{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T04:49:49Z","timestamp":1784695789872,"version":"3.55.0"},"reference-count":91,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"funder":[{"DOI":"10.13039\/501100000781","name":"European Research Council","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100000781","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,5]]},"DOI":"10.1109\/sp46215.2023.10179302","type":"proceedings-article","created":{"date-parts":[[2023,7,21]],"date-time":"2023-07-21T17:18:15Z","timestamp":1689959895000},"page":"1204-1219","source":"Crossref","is-referenced-by-count":19,"title":["TEEzz: Fuzzing Trusted Applications on COTS Android Devices"],"prefix":"10.1109","author":[{"given":"Marcel","family":"Busch","sequence":"first","affiliation":[{"name":"EPFL"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Aravind","family":"Machiry","sequence":"additional","affiliation":[{"name":"Purdue University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chad","family":"Spensky","sequence":"additional","affiliation":[{"name":"Allthenticate"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Giovanni","family":"Vigna","sequence":"additional","affiliation":[{"name":"UC Santa Barbara"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christopher","family":"Kruegel","sequence":"additional","affiliation":[{"name":"UC Santa Barbara"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mathias","family":"Payer","sequence":"additional","affiliation":[{"name":"EPFL"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Huawei Trusted Core Kernel Driver"},{"key":"ref2","volume-title":"QSEE Request, and Response Sizes"},{"key":"ref3","volume-title":"QSEECOM Driver"},{"key":"ref4","volume-title":"QSEEComAPI.h"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23384"},{"key":"ref6","volume-title":"SMC Calling Convention"},{"key":"ref7","volume-title":"Tee reference documentation","year":"2018"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3338906.3340456"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3140587.3062349"},{"key":"ref10","first-page":"41","article-title":"Qemu, a fast and portable dynamic translator","volume-title":"Proceedings of the FREENIX","author":"Bellard"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134020"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978428"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2013.6606558"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-93524-9_6"},{"key":"ref15","article-title":"Unearthing the trustedcore: A critical review on huawei\u2019s trusted execution environment","volume-title":"Proceedings of the Workshop on Offensive Technologies, WOOT","author":"Busch"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00061"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.50"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00046"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.14"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134069"},{"key":"ref21","volume-title":"Google android security vulnerabilities","year":"2018"},{"key":"ref22","article-title":"The evolving art of fuzzing","volume":"14","author":"DeMott","year":"2006","journal-title":"DEF CON"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/2843859.2843867"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516758"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.4108\/icst.mobicase.2014.257767"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2009.5070546"},{"key":"ref27","year":"2016","journal-title":"TEE Internal Core API Specification"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/1292414.1292416"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/1375581.1375607"},{"key":"ref30","volume-title":"Drm","year":"2001"},{"key":"ref31","volume-title":"Google play billing overview","year":"2001"},{"key":"ref32","volume-title":"syzkaller - linux syscall fuzzer","year":"2017"},{"key":"ref33","volume-title":"Android hal","year":"2018"},{"key":"ref34","volume-title":"Android security bulletins","year":"2018"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC.2019.00012"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3081333.3081349"},{"key":"ref37","first-page":"135","article-title":"Toward the analysis of embedded firmware through automated re-hosting","volume-title":"Proceedings of the 22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID)","author":"Gustafson"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134103"},{"key":"ref39","article-title":"Partemu: Enabling dynamic analysis of real-world trustzone software using emulation","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security)","author":"Harrison"},{"key":"ref40","first-page":"2271","article-title":"Fuzzgen: Automatic fuzzer generation","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security)","author":"Ispoglou"},{"key":"ref41","first-page":"2271","article-title":"Fuzzgen: Automatic fuzzer generation","volume-title":"Proceedings of the USENIX Security Symposium (USENIX Security)","author":"Ispoglou"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2016.2622261"},{"key":"ref43","first-page":"0","article-title":"Razzer: Finding kernel race bugs through fuzzing","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (S&P)","author":"Jeong"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24018"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2018.2867544"},{"key":"ref46","volume-title":"Exploring qualcomms secure execution environment","year":"2016"},{"key":"ref47","author":"Lee","year":"2011","journal-title":"Tie: Principled reverse engineering of types in binary programs"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/3304080.3304084"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3106295"},{"key":"ref50","volume-title":"The Java Native Interface: Programmer\u2019s Guide and Specification","author":"Liang","year":"1999"},{"key":"ref51","volume-title":"Open portable trusted execution environment","year":"2020"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23227"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/3527322"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/sp.2019.00069"},{"key":"ref55","volume-title":"TLK: A FOSS Stack for Secure Hardware Tokens","author":"Nahari","year":"2012"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/CIC.2016.065"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/2908080.2908119"},{"key":"ref58","volume-title":"Frida","year":"2020"},{"key":"ref59","first-page":"729","article-title":"Moonshine: Optimizing OS fuzzer seed selection with trace distillation","volume-title":"Proceedings of the USENIX Security Symposium (USENIX Security)","author":"Pailoor"},{"key":"ref60","volume-title":"The peach fuzzer","year":"2017"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00056"},{"key":"ref62","volume-title":"Qualcomm mobile security","year":"2018"},{"key":"ref63","article-title":"Not all bytes are equal: Neural byte sieve for fuzzing","author":"Rajpal","year":"2017"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23404"},{"key":"ref65","first-page":"861","article-title":"Optimizing seed selection for fuzzing","volume-title":"Proceedings of the USENIX Security Symposium (USENIX Security), SEC\u201914","author":"Rebert"},{"key":"ref66","article-title":"Bootstomp: on the security of bootloaders in mobile devices","volume-title":"Proceedings of the USENIX Security Symposium (USENIX Security)","author":"Redini"},{"key":"ref67","article-title":"Reflections on trusting trustzone","author":"Rosenberg","year":"2014","journal-title":"BlackHat USA"},{"key":"ref68","volume-title":"Samsung teegris","year":"2020"},{"key":"ref69","article-title":"Android binder","volume-title":"A shorter, more general work, but good for an overview of Binder","author":"Schreiber","year":"2011"},{"key":"ref70","volume-title":"Android kernel exploits","year":"2018"},{"issue":"46","key":"ref71","first-page":"38","article-title":"Neuzz: Efficient fuzzing with neural program smoothing","volume":"89","author":"She","year":"2018","journal-title":"machine learning"},{"key":"ref72","article-title":"Exploiting trustzone on android","author":"Di Shen","year":"2015","journal-title":"Black Hat USA"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23368"},{"key":"ref74","volume-title":"OP-TEE non-secure world-secure world driver"},{"key":"ref75","volume-title":"OP-TEE non-secure world-secure world smc call"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813692"},{"key":"ref77","first-page":"291","article-title":"Charm: facilitating dynamic analysis of device drivers of mobile systems","volume-title":"Proceedings of the USENIX Security Symposium (USENIX Security)","author":"Seyed Talebi"},{"key":"ref78","first-page":"1057","article-title":"Clkscrew: exposing the perils of security-oblivious energy management","volume-title":"Proceedings of the USENIX Security Symposium (USENIX Security)","author":"Tang"},{"key":"ref79","volume-title":"Emui 8.0 security technical white paper","year":"2017"},{"key":"ref80","volume-title":"trustonic-tee-user-space","year":"2015"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1109\/IWAST.2012.6228985"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417886"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243835"},{"key":"ref84","volume-title":"kernel exploits","year":"2018"},{"key":"ref85","volume-title":"Huawei kirin trustzone","year":"2017"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134046"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1109\/Trustcom\/BigDataSE\/ICESS.2017.243"},{"key":"ref88","volume-title":"Trust issues: Exploiting trustzone tees","year":"2018"},{"key":"ref89","author":"Zhang","year":"2014","journal-title":"Trustfa: Trustzone-assisted facial authentication on smartphone. Technical report, Technical Report"},{"key":"ref90","first-page":"980","article-title":"Truspy: Cache side-channel information leakage from the secure world on arm devices","volume":"2016","author":"Zhang","year":"2016","journal-title":"IACR Cryptology ePrint Archive"},{"key":"ref91","author":"Zimmer","year":"2016","journal-title":"Establishing the root of trust"}],"event":{"name":"2023 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2023,5,21]]},"end":{"date-parts":[[2023,5,25]]}},"container-title":["2023 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10179215\/10179280\/10179302.pdf?arnumber=10179302","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,20]],"date-time":"2024-07-20T04:40:31Z","timestamp":1721450431000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10179302\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5]]},"references-count":91,"URL":"https:\/\/doi.org\/10.1109\/sp46215.2023.10179302","relation":{},"subject":[],"published":{"date-parts":[[2023,5]]}}}