FM2021Top-tier venue
Fingerprinting Bluetooth Low Energy Devices via Active Automata Learning
Andrea Pferscher, Bernhard K. Aichernig
Abstract
Active automata learning is a technique to automatically infer behavioral models of black-box systems. Today's learning algorithms enable the deduction of models that describe complex system properties, e.g., timed or stochastic behavior. Despite recent improvements in the scalability of learning algorithms, their practical applicability is still an open issue. Little work exists that actually learns models of physical black-box systems. To fill this gap in the literature, we present a case study on applying automata learning on the Bluetooth Low Energy (BLE) protocol. It shows that not the size of the system limits the applicability of automata learning. Instead, the interaction with the system under learning, is a major bottleneck that is rarely discussed. In this paper, we propose a general automata learning architecture for learning a behavioral model of the BLE protocol implemented by a physical device. With this framework, we can successfully learn the behavior of five investigated BLE devices. The learned models reveal several behavioral differences. This shows that automata learning can be used for fingerprinting black-box devices, i.e., identifying systems via their specific learned models. Based on the fingerprint, an attacker may exploit vulnerabilities specific to a device.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fa4da097-82e5-4920-9ca8-0071eba8203fCited by top-tier papers4
- It's Not a Feature, It's a Bug: Fault-Tolerant Model Mining from Noisy DataFelix Wallner, Bernhard K. Aichernig, Christian BurghardICSE 2024 · 5 citations
- State Machine Mutation-based Testing Framework for Wireless Communication ProtocolsSyed Md. Mukit Rashid, Tianwei Wu, Kai Tu, Abdullah Al Ishtiaq et al.CCS 2024 · 4 citations
- Finding SSH Strict Key Exchange Violations by State LearningFabian Bäumer, Marcel Maehren, Marcus Brinkmann, Jörg SchwenkCCS 2025 · 1 citation
- BrakTooth: Causing Havoc on Bluetooth Link Manager via Directed FuzzingMatheus E. Garbelini, Vaibhav Bedi, Sudipta Chattopadhyay, Sumei Sun et al.USENIX Security 2022
Builds on3
- SweynTooth: Unleashing Mayhem over Bluetooth Low EnergyMatheus E. Garbelini, Chundong Wang, Sudipta Chattopadhyay, Sumei Sun et al.USENIX ATC 2020 · 83 citations
- SFADiff: Automated Evasion Attacks and Fingerprinting Using Black-box Differential Automata LearningGeorge Argyros, Ioannis Stais, Suman Jana, Angelos D. Keromytis et al.CCS 2016 · 65 citations
- Analysis of DTLS Implementations Using Protocol State FuzzingPaul Fiterau-Brostean, Bengt Jonsson, Robert Merget, Joeri de Ruiter et al.USENIX Security 2020
Related papers
- BLEDiff: Scalable and Property-Agnostic Noncompliance Checking for BLE ImplementationsImtiaz Karim, Abdullah Al Ishtiaq, Syed Rafiul Hussain, Elisa BertinoS&P 2023
- Evaluating Physical-Layer BLE Location Tracking Attacks on Mobile DevicesHadi Givehchian, Nishant Bhaskar, Eliana Rodriguez Herrera, Héctor Rodrigo López Soto et al.S&P 2022 · 55 citations
- Protecting Privacy of BLE Device UsersKassem Fawaz, Kyu-Han Kim, Kang G. ShinUSENIX Security 2016 · 111 citations
- Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile AppsChaoshun Zuo, Haohuang Wen, Zhiqiang Lin, Yinqian ZhangCCS 2019 · 77 citations
- State Matching and Multiple References in Adaptive Active Automata LearningLoes Kruger, Sebastian Junges, Jurriaan RotFM 2024 · 3 citations
