BrakTooth: Causing Havoc on Bluetooth Link Manager via Directed Fuzzing
Matheus E. Garbelini, Vaibhav Bedi, Sudipta Chattopadhyay, Sumei Sun, Ernest Kurniawan
摘要
In this paper we propose, design and evaluate a systematic directed fuzzing framework to automatically discover implementation bugs in arbitrary Bluetooth Classic (BT) devices. The core of our fuzzer is the first over-the-air approach that takes full control of the BT controller baseband from the host. This enables us to intercept and modify arbitrary packets, as well as to inject packets out-of-order in lower layers of closed-source BT stack, i.e., Link Manager Protocol (LMP) and Baseband. To systematically guide our fuzzing process, we propose an extensible and novel rule-based approach to automatically construct the protocol state machine during normal over-the-air communication. In particular, by writing a simple set of rules to identify protocol messages, we can dynamically construct an abstracted protocol state machine, fuzz packets resulting from a state and validate responses from target devices. As of today, we have fuzzed 13 BT devices from 11 vendors and we have discovered a total of 18 unknown implementation flaws, with 24 common vulnerability exposures (CVEs) assigned. Furthermore, our discoveries were awarded with six bug bounties from certain vendors. Finally, to show the broader applicability of our framework beyond BT, we have extended our approach to fuzz other wireless protocols, which additionally revealed 6 unknown bugs in certain Wi-Fi and BLE Host stacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper18
- From One Thousand Pages of Specification to Unveiling Hidden Bugs: Large Language Model Assisted Fuzzing of Matter IoT DevicesXiaoyue Ma, Lannan Luo, Qiang ZengUSENIX Security 2024 · 被引用 49 次
- SoK: The Long Journey of Exploiting and Defending the Legacy of King Harald BluetoothJianliang Wu, Ruoyu Wu, Dongyan Xu, Dave Jing Tian 等S&P 2024 · 被引用 22 次
- To Boldly Go Where No Fuzzer Has Gone Before: Finding Bugs in Linux' Wireless Stacks through VirtIO DevicesSönke Huster, Matthias Hollick, Jiska ClassenS&P 2024 · 被引用 8 次
- Enhancing Coverage-Guided Fuzzing via Phantom ProgramMingyuan Wu, Kunqiu Chen, Qi Luo, Jiahong Xiang 等FSE 2023 · 被引用 7 次
- BLUFFS: Bluetooth Forward and Future Secrecy Attacks and DefensesDaniele AntonioliCCS 2023 · 被引用 7 次
它引用的顶会 Paper12
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 被引用 1,026 次
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo 等NDSS 2018 · 被引用 311 次
- FIRM-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process EmulationYaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song 等USENIX Security 2019 · 被引用 279 次
- BIAS: Bluetooth Impersonation AttackSDaniele Antonioli, Nils Ole Tippenhauer, Kasper RasmussenS&P 2020 · 被引用 90 次
- The KNOB is Broken: Exploiting Low Entropy in the Encryption Key Negotiation Of Bluetooth BR/EDRDaniele Antonioli, Nils Ole Tippenhauer, Kasper Bonne RasmussenUSENIX Security 2019 · 被引用 89 次
相关 Paper
- BSFuzzer: Context-Aware Semantic Fuzzing for BLE Logic Flaw DetectionTing Yang, Yue Qin, Lan Zhang, Zhiyuan Fu 等NDSS 2026 · 被引用 1 次
- BLuEMan: A Stateful Simulation-based Fuzzing Framework for Open-Source RTOS Bluetooth Low Energy Protocol StacksWei-Che Kao, Yen-Chia Chen, Yu-Sheng Lin, Yu-Cheng Yang 等USENIX Security 2025
- SweynTooth: Unleashing Mayhem over Bluetooth Low EnergyMatheus E. Garbelini, Chundong Wang, Sudipta Chattopadhyay, Sumei Sun 等USENIX ATC 2020 · 被引用 83 次
- Bluetooth Low Energy Security Testing with Combinatorial MethodsDominik-Philip Schreiber, Manuel Leithner, Jovan Zivanovic, Dimitris E. SimosUSENIX ATC 2025 · 被引用 1 次
- Frankenstein: Advanced Wireless Fuzzing to Exploit New Bluetooth Escalation TargetsJan Ruge, Jiska Classen, Francesco Gringoli, Matthias HollickUSENIX Security 2020
