{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T16:14:10Z","timestamp":1783008850519,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":37,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,5,24]],"date-time":"2021-05-24T00:00:00Z","timestamp":1621814400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"ONR","award":["N00014-17-1-2011"],"award-info":[{"award-number":["N00014-17-1-2011"]}]},{"name":"DHS","award":["FA8750-19-2-0005"],"award-info":[{"award-number":["FA8750-19-2-0005"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,5,24]]},"DOI":"10.1145\/3433210.3437532","type":"proceedings-article","created":{"date-parts":[[2021,6,4]],"date-time":"2021-06-04T15:26:39Z","timestamp":1622820399000},"page":"95-109","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":18,"title":["Conware: Automated Modeling of Hardware Peripherals"],"prefix":"10.1145","author":[{"given":"Chad","family":"Spensky","sequence":"first","affiliation":[{"name":"Allthenticate, University of California, Santa Barbara &amp; Massachusetts Institute of Technology, Goleta, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Aravind","family":"Machiry","sequence":"additional","affiliation":[{"name":"Purdue University, West Lafayette, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nilo","family":"Redini","sequence":"additional","affiliation":[{"name":"University of California, Santa Barbara, Goleta, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Colin","family":"Unger","sequence":"additional","affiliation":[{"name":"University of California, Santa Barbara, Goleta, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Graham","family":"Foster","sequence":"additional","affiliation":[{"name":"University of California, Santa Barbara, Goleta, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Evan","family":"Blasband","sequence":"additional","affiliation":[{"name":"Allthenticate &amp; University of California, Santa Barbara, Goleta, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hamed","family":"Okhravi","sequence":"additional","affiliation":[{"name":"Massachusetts Institute of Technology, Lexinton, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christopher","family":"Kruegel","sequence":"additional","affiliation":[{"name":"University of California, Santa Barbara, Goleta, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Giovanni","family":"Vigna","sequence":"additional","affiliation":[{"name":"University of California, Santa Barbara, Goleta, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,6,4]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Open Review Mobicomm 2020. [n.d.]. Device-agnostic Firmware Execution is Possible: A Concolic Execution Approach for Peripheral Emulation. https:\/\/openreview.net\/pdf?id=rylaZ6iIDr.  Open Review Mobicomm 2020. [n.d.]. Device-agnostic Firmware Execution is Possible: A Concolic Execution Approach for Peripheral Emulation. https:\/\/openreview.net\/pdf?id=rylaZ6iIDr."},{"key":"e_1_3_2_1_2_1","unstructured":"Altium. 2017. NEC Infrared Transmission Protocol. https:\/\/techdocs.altium.com\/ display\/FPGA\/NEC+Infrared+Transmission+Protocol.  Altium. 2017. NEC Infrared Transmission Protocol. https:\/\/techdocs.altium.com\/ display\/FPGA\/NEC+Infrared+Transmission+Protocol."},{"key":"e_1_3_2_1_3_1","unstructured":"Atmel. 2015. SAM3X\/ SAM3A Series (DATASHEET). https:\/\/ww1.microchip.com\/ downloads\/en\/DeviceDoc\/Atmel-11057--32-bit-Cortex-M3-Microcontroller-SAM3X-SAM3A_Datasheet.pdf.  Atmel. 2015. SAM3X\/ SAM3A Series (DATASHEET). https:\/\/ww1.microchip.com\/ downloads\/en\/DeviceDoc\/Atmel-11057--32-bit-Cortex-M3-Microcontroller-SAM3X-SAM3A_Datasheet.pdf."},{"key":"e_1_3_2_1_4_1","unstructured":"BARRAGAN. 2013. Sweep. https:\/\/www.arduino.cc\/en\/Tutorial\/Sweep.  BARRAGAN. 2013. Sweep. https:\/\/www.arduino.cc\/en\/Tutorial\/Sweep."},{"key":"e_1_3_2_1_5_1","volume-title":"USENIX Annual Technical Conference, FREENIX Track","volume":"41","author":"Bellard Fabrice","year":"2005","unstructured":"Fabrice Bellard . 2005 . QEMU, a fast and portable dynamic translator .. In USENIX Annual Technical Conference, FREENIX Track , Vol. 41 . 46. Fabrice Bellard. 2005. QEMU, a fast and portable dynamic translator.. In USENIX Annual Technical Conference, FREENIX Track, Vol. 41. 46."},{"key":"e_1_3_2_1_6_1","unstructured":"Jacob Beningo. 2016. Prototype to production: Arduino for the professional. https:\/\/www.edn.com\/prototype-to-production-arduino-for-the-professional\/.  Jacob Beningo. 2016. Prototype to production: Arduino for the professional. https:\/\/www.edn.com\/prototype-to-production-arduino-for-the-professional\/."},{"key":"e_1_3_2_1_7_1","unstructured":"Duane Benson. 2015. Arduino as a rapid prototyping system. https:\/\/www.embedded.com\/arduino-as-a-rapid-prototyping-system\/.  Duane Benson. 2015. Arduino as a rapid prototyping system. https:\/\/www.embedded.com\/arduino-as-a-rapid-prototyping-system\/."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46298-1"},{"key":"e_1_3_2_1_9_1","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX '20)","author":"Clements Abraham","year":"2020","unstructured":"Abraham Clements , Eric Gustafson , Tobias Scharnowski , Paul Grosen , David Fritz , Christopher Kruegel , Giovanni Vigna , Saurabh Bagchi , and Mathias Payer . 2020 . HALucinator: Firmware Re-hosting through Abstraction Layer Emulation . Proceedings of the 29th USENIX Security Symposium (USENIX '20) (2020). Abraham Clements, Eric Gustafson, Tobias Scharnowski, Paul Grosen, David Fritz, Christopher Kruegel, Giovanni Vigna, Saurabh Bagchi, and Mathias Payer. 2020. HALucinator: Firmware Re-hosting through Abstraction Layer Emulation. Proceedings of the 29th USENIX Security Symposium (USENIX '20) (2020)."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCE.2015.7389814"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/2843859.2843867"},{"key":"e_1_3_2_1_12_1","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX'20)","author":"Feng Bo","year":"2020","unstructured":"Bo Feng , Alejandro Mera , and Long Lu . 2020 . P2IM: Scalable and Hardware independentFirmware Testing via Automatic Peripheral Interface Modeling (extended version) . Proceedings of the 29th USENIX Security Symposium (USENIX'20) (2020). Bo Feng, Alejandro Mera, and Long Lu. 2020. P2IM: Scalable and Hardware independentFirmware Testing via Automatic Peripheral Interface Modeling (extended version). Proceedings of the 29th USENIX Security Symposium (USENIX'20) (2020)."},{"key":"e_1_3_2_1_13_1","volume-title":"The Firmware Handbook","author":"Ganssle Jack","unstructured":"Jack Ganssle . 2004. Reentrancy . In The Firmware Handbook . Elsevier , 231--244. Jack Ganssle. 2004. Reentrancy. In The Firmware Handbook. Elsevier, 231--244."},{"key":"e_1_3_2_1_14_1","unstructured":"Geeetech. 2012. Arduino IR Remote Control. http:\/\/www.geeetech.com\/wiki\/index.php\/Arduino_IR_Remote_Control.  Geeetech. 2012. Arduino IR Remote Control. http:\/\/www.geeetech.com\/wiki\/index.php\/Arduino_IR_Remote_Control."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.sysarc.2012.06.003"},{"key":"e_1_3_2_1_16_1","first-page":"59","article-title":"Advanced hardware hacking techniques","volume":"12","author":"Grand Joe","year":"2004","unstructured":"Joe Grand and July Friday . 2004 . Advanced hardware hacking techniques . DEFCON 12 (2004), 59 . Joe Grand and July Friday. 2004. Advanced hardware hacking techniques. DEFCON 12 (2004), 59.","journal-title":"DEFCON"},{"key":"e_1_3_2_1_17_1","volume-title":"22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID","author":"Gustafson Eric","year":"2019","unstructured":"Eric Gustafson , Marius Muench , Chad Spensky , Nilo Redini , Aravind Machiry , Yanick Fratantonio , Davide Balzarotti , Aurelien Francillon , Yung Ryn Choe , Christophe Kruegel , 2019 . Toward the Analysis of Embedded Firmware through Automated Re-hosting . In 22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2019). 135--150. Eric Gustafson, Marius Muench, Chad Spensky, Nilo Redini, Aravind Machiry, Yanick Fratantonio, Davide Balzarotti, Aurelien Francillon, Yung Ryn Choe, Christophe Kruegel, et al. 2019. Toward the Analysis of Embedded Firmware through Automated Re-hosting. In 22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2019). 135--150."},{"key":"e_1_3_2_1_18_1","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX '20)","author":"Harrison Lee","year":"2020","unstructured":"Lee Harrison , Hayawardh Vijayakumar , Rohan Padhye , Koushik Sen , Michael Grace , Rohan Padhye , Caroline Lemieux , Koushik Sen , Laurent Simon , Hayawardh Vijayakumar , 2020 . Partemu: Enabling dynamic analysis of real-world trustzone software using emulation . In Proceedings of the 29th USENIX Security Symposium (USENIX '20) . Lee Harrison, Hayawardh Vijayakumar, Rohan Padhye, Koushik Sen, Michael Grace, Rohan Padhye, Caroline Lemieux, Koushik Sen, Laurent Simon, Hayawardh Vijayakumar, et al. 2020. Partemu: Enabling dynamic analysis of real-world trustzone software using emulation. In Proceedings of the 29th USENIX Security Symposium (USENIX '20)."},{"key":"e_1_3_2_1_19_1","volume-title":"Theory of machines and computations","author":"Hopcroft John","unstructured":"John Hopcroft . 1971. An n log n algorithm for minimizing states in a finite automaton . In Theory of machines and computations . Elsevier , 189--196. John Hopcroft. 1971. An n log n algorithm for minimizing states in a finite automaton. In Theory of machines and computations. Elsevier, 189--196."},{"key":"e_1_3_2_1_20_1","volume-title":"10th International Conference on Emerging Security Information, Systems and Technologies (SECUWARE).","author":"Kammerstetter Markus","year":"2016","unstructured":"Markus Kammerstetter , Daniel Burian , and Wolfgang Kastner . 2016 . Embedded security testing with peripheral device caching and runtime program state approximation . In 10th International Conference on Emerging Security Information, Systems and Technologies (SECUWARE). Markus Kammerstetter, Daniel Burian, and Wolfgang Kastner. 2016. Embedded security testing with peripheral device caching and runtime program state approximation. In 10th International Conference on Emerging Security Information, Systems and Technologies (SECUWARE)."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/2590296.2590301"},{"key":"e_1_3_2_1_22_1","volume-title":"9th USENIX Workshop on Offensive Technologies (WOOT '15)","author":"Koscher Karl","year":"2015","unstructured":"Karl Koscher , Tadayoshi Kohno , and David Molnar . 2015 . SURROGATES: Enabling near-real-time dynamic analyses of embedded systems . In 9th USENIX Workshop on Offensive Technologies (WOOT '15) . Karl Koscher, Tadayoshi Kohno, and David Molnar. 2015. SURROGATES: Enabling near-real-time dynamic analyses of embedded systems. In 9th USENIX Workshop on Offensive Technologies (WOOT '15)."},{"key":"e_1_3_2_1_23_1","volume-title":"The BSD conference","volume":"5","author":"Lattner Chris","year":"2008","unstructured":"Chris Lattner . 2008 . LLVM and Clang: Next generation compiler technology . In The BSD conference , Vol. 5 . Chris Lattner. 2008. LLVM and Clang: Next generation compiler technology. In The BSD conference, Vol. 5."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/CGO.2004.1281665"},{"key":"e_1_3_2_1_25_1","unstructured":"ARM Limited. 2010. Cortex-M3 Technical Reference Manual (Revision r2p1). http:\/\/users.ece.utexas.edu\/~valvano\/EE345L\/Labs\/Fall2011\/CortexM3_ TRM_r2p1.pdf.  ARM Limited. 2010. Cortex-M3 Technical Reference Manual (Revision r2p1). http:\/\/users.ece.utexas.edu\/~valvano\/EE345L\/Labs\/Fall2011\/CortexM3_ TRM_r2p1.pdf."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.982916"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.14722\/bar.2018.23017"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23166"},{"key":"e_1_3_2_1_29_1","unstructured":"Osbourne Paul. [n.d.]. CMSIS-SVD Repository and Parsers. https:\/\/github.com\/ posborne\/cmsis-svd.  Osbourne Paul. [n.d.]. CMSIS-SVD Repository and Parsers. https:\/\/github.com\/ posborne\/cmsis-svd."},{"key":"e_1_3_2_1_30_1","unstructured":"Ivan Pustogarov Qian Wu and David Lie. [n.d.]. Ex-vivo dynamic analysis framework for Android device drivers. ([n. d.]).  Ivan Pustogarov Qian Wu and David Lie. [n.d.]. Ex-vivo dynamic analysis framework for Android device drivers. ([n. d.])."},{"key":"e_1_3_2_1_31_1","volume-title":"KARONTE: Detecting Insecure Multi-binary Interactions in Embedded Firmware. In 2020 IEEE Symposium on Security and Privacy (SP). 431--448","author":"Redini Nilo","year":"2020","unstructured":"Nilo Redini , Aravind Machiry , Ruoyu Wang , Chad Spensky , Andrea Continella , Yan Shoshitaishvili , Christopher Kruegel , and Giovanni Vigna . 2020 . KARONTE: Detecting Insecure Multi-binary Interactions in Embedded Firmware. In 2020 IEEE Symposium on Security and Privacy (SP). 431--448 . Nilo Redini, Aravind Machiry, Ruoyu Wang, Chad Spensky, Andrea Continella, Yan Shoshitaishvili, Christopher Kruegel, and Giovanni Vigna. 2020. KARONTE: Detecting Insecure Multi-binary Interactions in Embedded Firmware. In 2020 IEEE Symposium on Security and Privacy (SP). 431--448."},{"key":"e_1_3_2_1_32_1","unstructured":"Miro Samek. 2016. State Machines for Event-Driven Systems. https:\/\/barrgroup. com\/embedded-systems\/how-to\/state-machines-event-driven-systems.  Miro Samek. 2016. State Machines for Event-Driven Systems. https:\/\/barrgroup. com\/embedded-systems\/how-to\/state-machines-event-driven-systems."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.17"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23176"},{"key":"e_1_3_2_1_35_1","volume-title":"27th USENIX Security Symposium (USENIX '18)","author":"Seyed Talebi Seyed Mohammadjavad","year":"2018","unstructured":"Seyed Mohammadjavad Seyed Talebi , Hamid Tavakoli , Hang Zhang , Zheng Zhang , Ardalan Amiri Sani , and Zhiyun Qian . 2018 . Charm: Facilitating dynamic analysis of device drivers of mobile systems . In 27th USENIX Security Symposium (USENIX '18) . 291--307. Seyed Mohammadjavad Seyed Talebi, Hamid Tavakoli, Hang Zhang, Zheng Zhang, Ardalan Amiri Sani, and Zhiyun Qian. 2018. Charm: Facilitating dynamic analysis of device drivers of mobile systems. In 27th USENIX Security Symposium (USENIX '18). 291--307."},{"key":"e_1_3_2_1_36_1","unstructured":"LLC. Where Labs. 2019. Bus Pirate. http:\/\/dangerousprototypes.com\/docs\/Bus_Pirate.  LLC. Where Labs. 2019. Bus Pirate. http:\/\/dangerousprototypes.com\/docs\/Bus_Pirate."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23229"}],"event":{"name":"ASIA CCS '21: ACM Asia Conference on Computer and Communications Security","location":"Virtual Event Hong Kong","acronym":"ASIA CCS '21","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3433210.3437532","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/abs\/10.1145\/3433210.3437532","content-type":"text\/html","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3433210.3437532","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3433210.3437532","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:48:11Z","timestamp":1750193291000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3433210.3437532"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,5,24]]},"references-count":37,"alternative-id":["10.1145\/3433210.3437532","10.1145\/3433210"],"URL":"https:\/\/doi.org\/10.1145\/3433210.3437532","relation":{},"subject":[],"published":{"date-parts":[[2021,5,24]]},"assertion":[{"value":"2021-06-04","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}