FirmWire: Transparent Dynamic Analysis for Cellular Baseband Firmware
Grant Hernandez, Marius Muench, Dominik Christian Maier, Alyssa Milburn, Shinjo Park, Tobias Scharnowski, Tyler Tucker, Patrick Traynor, Kevin R. B. Butler
摘要
—Smartphones today leverage baseband processors to implement the multitude of cellular protocols. Basebands execute firmware, which is responsible for decoding hundreds of message types developed from three decades of cellular standards. Despite its large over-the-air attack surface, baseband firmware has received little security analysis. Previous work mostly analyzed only a handful of firmware images from a few device models, but often relied heavily on time-consuming manual static analysis or single-function fuzzing. To fill this gap, we present F IRM W IRE , the first full-system emulation platform for baseband processors that executes unmod-ified baseband binary firmware. F IRM W IRE provides baseband-specific APIs to easily add support for new vendors, firmware images, and security analyses. To demonstrate F IRM W IRE ’s scalability, we support 213 firmware images across 2 vendors and 9 phone models, allowing them to be executed and tested. With these images, F IRM W IRE automatically discovers and bridges internal baseband APIs, allowing protocol messages to be injected with ease. Using these entry points, we selected the LTE and GSM protocols for fuzzing and discovered 7 pre-authentication memory corruptions that could lead to remote code execution – 4 of which were previously unknown. We reproduced these crashes over-the-air on real devices, proving F IRM W IRE ’s emulation accuracy. F IRM W IRE is a scalable platform for baseband
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper28
- Your Firmware Has Arrived: A Study of Firmware Update VulnerabilitiesYuhao Wu, Jinwen Wang, Yujie Wang, Shixuan Zhai 等USENIX Security 2024 · 被引用 33 次
- Logic Gone Astray: A Security Analysis Framework for the Control Plane Protocols of 5G BasebandsKai Tu, Abdullah Al Ishtiaq, Syed Md. Mukit Rashid, Yilu Dong 等USENIX Security 2024 · 被引用 26 次
- Learning Seed-Adaptive Mutation Strategies for Greybox FuzzingMyungho Lee, Sooyoung Cha, Hakjoo OhICSE 2023 · 被引用 23 次
- EL3XIR: Fuzzing COTS Secure MonitorsChristian Lindenmeier, Mathias Payer, Marcel BuschUSENIX Security 2024 · 被引用 10 次
- SIMurai: Slicing Through the Complexity of SIM Card Security ResearchTomasz Piotr Lisowski, Merlin Chlosta, Jinjin Wang, Marius MuenchUSENIX Security 2024 · 被引用 10 次
它引用的顶会 Paper21
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei 等CCS 2018 · 被引用 753 次
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 被引用 428 次
- FIRM-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process EmulationYaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song 等USENIX Security 2019 · 被引用 279 次
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 被引用 225 次
相关 Paper
- BaseBridge: Bridging the Gap Between Over-the-Air and Emulation Testing for Cellular Baseband FirmwareDaniel Klischies, Dyon Goos, David Hirsch, Alyssa Milburn 等S&P 2025
- BaseSpec: Comparative Analysis of Baseband Software and Cellular Specifications for L3 ProtocolsEunsoo Kim, Dongkwan Kim, CheolJun Park, Insu Yun 等NDSS 2021
- Stateful Analysis and Fuzzing of Commercial Baseband FirmwareAli Ranjbar, Tianchang Yang, Kai Tu, Saaman Khalilollahi 等S&P 2025
- User-Space Dependency-Aware Rehosting for Linux-Based Firmware BinariesChuan Qin, Cen Zhang, Yaowen Zheng, Puzhuo Liu 等NDSS 2026 · 被引用 2 次
- BaseMirror: Automatic Reverse Engineering of Baseband Commands from Android's Radio Interface LayerWenqiang Li, Haohuang Wen, Zhiqiang LinCCS 2024 · 被引用 1 次
