{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T01:43:36Z","timestamp":1787017416718,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":60,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,7,8]],"date-time":"2020-07-08T00:00:00Z","timestamp":1594166400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,7,8]]},"DOI":"10.1145\/3395351.3399360","type":"proceedings-article","created":{"date-parts":[[2020,7,22]],"date-time":"2020-07-22T00:29:10Z","timestamp":1595377750000},"page":"122-132","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":57,"title":["BaseSAFE"],"prefix":"10.1145","author":[{"given":"Dominik","family":"Maier","sequence":"first","affiliation":[{"name":"TU Berlin"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lukas","family":"Seidel","sequence":"additional","affiliation":[{"name":"TU Berlin"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shinjo","family":"Park","sequence":"additional","affiliation":[{"name":"TU Berlin"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,7,21]]},"reference":[{"key":"e_1_3_2_1_1_1","first-page":"007","article-title":"AT command set for User Equipment (UE)","volume":"27","author":"GPP.","year":"2018","unstructured":"3 GPP. 2018 . AT command set for User Equipment (UE) . Technical Specification (TS) 27 . 007 . 3rd Generation Partnership Project (3GPP). http:\/\/www.3gpp.org\/DynaReport\/27007.htm Version 15.4.0. 3GPP. 2018. AT command set for User Equipment (UE). Technical Specification (TS) 27.007. 3rd Generation Partnership Project (3GPP). http:\/\/www.3gpp.org\/DynaReport\/27007.htm Version 15.4.0.","journal-title":"Technical Specification (TS)"},{"key":"e_1_3_2_1_2_1","first-page":"040","article-title":"Technical realization of the Short Message Service (SMS)","volume":"23","author":"GPP.","year":"2018","unstructured":"3 GPP. 2018 . Technical realization of the Short Message Service (SMS) . Technical Specification (TS) 23 . 040 . 3rd Generation Partnership Project (3GPP). http:\/\/www.3gpp.org\/DynaReport\/23040.htm 3GPP. 2018. Technical realization of the Short Message Service (SMS). Technical Specification (TS) 23.040. 3rd Generation Partnership Project (3GPP). http:\/\/www.3gpp.org\/DynaReport\/23040.htm","journal-title":"Technical Specification (TS)"},{"key":"e_1_3_2_1_3_1","first-page":"331","article-title":"Evolved Universal Terrestrial Radio Access (E-UTRA); Radio Resource Control (RRC); Protocol specification","volume":"36","author":"GPP.","year":"2020","unstructured":"3 GPP. 2020 . Evolved Universal Terrestrial Radio Access (E-UTRA); Radio Resource Control (RRC); Protocol specification . Technical Specification (TS) 36 . 331 . 3rd Generation Partnership Project (3GPP). http:\/\/www.3gpp.org\/DynaReport\/36331.htm 3GPP. 2020. Evolved Universal Terrestrial Radio Access (E-UTRA); Radio Resource Control (RRC); Protocol specification. Technical Specification (TS) 36.331. 3rd Generation Partnership Project (3GPP). http:\/\/www.3gpp.org\/DynaReport\/36331.htm","journal-title":"Technical Specification (TS)"},{"key":"e_1_3_2_1_4_1","first-page":"008","article-title":"Mobile radio interface Layer 3 specification; Core network protocols; Stage 3","volume":"24","author":"GPP.","year":"2020","unstructured":"3 GPP. 2020 . Mobile radio interface Layer 3 specification; Core network protocols; Stage 3 . Technical Specification (TS) 24 . 008 . 3rd Generation Partnership Project (3GPP). http:\/\/www.3gpp.org\/DynaReport\/24008.htm 3GPP. 2020. Mobile radio interface Layer 3 specification; Core network protocols; Stage 3. Technical Specification (TS) 24.008. 3rd Generation Partnership Project (3GPP). http:\/\/www.3gpp.org\/DynaReport\/24008.htm","journal-title":"Technical Specification (TS)"},{"key":"e_1_3_2_1_5_1","first-page":"301","article-title":"Non-Access-Stratum (NAS) protocol for Evolved Packet System (EPS); Stage 3","volume":"24","author":"GPP.","year":"2020","unstructured":"3 GPP. 2020 . Non-Access-Stratum (NAS) protocol for Evolved Packet System (EPS); Stage 3 . Technical Specification (TS) 24 . 301 . 3rd Generation Partnership Project (3GPP). http:\/\/www.3gpp.org\/DynaReport\/24301.htm 3GPP. 2020. Non-Access-Stratum (NAS) protocol for Evolved Packet System (EPS); Stage 3. Technical Specification (TS) 24.301. 3rd Generation Partnership Project (3GPP). http:\/\/www.3gpp.org\/DynaReport\/24301.htm","journal-title":"Technical Specification (TS)"},{"key":"e_1_3_2_1_6_1","first-page":"331","article-title":"Radio Resource Control (RRC); Protocol specification","volume":"25","author":"GPP.","year":"2020","unstructured":"3 GPP. 2020 . Radio Resource Control (RRC); Protocol specification . Technical Specification (TS) 25 . 331 . 3rd Generation Partnership Project (3GPP). http:\/\/www.3gpp.org\/DynaReport\/25331.htm 3GPP. 2020. Radio Resource Control (RRC); Protocol specification. Technical Specification (TS) 25.331. 3rd Generation Partnership Project (3GPP). http:\/\/www.3gpp.org\/DynaReport\/25331.htm","journal-title":"Technical Specification (TS)"},{"key":"e_1_3_2_1_7_1","unstructured":"AFL. 2020. AFL QEMU Mode. https:\/\/github.com\/mirrorer\/afl\/blob\/master\/qemu_mode\/README.qemu  AFL. 2020. AFL QEMU Mode. https:\/\/github.com\/mirrorer\/afl\/blob\/master\/qemu_mode\/README.qemu"},{"key":"e_1_3_2_1_8_1","volume-title":"SMS fuzzing-SIM toolkit attack. DEF CON 21","author":"Alecu Bogdan","year":"2013","unstructured":"Bogdan Alecu . 2013. SMS fuzzing-SIM toolkit attack. DEF CON 21 ( 2013 ). Bogdan Alecu. 2013. SMS fuzzing-SIM toolkit attack. DEF CON 21 (2013)."},{"key":"e_1_3_2_1_9_1","volume-title":"USENIX Annual Technical Conference, FREENIX Track","volume":"41","author":"Bellard Fabrice","year":"2005","unstructured":"Fabrice Bellard . 2005 . QEMU, a fast and portable dynamic translator .. In USENIX Annual Technical Conference, FREENIX Track , Vol. 41 . 46. Fabrice Bellard. 2005. QEMU, a fast and portable dynamic translator.. In USENIX Annual Technical Conference, FREENIX Track, Vol. 41. 46."},{"key":"e_1_3_2_1_10_1","unstructured":"Fabrice Bellard. 2020. Tiny Code Generator. https:\/\/git.qemu.org\/?p=qemu.git;a=blob_plain;f=tcg\/README;hb=HEAD  Fabrice Bellard. 2020. Tiny Code Generator. https:\/\/git.qemu.org\/?p=qemu.git;a=blob_plain;f=tcg\/README;hb=HEAD"},{"key":"e_1_3_2_1_11_1","volume-title":"Improving AFL's QEMU mode performance. 0x41414141 in ??() (Sep","author":"Biondo Andrea","year":"2018","unstructured":"Andrea Biondo . 2018. Improving AFL's QEMU mode performance. 0x41414141 in ??() (Sep 2018 ). https:\/\/abiondo.me\/2018\/09\/21\/improving-afl-qemu-mode Andrea Biondo. 2018. Improving AFL's QEMU mode performance. 0x41414141 in ??() (Sep 2018). https:\/\/abiondo.me\/2018\/09\/21\/improving-afl-qemu-mode"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-007-0065-x"},{"key":"e_1_3_2_1_13_1","unstructured":"Comsecuris. 2020. QEMU with support for QDSP6 user mode emulation. https:\/\/github.com\/Comsecuris\/qemu-hexagon  Comsecuris. 2020. QEMU with support for QDSP6 user mode emulation. https:\/\/github.com\/Comsecuris\/qemu-hexagon"},{"key":"e_1_3_2_1_14_1","volume-title":"RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and Sanitization","author":"Dinesh S. Dinesh S.","year":"2020","unstructured":"S. Dinesh S. Dinesh , Nathan Burow , Dongyan Xu , and Mathias Payer . 2020. RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and Sanitization . In IEEE S &P 2020 . S. Dinesh S. Dinesh, Nathan Burow, Dongyan Xu, and Mathias Payer. 2020. RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and Sanitization. In IEEE S&P 2020."},{"key":"e_1_3_2_1_15_1","unstructured":"David Drysdale. 2016. Coverage-guided kernel fuzzing with syzkaller. https:\/\/lwn.net\/Articles\/677764\/  David Drysdale. 2016. Coverage-guided kernel fuzzing with syzkaller. https:\/\/lwn.net\/Articles\/677764\/"},{"key":"e_1_3_2_1_16_1","unstructured":"S\u00e9bastien Duquette. 2020. Rust bindings for the unicorn CPU emulator. https:\/\/github.com\/ekse\/unicorn-rs  S\u00e9bastien Duquette. 2020. Rust bindings for the unicorn CPU emulator. https:\/\/github.com\/ekse\/unicorn-rs"},{"key":"e_1_3_2_1_17_1","volume-title":"Vectorized Emulation: Hardware accelerated taint tracking at 2 trillion instructions per second. https:\/\/gamozolabs.github.io\/fuzzing\/2018\/10\/14\/vectorized_emulation.html [Online","author":"Falk Brandon","year":"2018","unstructured":"Brandon Falk . 2018 . Vectorized Emulation: Hardware accelerated taint tracking at 2 trillion instructions per second. https:\/\/gamozolabs.github.io\/fuzzing\/2018\/10\/14\/vectorized_emulation.html [Online ; accessed 11. Nov. 2018]. Brandon Falk. 2018. Vectorized Emulation: Hardware accelerated taint tracking at 2 trillion instructions per second. https:\/\/gamozolabs.github.io\/fuzzing\/2018\/10\/14\/vectorized_emulation.html [Online; accessed 11. Nov. 2018]."},{"key":"e_1_3_2_1_18_1","unstructured":"Andrea Fioraldi. 2019. Sanitized Emulation with QASan. https:\/\/andreafioraldi.github.io\/articles\/2019\/12\/20\/sanitized-emulation-with-qasan.html  Andrea Fioraldi. 2019. Sanitized Emulation with QASan. https:\/\/andreafioraldi.github.io\/articles\/2019\/12\/20\/sanitized-emulation-with-qasan.html"},{"key":"e_1_3_2_1_19_1","unstructured":"Nico Golde and Daniel Komaromy. 2016. Breaking Band: reverse engineering and exploiting the shannon baseband. https:\/\/comsecuris.com\/slides\/recon2016-breaking_band.pdf  Nico Golde and Daniel Komaromy. 2016. Breaking Band: reverse engineering and exploiting the shannon baseband. https:\/\/comsecuris.com\/slides\/recon2016-breaking_band.pdf"},{"key":"e_1_3_2_1_20_1","volume-title":"Leith","author":"Gomez-Miguelez Ismael","year":"2016","unstructured":"Ismael Gomez-Miguelez , Andres Garcia-Saavedra , Paul D. Sutton , Pablo Serrano , Cristina Cano , and Douglas J . Leith . 2016 . srsLTE: An Open-Source Platform for LTE Evolution and Experimentation. CoRR abs\/1602.04629 (2016). http:\/\/arxiv.org\/abs\/1602.04629 Ismael Gomez-Miguelez, Andres Garcia-Saavedra, Paul D. Sutton, Pablo Serrano, Cristina Cano, and Douglas J. Leith. 2016. srsLTE: An Open-Source Platform for LTE Evolution and Experimentation. CoRR abs\/1602.04629 (2016). http:\/\/arxiv.org\/abs\/1602.04629"},{"key":"e_1_3_2_1_21_1","unstructured":"Marco Grassi and Xingyu Chen. 2020. Exploring the MediaTek Baseband. In OffensiveCon.  Marco Grassi and Xingyu Chen. 2020. Exploring the MediaTek Baseband. In OffensiveCon."},{"key":"e_1_3_2_1_22_1","volume-title":"11th USENIX Workshop on Offensive Technologies (WOOT 17)","author":"Hay Roee","year":"2017","unstructured":"Roee Hay . 2017 . fastboot OEM vuln: Android bootloader vulnerabilities in vendor customizations . In 11th USENIX Workshop on Offensive Technologies (WOOT 17) . Roee Hay. 2017. fastboot OEM vuln: Android bootloader vulnerabilities in vendor customizations. In 11th USENIX Workshop on Offensive Technologies (WOOT 17)."},{"key":"e_1_3_2_1_23_1","unstructured":"Willem Hengeveld. 2013. IDA processor module for the hexagon (QDSP6) processor. https:\/\/github.com\/gsmk\/hexagon  Willem Hengeveld. 2013. IDA processor module for the hexagon (QDSP6) processor. https:\/\/github.com\/gsmk\/hexagon"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3317549.3326310"},{"key":"e_1_3_2_1_26_1","unstructured":"Marc Heuse Heiko Ei\u00dffeld Andrea Fioraldi and Dominik Maier. 2020. american fuzzy lop plus plus (afl++). GitHub. https:\/\/github.com\/vanhauser-thc\/AFLplusplus  Marc Heuse Heiko Ei\u00dffeld Andrea Fioraldi and Dominik Maier. 2020. american fuzzy lop plus plus (afl++). GitHub. https:\/\/github.com\/vanhauser-thc\/AFLplusplus"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23313"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354263"},{"key":"e_1_3_2_1_29_1","unstructured":"Imagination Technologies. 2017. MediaTek selects MIPS for LTE modems. https:\/\/www.mips.com\/press\/mediatek-selects-mips-for-lte-modems\/  Imagination Technologies. 2017. MediaTek selects MIPS for LTE modems. https:\/\/www.mips.com\/press\/mediatek-selects-mips-for-lte-modems\/"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2014.45"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359833"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00038"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/CECNET.2011.5768296"},{"key":"e_1_3_2_1_34_1","volume-title":"Unicorefuzz: On the Viability of Emulation for Kernelspace Fuzzing. In 13th USENIX Workshop on Offensive Technologies, WOOT 2019","author":"Maier Dominik","year":"2019","unstructured":"Dominik Maier , Benedikt Radtke , and Bastian Harren . 2019 . Unicorefuzz: On the Viability of Emulation for Kernelspace Fuzzing. In 13th USENIX Workshop on Offensive Technologies, WOOT 2019 , Santa Clara, CA, USA , August 12-13, 2019, Alex Gantman and Cl\u00e9mentine Maurice (Eds.). USENIX Association. https:\/\/www.usenix.org\/conference\/woot19\/presentation\/maier Dominik Maier, Benedikt Radtke, and Bastian Harren. 2019. Unicorefuzz: On the Viability of Emulation for Kernelspace Fuzzing. In 13th USENIX Workshop on Offensive Technologies, WOOT 2019, Santa Clara, CA, USA, August 12-13, 2019, Alex Gantman and Cl\u00e9mentine Maurice (Eds.). USENIX Association. https:\/\/www.usenix.org\/conference\/woot19\/presentation\/maier"},{"key":"e_1_3_2_1_35_1","unstructured":"Gy\u00f6rgy Miru. 2017. Path of Least Resistance: Cellular Baseband to Application Processor Escalation on Mediatek Devices. https:\/\/comsecuris.com\/blog\/posts\/path_of_least_resistance\/  Gy\u00f6rgy Miru. 2017. Path of Least Resistance: Cellular Baseband to Application Processor Escalation on Mediatek Devices. https:\/\/comsecuris.com\/blog\/posts\/path_of_least_resistance\/"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.14722\/bar.2018.23017"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23166"},{"key":"e_1_3_2_1_38_1","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment, Konrad Rieck, Patrick Stewin, and Jean-Pierre Seifert (Eds.)","author":"Mulliner Collin","unstructured":"Collin Mulliner , Ravishankar Borgaonkar , Patrick Stewin , and Jean-Pierre Seifert . 2013. SMS-Based One-Time Passwords: Attacks and Defense . In Detection of Intrusions and Malware, and Vulnerability Assessment, Konrad Rieck, Patrick Stewin, and Jean-Pierre Seifert (Eds.) . Springer Berlin Heidelberg , Berlin, Heidelberg , 150--159. Collin Mulliner, Ravishankar Borgaonkar, Patrick Stewin, and Jean-Pierre Seifert. 2013. SMS-Based One-Time Passwords: Attacks and Defense. In Detection of Intrusions and Malware, and Vulnerability Assessment, Konrad Rieck, Patrick Stewin, and Jean-Pierre Seifert (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 150--159."},{"key":"e_1_3_2_1_39_1","volume-title":"SMS of Death: from analyzing to attacking mobile phones on a large scale. USENIX Security","author":"Mulliner Collin","year":"2011","unstructured":"Collin Mulliner , Nico Golde , and Jean-Pierre Seifert . 2011. SMS of Death: from analyzing to attacking mobile phones on a large scale. USENIX Security ( 2011 ). http:\/\/static.usenix.org\/events\/sec11\/tech\/full{_}papers\/Mulliner.pdf Collin Mulliner, Nico Golde, and Jean-Pierre Seifert. 2011. SMS of Death: from analyzing to attacking mobile phones on a large scale. USENIX Security (2011). http:\/\/static.usenix.org\/events\/sec11\/tech\/full{_}papers\/Mulliner.pdf"},{"key":"e_1_3_2_1_40_1","volume-title":"Black Hat USA 2009","author":"Mulliner Collin","year":"2009","unstructured":"Collin Mulliner and Charlie Miller . 2009 . Fuzzing the Phone in your Phone . Black Hat USA 2009 (2009). https:\/\/www.blackhat.com\/presentations\/bh-usa-09\/MILLER\/BHUSA09-Miller-FuzzingPhone-PAPER.pdf Collin Mulliner and Charlie Miller. 2009. Fuzzing the Phone in your Phone. Black Hat USA 2009 (2009). https:\/\/www.blackhat.com\/presentations\/bh-usa-09\/MILLER\/BHUSA09-Miller-FuzzingPhone-PAPER.pdf"},{"key":"e_1_3_2_1_41_1","volume-title":"Unicorn: Next Generation CPU Emulator Framework","author":"Ngyuen Anh Quynh","year":"2020","unstructured":"Anh Quynh Ngyuen and Hoang Vu Dang . 2020 . Unicorn: Next Generation CPU Emulator Framework . http:\/\/www.unicorn-engine.org\/BHUSA2015-unicorn.pdf Anh Quynh Ngyuen and Hoang Vu Dang. 2020. Unicorn: Next Generation CPU Emulator Framework. http:\/\/www.unicorn-engine.org\/BHUSA2015-unicorn.pdf"},{"key":"e_1_3_2_1_42_1","unstructured":"OpenBTS. 2020. OpenBTS-UMTS. http:\/\/openbts.org\/w\/index.php?title=OpenBTS-UMTS  OpenBTS. 2020. OpenBTS-UMTS. http:\/\/openbts.org\/w\/index.php?title=OpenBTS-UMTS"},{"key":"e_1_3_2_1_43_1","unstructured":"Osmocom Project. 2020. Cellular Network Infrastructure. https:\/\/osmocom.org\/projects\/cellular-infrastructure\/wiki  Osmocom Project. 2020. Cellular Network Infrastructure. https:\/\/osmocom.org\/projects\/cellular-infrastructure\/wiki"},{"key":"e_1_3_2_1_44_1","unstructured":"P1 Security. 2020. P1 Telecom Fuzzer. https:\/\/www.p1sec.com\/corp\/products\/p1-telecom-fuzzer-ptf\/  P1 Security. 2020. P1 Telecom Fuzzer. https:\/\/www.p1sec.com\/corp\/products\/p1-telecom-fuzzer-ptf\/"},{"key":"e_1_3_2_1_45_1","volume-title":"SCAT: Signaling Collection and Analysis Tool. https:\/\/github.com\/fgsect\/scat","author":"Park Shinjo","year":"2017","unstructured":"Shinjo Park . 2017 . SCAT: Signaling Collection and Analysis Tool. https:\/\/github.com\/fgsect\/scat Shinjo Park. 2017. SCAT: Signaling Collection and Analysis Tool. https:\/\/github.com\/fgsect\/scat"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/2994459.2994465"},{"key":"e_1_3_2_1_47_1","volume-title":"On Security Research Towards Future Mobile Network Generations. (oct","author":"Rupprecht David","year":"2017","unstructured":"David Rupprecht , Adrian Dabrowski , Thorsten Holz , Edgar Weippl , and Christina P\u00f6pper . 2017. On Security Research Towards Future Mobile Network Generations. (oct 2017 ). arXiv:1710.08932 http:\/\/arxiv.org\/abs\/1710.08932 David Rupprecht, Adrian Dabrowski, Thorsten Holz, Edgar Weippl, and Christina P\u00f6pper. 2017. On Security Research Towards Future Mobile Network Generations. (oct 2017). arXiv:1710.08932 http:\/\/arxiv.org\/abs\/1710.08932"},{"key":"e_1_3_2_1_48_1","volume-title":"10th USENIX Workshop on Offensive Technologies (WOOT 16)","author":"Rupprecht David","year":"2016","unstructured":"David Rupprecht , Kai Jansen , and Christina P\u00f6pper . 2016 . Putting LTE Security Functions to the Test: A Framework to Evaluate Implementation Correctness . In 10th USENIX Workshop on Offensive Technologies (WOOT 16) . David Rupprecht, Kai Jansen, and Christina P\u00f6pper. 2016. Putting LTE Security Functions to the Test: A Framework to Evaluate Implementation Correctness. In 10th USENIX Workshop on Offensive Technologies (WOOT 16)."},{"key":"e_1_3_2_1_49_1","volume-title":"Breaking LTE on Layer Two. In 2019 IEEE Symposium on Security and Privacy (SP).","author":"Rupprecht David","year":"2019","unstructured":"David Rupprecht , Katharina Kohls , Thorsten Holz , and Christina P\u00f6pper . 2019 . Breaking LTE on Layer Two. In 2019 IEEE Symposium on Security and Privacy (SP). David Rupprecht, Katharina Kohls, Thorsten Holz, and Christina P\u00f6pper. 2019. Breaking LTE on Layer Two. In 2019 IEEE Symposium on Security and Privacy (SP)."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.23096"},{"key":"e_1_3_2_1_51_1","volume-title":"26th USENIX Security Symposium (USENIX Security 17)","author":"Schumilo Sergej","year":"2017","unstructured":"Sergej Schumilo , Cornelius Aschermann , Robert Gawlik , Sebastian Schinzel , and Thorsten Holz . 2017 . kAFL: Hardware-Assisted Feedback Fuzzing for OS Kernels . In 26th USENIX Security Symposium (USENIX Security 17) . USENIX Association, Vancouver, BC, 167--182. Sergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel, and Thorsten Holz. 2017. kAFL: Hardware-Assisted Feedback Fuzzing for OS Kernels. In 26th USENIX Security Symposium (USENIX Security 17). USENIX Association, Vancouver, BC, 167--182."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"crossref","unstructured":"Altaf Shaik Ravishankar Borgaonkar N. Asokan Valtteri Niemi and Jean-Pierre Seifert. 2015. Practical attacks against privacy and availability in 4G\/LTE mobile communication systems. (2015). http:\/\/arxiv.org\/abs\/1510.07563  Altaf Shaik Ravishankar Borgaonkar N. Asokan Valtteri Niemi and Jean-Pierre Seifert. 2015. Practical attacks against privacy and availability in 4G\/LTE mobile communication systems. (2015). http:\/\/arxiv.org\/abs\/1510.07563","DOI":"10.14722\/ndss.2016.23236"},{"key":"e_1_3_2_1_53_1","volume-title":"PeriScope: An Effective Probing and Fuzzing Framework for the Hardware-OS Boundary. In 26th Annual Network and Distributed System Security Symposium, NDSS 2019","author":"Song Dokyung","year":"2019","unstructured":"Dokyung Song , Felicitas Hetzelt , Dipanjan Das , Chad Spensky , Yeoul Na , Stijn Volckaert , Giovanni Vigna , Christopher Kruegel , Jean-Pierre Seifert , and Michael Franz . 2019 . PeriScope: An Effective Probing and Fuzzing Framework for the Hardware-OS Boundary. In 26th Annual Network and Distributed System Security Symposium, NDSS 2019 , San Diego, California, USA , February 24-27, 2019. The Internet Society. https:\/\/www.ndss-symposium.org\/ndss-paper\/periscope-an-effective-probing-and-fuzzing-framework-for-the-hardware-os-boundary\/ Dokyung Song, Felicitas Hetzelt, Dipanjan Das, Chad Spensky, Yeoul Na, Stijn Volckaert, Giovanni Vigna, Christopher Kruegel, Jean-Pierre Seifert, and Michael Franz. 2019. PeriScope: An Effective Probing and Fuzzing Framework for the Hardware-OS Boundary. In 26th Annual Network and Distributed System Security Symposium, NDSS 2019, San Diego, California, USA, February 24-27, 2019. The Internet Society. https:\/\/www.ndss-symposium.org\/ndss-paper\/periscope-an-effective-probing-and-fuzzing-framework-for-the-hardware-os-boundary\/"},{"key":"e_1_3_2_1_54_1","volume-title":"Ruhr-Universit\u00e4t Bochum","author":"Strobel Daehyun","year":"2007","unstructured":"Daehyun Strobel . 2007. IMSI Catcher . Chair for Communication Security , Ruhr-Universit\u00e4t Bochum ( 2007 ). Daehyun Strobel. 2007. IMSI Catcher. Chair for Communication Security, Ruhr-Universit\u00e4t Bochum (2007)."},{"key":"e_1_3_2_1_55_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Tian Dave Jing","year":"2018","unstructured":"Dave Jing Tian , Grant Hernandez , Joseph I Choi , Vanessa Frost , Christie Raules , Patrick Traynor , Hayawardh Vijayakumar , Lee Harrison , Amir Rahmati , Michael Grace , 2018 . ATtention Spanned: Comprehensive Vulnerability Analysis of {AT} Commands Within the Android Ecosystem . In 27th USENIX Security Symposium (USENIX Security 18) . 273--290. Dave Jing Tian, Grant Hernandez, Joseph I Choi, Vanessa Frost, Christie Raules, Patrick Traynor, Hayawardh Vijayakumar, Lee Harrison, Amir Rahmati, Michael Grace, et al. 2018. ATtention Spanned: Comprehensive Vulnerability Analysis of {AT} Commands Within the Android Ecosystem. In 27th USENIX Security Symposium (USENIX Security 18). 273--290."},{"key":"e_1_3_2_1_56_1","unstructured":"Nathan Voss. 2017. afl-unicorn: Fuzzing Arbitrary Binary Code. https:\/\/hackernoon.com\/afl-unicorn-fuzzing-arbitrary-binary-code-563ca28936bf  Nathan Voss. 2017. afl-unicorn: Fuzzing Arbitrary Binary Code. https:\/\/hackernoon.com\/afl-unicorn-fuzzing-arbitrary-binary-code-563ca28936bf"},{"key":"e_1_3_2_1_57_1","volume-title":"Baseband Attacks: Remote Exploitation of Memory Corruptions in Cellular Protocol Stacks. USENIX Workshop on Offensive Technologies","author":"Weinmann Ralf-Philipp","year":"2012","unstructured":"Ralf-Philipp Weinmann . 2012 . Baseband Attacks: Remote Exploitation of Memory Corruptions in Cellular Protocol Stacks. USENIX Workshop on Offensive Technologies (2012). Ralf-Philipp Weinmann. 2012. Baseband Attacks: Remote Exploitation of Memory Corruptions in Cellular Protocol Stacks. USENIX Workshop on Offensive Technologies (2012)."},{"key":"e_1_3_2_1_58_1","unstructured":"WikiChip. 2020. Helio X10 (MT6795) - MediaTek. https:\/\/en.wikichip.org\/wiki\/mediatek\/helio\/mt6795  WikiChip. 2020. Helio X10 (MT6795) - MediaTek. https:\/\/en.wikichip.org\/wiki\/mediatek\/helio\/mt6795"},{"key":"e_1_3_2_1_59_1","unstructured":"Ben Wojtowicz. [n.d.]. OpenLTE. http:\/\/openlte.sourceforge.net\/  Ben Wojtowicz. [n.d.]. OpenLTE. http:\/\/openlte.sourceforge.net\/"},{"key":"e_1_3_2_1_60_1","unstructured":"Michael Zalewski. 2016. Technical \"whitepaper\" for AFL-fuzz. http:\/\/lcamtuf.coredump.cx\/afl\/  Michael Zalewski. 2016. Technical \"whitepaper\" for AFL-fuzz. http:\/\/lcamtuf.coredump.cx\/afl\/"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2851237"}],"event":{"name":"WiSec '20: 13th ACM Conference on Security and Privacy in Wireless and Mobile Networks","location":"Linz Austria","acronym":"WiSec '20","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control","SIGMOBILE ACM Special Interest Group on Mobility of Systems, Users, Data and Computing"]},"container-title":["Proceedings of the 13th ACM Conference on Security and Privacy in Wireless and Mobile Networks"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3395351.3399360","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3395351.3399360","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T18:38:34Z","timestamp":1750185514000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3395351.3399360"}},"subtitle":["baseband sanitized fuzzing through emulation"],"short-title":[],"issued":{"date-parts":[[2020,7,8]]},"references-count":60,"alternative-id":["10.1145\/3395351.3399360","10.1145\/3395351"],"URL":"https:\/\/doi.org\/10.1145\/3395351.3399360","relation":{},"subject":[],"published":{"date-parts":[[2020,7,8]]},"assertion":[{"value":"2020-07-21","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}