity protection. Then, with additional manual analysis, BASECOMP performs symbolic analysis to validate that its behavior conforms to the specification and reports any discrepancies. We applied BASECOMP to 16 firmware images from two vendors (Samsung and MediaTek) in addition to srsRAN, an open-source 4G and 5G software radio suite. As a result, we discovered 29 bugs, including a NAS AKA bypass vulnerability in Samsung which was assigned critical severity. Moreover, BASECOMP can narrow down the number of functions to be manually analyzed to 1.56 on average. This can significantly reduce manual efforts for analysis, the primary limitation of the previous static analysis approach for baseband.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers11
- Logic Gone Astray: A Security Analysis Framework for the Control Plane Protocols of 5G BasebandsKai Tu, Abdullah Al Ishtiaq, Syed Md. Mukit Rashid, Yilu Dong et al.USENIX Security 2024 · 26 citations
- SIMurai: Slicing Through the Complexity of SIM Card Security ResearchTomasz Piotr Lisowski, Merlin Chlosta, Jinjin Wang, Marius MuenchUSENIX Security 2024 · 10 citations
- State Machine Mutation-based Testing Framework for Wireless Communication ProtocolsSyed Md. Mukit Rashid, Tianwei Wu, Kai Tu, Abdullah Al Ishtiaq et al.CCS 2024 · 4 citations
- Strong Privacy-Preserving Universally Composable AKA Protocol with Seamless Handover Support for Mobile Virtual Network OperatorRabiah Alnashwan, Yang Yang, Yilu Dong, Prosanta Gope et al.CCS 2024 · 4 citations
- BaseMirror: Automatic Reverse Engineering of Baseband Commands from Android's Radio Interface LayerWenqiang Li, Haohuang Wen, Zhiqiang LinCCS 2024 · 1 citation
Builds on15
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication SystemsAltaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan et al.NDSS 2016 · 342 citations
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 225 citations
- Breaking LTE on Layer TwoDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperS&P 2019 · 219 citations
- 5GReasoner: A Property-Directed Security and Privacy Analysis Framework for 5G Cellular Network ProtocolSyed Rafiul Hussain, Mitziu Echeverria, Imtiaz Karim, Omar Chowdhury et al.CCS 2019 · 188 citations
Related papers
- BaseSpec: Comparative Analysis of Baseband Software and Cellular Specifications for L3 ProtocolsEunsoo Kim, Dongkwan Kim, CheolJun Park, Insu Yun et al.NDSS 2021
- BaseBridge: Bridging the Gap Between Over-the-Air and Emulation Testing for Cellular Baseband FirmwareDaniel Klischies, Dyon Goos, David Hirsch, Alyssa Milburn et al.S&P 2025
- Stateful Analysis and Fuzzing of Commercial Baseband FirmwareAli Ranjbar, Tianchang Yang, Kai Tu, Saaman Khalilollahi et al.S&P 2025
- Semantic-Enhanced Static Vulnerability Detection in Baseband FirmwareYiming Liu, Cen Zhang, Feng Li, Yeting Li et al.ICSE 2024 · 4 citations
- FirmWire: Transparent Dynamic Analysis for Cellular Baseband FirmwareGrant Hernandez, Marius Muench, Dominik Christian Maier, Alyssa Milburn et al.NDSS 2022
