{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:31:21Z","timestamp":1750221081222,"version":"3.41.0"},"reference-count":49,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2018,12,19]],"date-time":"2018-12-19T00:00:00Z","timestamp":1545177600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Cyber-Phys. Syst."],"published-print":{"date-parts":[[2019,4,30]]},"abstract":"<jats:p>Z-Wave is a proprietary Internet of Things substrate providing distributed home and office automation services. The proprietary nature of Z-Wave devices makes it difficult to determine their security aptitude. While there are a variety of open source tools for analyzing Z-Wave frames, inspecting non-volatile memory, and disassembling firmware, there are no dynamic analysis tools allowing one to inspect the internal state of a Z-Wave transceiver while it is running. In this work, a memory introspection capability is developed for three Z-Wave devices containing a ZW0301, a Z-Wave transceiver system-on-chip. In all three devices, the firmware image is modified to include the memory introspection capability by hooking an existing data exfiltration mechanism used by the device. The memory introspection capability is applied to determine how nonces are generated by Z-Wave devices to prevent replay attacks. Through a combination of static and dynamic analysis, the nonce generating algorithm is found to be based on a nonce round key that updates every secure frame transaction.<\/jats:p>","DOI":"10.1145\/3285030","type":"journal-article","created":{"date-parts":[[2018,12,19]],"date-time":"2018-12-19T13:07:08Z","timestamp":1545224828000},"page":"1-24","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Looking Under the Hood of Z-Wave"],"prefix":"10.1145","volume":"3","author":[{"given":"C. W.","family":"Badenhop","sequence":"first","affiliation":[{"name":"Air Force Institute of Technology, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"S. R.","family":"Graham","sequence":"additional","affiliation":[{"name":"Air Force Institute of Technology, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"B. E.","family":"Mullins","sequence":"additional","affiliation":[{"name":"Air Force Institute of Technology, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"L. O.","family":"Mailloux","sequence":"additional","affiliation":[{"name":"Air Force Institute of Technology, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2018,12,19]]},"reference":[{"volume-title":"Proceedings of the 2015 International Carnahan Conference on Security Technology (ICCST). v1--6.","author":"Agosta G.","key":"e_1_2_1_1_1","unstructured":"G. Agosta , A. Antonini , A. Barenghi , D. Galeri , and G. Pelosi . 2015. Cyber-security analysis and evaluation for smart home management solutions . In Proceedings of the 2015 International Carnahan Conference on Security Technology (ICCST). v1--6. G. Agosta, A. Antonini, A. Barenghi, D. Galeri, and G. Pelosi. 2015. Cyber-security analysis and evaluation for smart home management solutions. In Proceedings of the 2015 International Carnahan Conference on Security Technology (ICCST). v1--6."},{"key":"e_1_2_1_2_1","unstructured":"C. Badenhop J. Fuller J. Hall B. Ramsey and M. Rice. 2015. Evaluating ITU-T G.9959: Wireless systems in the critical infrastructure. In Critical Infrastructure Protection IX IFIPS WG 11.10 J. Butts and S. Shenoi (Eds.). Springer 61--79.  C. Badenhop J. Fuller J. Hall B. Ramsey and M. Rice. 2015. Evaluating ITU-T G.9959: Wireless systems in the critical infrastructure. In Critical Infrastructure Protection IX IFIPS WG 11.10 J. Butts and S. Shenoi (Eds.). Springer 61--79."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.04.004"},{"key":"e_1_2_1_4_1","unstructured":"C. Badenhop and B. Ramsey. 2016. Carols of the Z-Wave security layer; Or robbing keys from Peter to unlock Paul. PoC or GTFO 12 (2016) 6--12.  C. Badenhop and B. Ramsey. 2016. Carols of the Z-Wave security layer; Or robbing keys from Peter to unlock Paul. PoC or GTFO 12 (2016) 6--12."},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2016.02.002"},{"key":"e_1_2_1_6_1","doi-asserted-by":"crossref","unstructured":"T. Bihl K. Bauer M. Temple and B. Ramsey. 2015. Dimensional reduction analysis for physical layer device fingerprints with application to ZigBee and Z-Wave devices. In MILCOM. 360--365.  T. Bihl K. Bauer M. Temple and B. Ramsey. 2015. Dimensional reduction analysis for physical layer device fingerprints with application to ZigBee and Z-Wave devices. In MILCOM. 360--365.","DOI":"10.1109\/MILCOM.2015.7357469"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2015.01.012"},{"key":"e_1_2_1_8_1","unstructured":"A. Crenshaw. 2015. TSA Master Key Duplication 8 Why \u201cSecurity Through (Not So) Obscurity\u201d Fails\u2014TrustedSec. Retrieved from https:\/\/www.trustedsec.com\/august-2015\/master-key-duplication\/.  A. Crenshaw. 2015. TSA Master Key Duplication 8 Why \u201cSecurity Through (Not So) Obscurity\u201d Fails\u2014TrustedSec. Retrieved from https:\/\/www.trustedsec.com\/august-2015\/master-key-duplication\/."},{"volume-title":"Proceedings of the NDSS Symposium.","author":"Cui A.","key":"e_1_2_1_9_1","unstructured":"A. Cui , M. Costello , and S. Stolfo . 2013. When firmware modifications attack: A case study of embedded exploitation . In Proceedings of the NDSS Symposium. A. Cui, M. Costello, and S. Stolfo. 2013. When firmware modifications attack: A case study of embedded exploitation. In Proceedings of the NDSS Symposium."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516697"},{"key":"e_1_2_1_11_1","unstructured":"B. Fouladi and S. Ghanoun. 2013. Security evaluation of the Z-Wave wireless protocol. In Blackhat USA.  B. Fouladi and S. Ghanoun. 2013. Security evaluation of the Z-Wave wireless protocol. In Blackhat USA."},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/LCNW.2015.7365922"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2016.10.003"},{"volume-title":"Proceedings of the 5th International Conference on Intelligent Control and Information Processing. 270--275","author":"Gao Y.","key":"e_1_2_1_14_1","unstructured":"Y. Gao , Z. Lu , and Y. Lu . 2014. Survey on malware anti-analysis . In Proceedings of the 5th International Conference on Intelligent Control and Information Processing. 270--275 . Y. Gao, Z. Lu, and Y. Lu. 2014. Survey on malware anti-analysis. In Proceedings of the 5th International Conference on Intelligent Control and Information Processing. 270--275."},{"key":"e_1_2_1_15_1","unstructured":"T. Goodspeed. 2013. Some shellcode tips for MSP430 and related MCUs. In Children\u2019s Bible Coloring Book of PoC or GTFO Issue 0x02. 10--12.  T. Goodspeed. 2013. Some shellcode tips for MSP430 and related MCUs. In Children\u2019s Bible Coloring Book of PoC or GTFO Issue 0x02. 10--12."},{"key":"e_1_2_1_16_1","unstructured":"T. Goodspeed. 2015. GoodFET Homepage. Retrieved from http:\/\/www.goodfet.sourceforge.net.  T. Goodspeed. 2015. GoodFET Homepage. Retrieved from http:\/\/www.goodfet.sourceforge.net."},{"key":"e_1_2_1_17_1","unstructured":"J. Hall and B. Ramsey. 2016. Breaking bulbs briskly by bogus broadcasts. In Presented at ShmooCon Washington D.C.  J. Hall and B. Ramsey. 2016. Breaking bulbs briskly by bogus broadcasts. In Presented at ShmooCon Washington D.C."},{"volume-title":"Proceedings of the International Conference on Cyber Warfare and Security. 163--171","author":"Hall J.","key":"e_1_2_1_18_1","unstructured":"J. Hall , B. Ramsey , M. Rice , and T. Lacey . 2016. Z-Wave network reconnaissance and transceiver fingerprinting using software-defined radios . In Proceedings of the International Conference on Cyber Warfare and Security. 163--171 . J. Hall, B. Ramsey, M. Rice, and T. Lacey. 2016. Z-Wave network reconnaissance and transceiver fingerprinting using software-defined radios. In Proceedings of the International Conference on Cyber Warfare and Security. 163--171."},{"key":"e_1_2_1_19_1","volume-title":"Sigma Designs Acquires Zensys Holdings. Retrieved","author":"Hightower D.","year":"2017","unstructured":"D. Hightower . 2017. Sigma Designs Acquires Zensys Holdings. Retrieved March 2, 2017 from http:\/\/mwrf.com\/content\/sigma-designs-acquires-zensys-holdings. D. Hightower. 2017. Sigma Designs Acquires Zensys Holdings. Retrieved March 2, 2017 from http:\/\/mwrf.com\/content\/sigma-designs-acquires-zensys-holdings."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2006.36"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.2006.1705877"},{"key":"e_1_2_1_24_1","unstructured":"J. Johansson and R. Grimes. 2008. Is Security by Obscurity a valid approach? Retrieved from https:\/\/technet.microsoft.com\/en-us\/library\/2008.06.obscurity.aspx.  J. Johansson and R. Grimes. 2008. Is Security by Obscurity a valid approach? Retrieved from https:\/\/technet.microsoft.com\/en-us\/library\/2008.06.obscurity.aspx."},{"key":"e_1_2_1_25_1","unstructured":"Keil. 2015. Keil C51 C Compiler. Retrieved from http:\/\/www.keil.com\/c51\/c51.asp.  Keil. 2015. Keil C51 C Compiler. Retrieved from http:\/\/www.keil.com\/c51\/c51.asp."},{"volume-title":"Proceedings of the 2014 International Conference on IT Convergence and Security (ICITCS). 1--3.","author":"Kwon S.","key":"e_1_2_1_26_1","unstructured":"S. Kwon , H. Yoo , T. Shon , and G. Lee . 2014. Scenario-based attack route on industrial control system . In Proceedings of the 2014 International Conference on IT Convergence and Security (ICITCS). 1--3. S. Kwon, H. Yoo, T. Shon, and G. Lee. 2014. Scenario-based attack route on industrial control system. In Proceedings of the 2014 International Conference on IT Convergence and Security (ICITCS). 1--3."},{"key":"e_1_2_1_27_1","unstructured":"J. Larson. 2014. Miniaturization. Presented at Blackhat USA.  J. Larson. 2014. Miniaturization. Presented at Blackhat USA."},{"key":"e_1_2_1_28_1","volume-title":"Proceedings of the 2016 IEEE 23rd International Conference on Software Analysis, Evolution, and Reengineering (SANER)","volume":"1","author":"Leach K.","unstructured":"K. Leach , C. Spensky , W. Weimer , and F. Zhang . 2016. Towards transparent introspection . In Proceedings of the 2016 IEEE 23rd International Conference on Software Analysis, Evolution, and Reengineering (SANER) , Vol. 1 . v248--259. K. Leach, C. Spensky, W. Weimer, and F. Zhang. 2016. Towards transparent introspection. In Proceedings of the 2016 IEEE 23rd International Conference on Software Analysis, Evolution, and Reengineering (SANER), Vol. 1. v248--259."},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948149"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/CITCON.2012.6215678"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICPADS.2008.126"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCE.2011.5973848"},{"key":"e_1_2_1_33_1","unstructured":"OpenZWave. 2015. OpenZWave Homepage. Retrieved from http:\/\/www.openzwave.com\/home.  OpenZWave. 2015. OpenZWave Homepage. Retrieved from http:\/\/www.openzwave.com\/home."},{"key":"e_1_2_1_34_1","unstructured":"A. Palmer. 2013. Security Through Obscurity\u2014Fail. Retrieved from https:\/\/www.adampalmer.me\/iodigitalsec\/2013\/07\/03\/security-through-obscurity-fail\/.  A. Palmer. 2013. Security Through Obscurity\u2014Fail. Retrieved from https:\/\/www.adampalmer.me\/iodigitalsec\/2013\/07\/03\/security-through-obscurity-fail\/."},{"key":"e_1_2_1_35_1","doi-asserted-by":"crossref","unstructured":"J. Patel and B. Ramsey. 2015. Comparison of parametric and non-parametric statistical features for Z-Wave fingerprinting. In MILCOM. 378--382.  J. Patel and B. Ramsey. 2015. Comparison of parametric and non-parametric statistical features for Z-Wave fingerprinting. In MILCOM. 378--382.","DOI":"10.1109\/MILCOM.2015.7357472"},{"key":"e_1_2_1_36_1","unstructured":"J. M. Picod. 2014. Dumping firmware out of a Z-Wave ASIC. Retrieved from http:\/\/blog.cassidiancybersecurity.com\/post\/2014\/02\/Dumping-firmware-from-ASIC.  J. M. Picod. 2014. Dumping firmware out of a Z-Wave ASIC. Retrieved from http:\/\/blog.cassidiancybersecurity.com\/post\/2014\/02\/Dumping-firmware-from-ASIC."},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2012.6378631"},{"key":"e_1_2_1_38_1","unstructured":"Scapy-Radio 2016. GitHub\u2014BastilleResearch\/scapy-radio: Scapy-radio (from original Hg repo). Retrieved from https:\/\/github.com\/BastilleResearch\/scapy-radio.  Scapy-Radio 2016. GitHub\u2014BastilleResearch\/scapy-radio: Scapy-radio (from original Hg repo). Retrieved from https:\/\/github.com\/BastilleResearch\/scapy-radio."},{"key":"e_1_2_1_39_1","unstructured":"B. Schneier. 2014. The Insecurity of Secret IT Systems. Retrieved from https:\/\/www.schneier.com\/blog\/archives\/2014\/02\/the_insecurity_2.html.  B. Schneier. 2014. The Insecurity of Secret IT Systems. Retrieved from https:\/\/www.schneier.com\/blog\/archives\/2014\/02\/the_insecurity_2.html."},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3131473.3131476"},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISORC.2014.16"},{"volume-title":"The 8051\/8052 Microcontroller","author":"Steiner C.","key":"e_1_2_1_42_1","unstructured":"C. Steiner . 2005. The 8051\/8052 Microcontroller . Universal Publishers, Boca Raton , FL. C. Steiner. 2005. The 8051\/8052 Microcontroller. Universal Publishers, Boca Raton, FL."},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/568235.568237"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2015.01.010"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/WCRE.2005.13"},{"key":"e_1_2_1_46_1","unstructured":"M. Yason. 2007. The art of unpacking. In Blackhat USA.  M. Yason. 2007. The art of unpacking. In Blackhat USA."},{"volume-title":"Proceedings of the International Conference on Security and Cryptography. 418--421","author":"Yu J.","key":"e_1_2_1_47_1","unstructured":"J. Yu and P. Brune . 2011. No security by obscurity\u2014Why two factor authentication should be based on an open design . In Proceedings of the International Conference on Security and Cryptography. 418--421 . J. Yu and P. Brune. 2011. No security by obscurity\u2014Why two factor authentication should be based on an open design. In Proceedings of the International Conference on Security and Cryptography. 418--421."},{"key":"e_1_2_1_48_1","unstructured":"Z-Wave. 2017. Z-Wave the Smartest Choice for your Smart Home. Retrieved from http:\/\/www.z-wave.com.  Z-Wave. 2017. Z-Wave the Smartest Choice for your Smart Home. Retrieved from http:\/\/www.z-wave.com."},{"key":"e_1_2_1_49_1","unstructured":"Zensys. 2007. ZM3102N Z-Wave Module Datasheet. Zensys.  Zensys. 2007. ZM3102N Z-Wave Module Datasheet. Zensys."},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.11"},{"key":"e_1_2_1_51_1","unstructured":"ZWAlliance. 2017. The Internet of Things is powered by Z-Wave. Retrieved from http:\/\/www.z-wavealliance.org.  ZWAlliance. 2017. The Internet of Things is powered by Z-Wave. Retrieved from http:\/\/www.z-wavealliance.org."}],"container-title":["ACM Transactions on Cyber-Physical Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3285030","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3285030","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T00:57:40Z","timestamp":1750208260000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3285030"}},"subtitle":["Volatile Memory Introspection for the ZW0301 Transceiver"],"short-title":[],"issued":{"date-parts":[[2018,12,19]]},"references-count":49,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2019,4,30]]}},"alternative-id":["10.1145\/3285030"],"URL":"https:\/\/doi.org\/10.1145\/3285030","relation":{},"ISSN":["2378-962X","2378-9638"],"issn-type":[{"type":"print","value":"2378-962X"},{"type":"electronic","value":"2378-9638"}],"subject":[],"published":{"date-parts":[[2018,12,19]]},"assertion":[{"value":"2017-11-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2018-10-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2018-12-19","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}