Stateful Analysis and Fuzzing of Commercial Baseband Firmware
Ali Ranjbar, Tianchang Yang, Kai Tu, Saaman Khalilollahi, Syed Rafiul Hussain
摘要
Baseband firmware plays a critical role in cellular communication, yet its proprietary, closed-source nature and complex, stateful processing logic make systematic security testing challenging. Existing methods often fail to account for the interdependencies between baseband tasks and the statefulness of input processing logic, limiting their scope and effectiveness. We present Loris, a stateful fuzz testing frame-work designed to explore and analyze baseband firmware implementations effectively. We employ iterative symbolic analysis to progressively identify state variables and the predicates over them that define different protocol states, while alleviating the state explosion problem. It enables Loris to perform targeted exploration and fuzzing of program regions with high potential for vulnerabilities. We evaluated Loris across 5 commercial devices from two major vendors, covering both 4G Long-Term Evolution (LTE) and 5G New Radio (NR), demonstrating its broad applicability. Our testing revealed 7 new vulnerabilities exploitable by over-the-air attackers, potentially leading to baseband crashes, remote code execution, and denial of service.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper20
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 被引用 428 次
- NAUTILUS: Fishing for Deep Bugs with GrammarsCornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig 等NDSS 2019 · 被引用 291 次
- Breaking LTE on Layer TwoDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperS&P 2019 · 被引用 219 次
- Touching the Untouchables: Dynamic Security Analysis of the LTE Control PlaneHongil Kim, Jiho Lee, Eunkyu Lee, Yongdae KimS&P 2019 · 被引用 174 次
相关 Paper
- CoreCrisis: Threat-Guided and Context-Aware Iterative Learning and Fuzzing of 5G Core NetworksYilu Dong, Tianchang Yang, Abdullah Al Ishtiaq, Syed Md. Mukit Rashid 等USENIX Security 2025
- RANsacked: A Domain-Informed Approach for Fuzzing LTE and 5G RAN-Core InterfacesNathaniel Bennett, Weidong Zhu, Benjamin Simon, Ryon Kennedy 等CCS 2024 · 被引用 9 次
- 5GC-Fuzz: Finding Deep Stateful Vulnerabilities in 5G Core Network with Black-Box FuzzingYu Sun, Xinyu Liu, Qian Sun, Jiaming Wang 等INFOCOM 2025 · 被引用 5 次
- BaseBridge: Bridging the Gap Between Over-the-Air and Emulation Testing for Cellular Baseband FirmwareDaniel Klischies, Dyon Goos, David Hirsch, Alyssa Milburn 等S&P 2025
- BASECOMP: A Comparative Analysis for Integrity Protection in Cellular Baseband SoftwareEunsoo Kim, Minwoo Baek, CheolJun Park, Dongkwan Kim 等USENIX Security 2023
