BASECOMP: A Comparative Analysis for Integrity Protection in Cellular Baseband Software
Eunsoo Kim, Minwoo Baek, CheolJun Park, Dongkwan Kim, Yongdae Kim, Insu Yun
摘要
Baseband software is an important component in cellular communication. Unfortunately, it is almost impossible to implement baseband software correctly due to the complexity and the large volume of cellular specifications. As a result, dynamic testing has been widely used to discover implementation bugs in them. However, this approach suffers from the reachability problem, resulting in many missed bugs. Recently, BaseSpec proposed a static approach for analyzing baseband. However, BaseSpec requires heavy manual analysis and is limited to message decoding, failing to support integrity protection, the most critical step in mobile communication. In this paper, we propose a novel, semi-automated approach, BASECOMP, for analyzing integrity protection. To tame the complexity of baseband firmware, BASECOMP utilizes probabilistic inference to identify the integrity protection function. In particular, BASECOMP builds a factor graph from the firmware based on specifications and discovers the most probable function for integrity protection. Then, with additional manual analysis, BASECOMP performs symbolic analysis to validate that its behavior conforms to the specification and reports any discrepancies. We applied BASECOMP to 16 firmware images from two vendors (Samsung and MediaTek) in addition to srsRAN, an open-source 4G and 5G software radio suite. As a result, we discovered 29 bugs, including a NAS AKA bypass vulnerability in Samsung which was assigned critical severity. Moreover, BASECOMP can narrow down the number of functions to be manually analyzed to 1.56 on average. This can significantly reduce manual efforts for analysis, the primary limitation of the previous static analysis approach for baseband.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- Logic Gone Astray: A Security Analysis Framework for the Control Plane Protocols of 5G BasebandsKai Tu, Abdullah Al Ishtiaq, Syed Md. Mukit Rashid, Yilu Dong 等USENIX Security 2024 · 被引用 26 次
- SIMurai: Slicing Through the Complexity of SIM Card Security ResearchTomasz Piotr Lisowski, Merlin Chlosta, Jinjin Wang, Marius MuenchUSENIX Security 2024 · 被引用 10 次
- State Machine Mutation-based Testing Framework for Wireless Communication ProtocolsSyed Md. Mukit Rashid, Tianwei Wu, Kai Tu, Abdullah Al Ishtiaq 等CCS 2024 · 被引用 4 次
- Strong Privacy-Preserving Universally Composable AKA Protocol with Seamless Handover Support for Mobile Virtual Network OperatorRabiah Alnashwan, Yang Yang, Yilu Dong, Prosanta Gope 等CCS 2024 · 被引用 4 次
- BaseMirror: Automatic Reverse Engineering of Baseband Commands from Android's Radio Interface LayerWenqiang Li, Haohuang Wen, Zhiqiang LinCCS 2024 · 被引用 1 次
它引用的顶会 Paper15
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication SystemsAltaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan 等NDSS 2016 · 被引用 342 次
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 被引用 225 次
- Breaking LTE on Layer TwoDavid Rupprecht, Katharina Kohls, Thorsten Holz, Christina PöpperS&P 2019 · 被引用 219 次
- 5GReasoner: A Property-Directed Security and Privacy Analysis Framework for 5G Cellular Network ProtocolSyed Rafiul Hussain, Mitziu Echeverria, Imtiaz Karim, Omar Chowdhury 等CCS 2019 · 被引用 188 次
相关 Paper
- BaseSpec: Comparative Analysis of Baseband Software and Cellular Specifications for L3 ProtocolsEunsoo Kim, Dongkwan Kim, CheolJun Park, Insu Yun 等NDSS 2021
- BaseBridge: Bridging the Gap Between Over-the-Air and Emulation Testing for Cellular Baseband FirmwareDaniel Klischies, Dyon Goos, David Hirsch, Alyssa Milburn 等S&P 2025
- Stateful Analysis and Fuzzing of Commercial Baseband FirmwareAli Ranjbar, Tianchang Yang, Kai Tu, Saaman Khalilollahi 等S&P 2025
- Semantic-Enhanced Static Vulnerability Detection in Baseband FirmwareYiming Liu, Cen Zhang, Feng Li, Yeting Li 等ICSE 2024 · 被引用 4 次
- FirmWire: Transparent Dynamic Analysis for Cellular Baseband FirmwareGrant Hernandez, Marius Muench, Dominik Christian Maier, Alyssa Milburn 等NDSS 2022
