{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T17:01:13Z","timestamp":1783098073607,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":94,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T00:00:00Z","timestamp":1638748800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100000266","name":"Engineering and Physical Sciences Research Council","doi-asserted-by":"publisher","award":["EP\/P009301\/1"],"award-info":[{"award-number":["EP\/P009301\/1"]}],"id":[{"id":"10.13039\/501100000266","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,12,6]]},"DOI":"10.1145\/3485832.3488007","type":"proceedings-article","created":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T13:42:32Z","timestamp":1638798152000},"page":"861-876","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["argXtract: Deriving IoT Security Configurations via Automated Static Analysis of Stripped ARM Cortex-M Binaries"],"prefix":"10.1145","author":[{"given":"Pallavi","family":"Sivakumaran","sequence":"first","affiliation":[{"name":"Royal Holloway, University of London, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jorge","family":"Blasco","sequence":"additional","affiliation":[{"name":"Royal Holloway, University of London, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,12,6]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2901739.2903508"},{"key":"e_1_3_2_1_2_1","unstructured":"Sergi Alvarez. 2021. radare2. https:\/\/github.com\/radareorg\/radare2."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359825"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2017.11"},{"key":"e_1_3_2_1_5_1","volume-title":"26th USENIX security symposium (USENIX Security 17). 1093\u20131110.","author":"Antonakakis Manos","unstructured":"Manos Antonakakis, Tim April, Michael Bailey, Matt Bernhard, Elie Bursztein, Jaime Cochran, Zakir Durumeric, J\u00a0Alex Halderman, Luca Invernizzi, Michalis Kallitsis, 2017. Understanding the Mirai botnet. In 26th USENIX security symposium (USENIX Security 17). 1093\u20131110."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394497"},{"key":"e_1_3_2_1_7_1","volume-title":"Supervisor calls. Available: https:\/\/developer.arm.com\/documentation\/dui0471\/g\/handling-processor-exceptions\/supervisor-calls[Accessed","author":"ARM.","year":"2020","unstructured":"ARM. 2012. Supervisor calls. Available: https:\/\/developer.arm.com\/documentation\/dui0471\/g\/handling-processor-exceptions\/supervisor-calls[Accessed: 28 July 2020]."},{"key":"e_1_3_2_1_8_1","volume-title":"Calling SVCs from an application. Available: https:\/\/developer.arm.com\/documentation\/dui0471\/m\/handling-processor-exceptions\/calling-svcs-from-an-application [Accessed","author":"ARM.","year":"2020","unstructured":"ARM. 2016. Calling SVCs from an application. Available: https:\/\/developer.arm.com\/documentation\/dui0471\/m\/handling-processor-exceptions\/calling-svcs-from-an-application [Accessed: 28 July 2020]."},{"key":"e_1_3_2_1_9_1","volume-title":"Record shipments of Arm-based chips in previous quarter. Available: https:\/\/www.arm.com\/company\/news\/2020\/02\/record-shipments-of-arm-based-chips-in-previous-quarter[Accessed","year":"2020","unstructured":"Arm. 2020. Record shipments of Arm-based chips in previous quarter. Available: https:\/\/www.arm.com\/company\/news\/2020\/02\/record-shipments-of-arm-based-chips-in-previous-quarter[Accessed: 28 June 2020]."},{"key":"e_1_3_2_1_10_1","volume-title":"Vector table. Available: https:\/\/developer.arm.com\/documentation\/dui0552\/a\/the-cortex-m3-processor\/exception-model\/vector-table[Accessed","author":"ARM.","year":"2020","unstructured":"ARM. 2021. Vector table. Available: https:\/\/developer.arm.com\/documentation\/dui0552\/a\/the-cortex-m3-processor\/exception-model\/vector-table[Accessed: 03 July 2020]."},{"key":"e_1_3_2_1_11_1","volume-title":"23rd USENIX Security Symposium (USENIX Security 14)","author":"Bao Tiffany","year":"2014","unstructured":"Tiffany Bao, Jonathan Burket, Maverick Woo, Rafael Turner, and David Brumley. 2014. BYTEWEIGHT: Learning to recognize functions in binary code. In 23rd USENIX Security Symposium (USENIX Security 14). 845\u2013860."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0036"},{"key":"e_1_3_2_1_13_1","volume-title":"USENIX Annual Technical Conference, FREENIX Track, Vol.\u00a041","author":"Bellard Fabrice","year":"2005","unstructured":"Fabrice Bellard. 2005. QEMU, a fast and portable dynamic translator.. In USENIX Annual Technical Conference, FREENIX Track, Vol.\u00a041. 46."},{"key":"e_1_3_2_1_14_1","unstructured":"Bluetooth Special Interest Group. 2019. 2019 Bluetooth Market Update. Available: https:\/\/www.bluetooth.com\/bluetooth-resources\/2019-bluetooth-market-update[Accessed 01-Feb-2021]."},{"key":"e_1_3_2_1_15_1","unstructured":"Bluetooth Special Interest Group. 2019. Bluetooth Core Specification v5.2."},{"key":"e_1_3_2_1_16_1","volume-title":"Intro to Bluetooth Low Energy. Available: https:\/\/www.bluetooth.com\/bluetooth-resources\/intro-to-bluetooth-low-energy\/[Accessed","author":"Bluetooth Special Interest Group","year":"2020","unstructured":"Bluetooth Special Interest Group. 2019. Intro to Bluetooth Low Energy. Available: https:\/\/www.bluetooth.com\/bluetooth-resources\/intro-to-bluetooth-low-energy\/[Accessed: 27 July 2020]."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2430553.2430557"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-22110-1_37"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3360774.3360777"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"crossref","unstructured":"Daming\u00a0D Chen Maverick Woo David Brumley and Manuel Egele. 2016. Towards Automated Dynamic Analysis for Linux-based Embedded Firmware. In NDSS Vol.\u00a016. 1\u201316.","DOI":"10.14722\/ndss.2016.23415"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Jiongyi Chen Wenrui Diao Qingchuan Zhao Chaoshun Zuo Zhiqiang Lin XiaoFeng Wang Wing\u00a0Cheong Lau Menghan Sun Ronghai Yang and Kehuan Zhang. 2018. IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based Fuzzing.. In NDSS.","DOI":"10.14722\/ndss.2018.23159"},{"key":"e_1_3_2_1_22_1","volume-title":"Finns chilling as DDoS knocks out building control system. Available: https:\/\/www.theregister.com\/2016\/11\/09\/finns_chilling_as_ddos_knocks_out_building_control_system. [Accessed","author":"Chirgwin Richard","year":"2020","unstructured":"Richard Chirgwin. 2016. Finns chilling as DDoS knocks out building control system. Available: https:\/\/www.theregister.com\/2016\/11\/09\/finns_chilling_as_ddos_knocks_out_building_control_system. [Accessed: 11 June 2020]."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3191737"},{"key":"e_1_3_2_1_24_1","volume-title":"23rd USENIX Security Symposium (USENIX Security 14)","author":"Costin Andrei","year":"2014","unstructured":"Andrei Costin, Jonas Zaddach, Aur\u00e9lien Francillon, and Davide Balzarotti. 2014. A large-scale analysis of the security of embedded firmwares. In 23rd USENIX Security Symposium (USENIX Security 14). 95\u2013110."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2897845.2897900"},{"key":"e_1_3_2_1_26_1","volume-title":"Security Analysis of Wearable Fitness Devices (Fitbit)","author":"Cyr Britt","year":"2014","unstructured":"Britt Cyr, Webb Horn, Daniela Miao, and Michael Specter. 2014. Security Analysis of Wearable Fitness Devices (Fitbit). Massachusetts Institute of Technology(2014)."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/2873587.2873594"},{"key":"e_1_3_2_1_28_1","volume-title":"22nd USENIX Security Symposium (USENIX Security 13)","author":"Davidson Drew","year":"2013","unstructured":"Drew Davidson, Benjamin Moench, Thomas Ristenpart, and Somesh Jha. 2013. FIE on firmware: Finding vulnerabilities in embedded systems using symbolic execution. In 22nd USENIX Security Symposium (USENIX Security 13). 463\u2013478."},{"key":"e_1_3_2_1_29_1","volume-title":"Proceedings of the 26th International Conference on Compiler Construction.","author":"Di\u00a0Federico Alessandro","unstructured":"Alessandro Di\u00a0Federico, Mathias Payer, and Giovanni Agosta. [n. d.]. rev. ng: a unified binary analysis framework to recover CFGs and function boundaries. In Proceedings of the 26th International Conference on Compiler Construction."},{"key":"e_1_3_2_1_30_1","volume-title":"23rd {USENIX} Security Symposium ({USENIX} Security 14). 303\u2013317.","author":"Egele Manuel","unstructured":"Manuel Egele, Maverick Woo, Peter Chapman, and David Brumley. 2014. Blanket execution: Dynamic similarity testing for program binaries and components. In 23rd {USENIX} Security Symposium ({USENIX} Security 14). 303\u2013317."},{"key":"e_1_3_2_1_31_1","volume-title":"25th {USENIX} Security Symposium ({USENIX} Security 16). 1205\u20131221.","author":"Fawaz Kassem","unstructured":"Kassem Fawaz, Kyu-Han Kim, and Kang\u00a0G Shin. 2016. Protecting privacy of {BLE} device users. In 25th {USENIX} Security Symposium ({USENIX} Security 16). 1205\u20131221."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"crossref","unstructured":"Jan Friebertsh\u00e4user Florian Kosterhon Jiska Classen and Matthias Hollick. 2020. Polypyus\u2013The Firmware Historian.","DOI":"10.14722\/bar.2021.23004"},{"key":"e_1_3_2_1_33_1","volume-title":"What is ANT+. Available: https:\/\/www.thisisant.com\/consumer\/ant-101\/what-is-ant [Accessed","author":"Garmin Canada Inc.","year":"2020","unstructured":"Garmin Canada Inc.2020. What is ANT+. Available: https:\/\/www.thisisant.com\/consumer\/ant-101\/what-is-ant [Accessed: 27 July 2020]."},{"key":"e_1_3_2_1_34_1","volume-title":"What kind of security does ANT provide?Available: https:\/\/www.thisisant.com\/developer\/resources\/tech-faq\/what-kind-of-security-does-ant-provide-1[Accessed","author":"Garmin Canada Inc.","year":"2020","unstructured":"Garmin Canada Inc.2020. What kind of security does ANT provide?Available: https:\/\/www.thisisant.com\/developer\/resources\/tech-faq\/what-kind-of-security-does-ant-provide-1[Accessed: 07 Dec 2020]."},{"key":"e_1_3_2_1_35_1","volume-title":"COMPCON\u201996. Technologies for the Information Superhighway Digest of Papers","author":"Goudge Liam","unstructured":"Liam Goudge and Simon Segars. 1996. Thumb: reducing the cost of 32-bit RISC performance in portable and consumer applications. In COMPCON\u201996. Technologies for the Information Superhighway Digest of Papers. IEEE, 176\u2013181."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/1127577.1127590"},{"key":"e_1_3_2_1_37_1","volume-title":"Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security.","author":"He Jingxuan","unstructured":"Jingxuan He, Pesho Ivanov, Petar Tsankov, Veselin Raychev, and Martin Vechev. [n. d.]. Debin: Predicting debug information in stripped binaries. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security."},{"key":"e_1_3_2_1_38_1","volume-title":"IDA pro disassembler. Available: https:\/\/www.hex-rays.com\/products\/ida\/support\/download_freeware\/. [Accessed","year":"2021","unstructured":"Hex-Rays. 2021. IDA pro disassembler. Available: https:\/\/www.hex-rays.com\/products\/ida\/support\/download_freeware\/. [Accessed: 31 Jan 2021]."},{"key":"e_1_3_2_1_39_1","unstructured":"Andrew Hilts Christopher Parsons and Jeffrey Knockel. 2016. Every Step You Fake: A Comparative Analysis of Fitness Tracker Privacy and Security. (2016)."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/NEXTCOMP.2017.8016185"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3395363.3397377"},{"key":"e_1_3_2_1_42_1","volume-title":"ICSREF: A framework for automated reverse engineering of industrial control systems binaries. arXiv preprint arXiv:1812.03478(2018).","author":"Keliris Anastasis","year":"2018","unstructured":"Anastasis Keliris and Michail Maniatakos. 2018. ICSREF: A framework for automated reverse engineering of industrial control systems binaries. arXiv preprint arXiv:1812.03478(2018)."},{"key":"e_1_3_2_1_43_1","volume-title":"Case Study: Security of Modern Bluetooth Keyboards.","author":"Klostermeier Gerhard","year":"2018","unstructured":"Gerhard Klostermeier and Matthias Deeg. 2018. Case Study: Security of Modern Bluetooth Keyboards. (2018). Available: https:\/\/www.syss.de\/fileadmin\/dokumente\/Publikationen\/2018\/Security_of_Modern_Bluetooth_Keyboards.pdf[Accessed: 30 Nov 2020]."},{"key":"e_1_3_2_1_44_1","unstructured":"Jesse Kornblum Helmut Grohne and Tsukasa OI. 2021. ssdeep - Fuzzy hashing program. Available: https:\/\/ssdeep-project.github.io\/ssdeep\/index.html[Accessed 16-Mar-2021]."},{"key":"e_1_3_2_1_45_1","volume-title":"FDA confirms that St. Jude\u2019s cardiac devices can be hacked. Available: https:\/\/money.cnn.com\/2017\/01\/09\/technology\/fda-st-jude-cardiac-hack. [Accessed","author":"Larson Selena","year":"2020","unstructured":"Selena Larson. 2017. FDA confirms that St. Jude\u2019s cardiac devices can be hacked. Available: https:\/\/money.cnn.com\/2017\/01\/09\/technology\/fda-st-jude-cardiac-hack. [Accessed: 11 June 2020]."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/2513228.2513300"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/3139937.3139938"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3307334.3326089"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-22038-9_15"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1002\/9781119051091"},{"key":"e_1_3_2_1_51_1","volume-title":"Available: https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2015-2880 [Accessed","year":"2020","unstructured":"Mitre. 2015. CVE-2015-2880. Available: https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2015-2880 [Accessed: 14 July 2020]."},{"key":"e_1_3_2_1_52_1","volume-title":"Available: https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-10825[Accessed","year":"2020","unstructured":"Mitre. 2018. CVE-2018-10825. Available: https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-10825[Accessed: 14 July 2020]."},{"key":"e_1_3_2_1_53_1","volume-title":"Available: https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-16518[Accessed","year":"2020","unstructured":"Mitre. 2019. CVE-2019-16518. Available: https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-16518[Accessed: 14 July 2020]."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/1066677.1066753"},{"key":"e_1_3_2_1_55_1","unstructured":"National Security Agency. 2020. Ghidra. https:\/\/github.com\/NationalSecurityAgency\/ghidra."},{"key":"e_1_3_2_1_56_1","unstructured":"Nordic Semiconductor. 2020. nRF Connect for Mobile. https:\/\/www.nordicsemi.com\/Software-and-tools\/Development-Tools\/nRF-Connect-for-mobile."},{"key":"e_1_3_2_1_57_1","volume-title":"Available: https:\/\/infocenter.nordicsemi.com\/index.jsp?topic=%2Fug_gsg_ses%2FUG%2Fgsg%2Fsoftdevices.html[Accessed","author":"SoftDevices Nordic Semiconductor ASA.","year":"2020","unstructured":"Nordic Semiconductor ASA. 2020. SoftDevices. Available: https:\/\/infocenter.nordicsemi.com\/index.jsp?topic=%2Fug_gsg_ses%2FUG%2Fgsg%2Fsoftdevices.html[Accessed: 03 July 2020]."},{"key":"e_1_3_2_1_58_1","volume-title":"Probabilistic Naming of Functions in Stripped Binaries. In Annual Computer Security Applications Conference. 373\u2013385","author":"Patrick-Evans James","year":"2020","unstructured":"James Patrick-Evans, Lorenzo Cavallaro, and Johannes Kinder. 2020. Probabilistic Naming of Functions in Stripped Binaries. In Annual Computer Security Applications Conference. 373\u2013385."},{"key":"e_1_3_2_1_59_1","volume-title":"USENIX Annual Technical Conference, General Track. 211\u2013224","author":"Prasad Manish","year":"2003","unstructured":"Manish Prasad and Tzi-cker Chiueh. 2003. A Binary Rewriting Defense Against Stack based Buffer Overflow Attacks.. In USENIX Annual Technical Conference, General Track. 211\u2013224."},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/3432893"},{"key":"e_1_3_2_1_61_1","volume-title":"2017 47th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN).","author":"Qiao Rui","unstructured":"Rui Qiao and R Sekar. [n. d.]. Function interface analysis: A principled approach for function recognition in COTS binaries. In 2017 47th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN)."},{"key":"e_1_3_2_1_62_1","volume-title":"Capstone: The Ultimate Disassembler. https:\/\/www.capstone-engine.org.","author":"Quynh Nguyen\u00a0Anh","year":"2020","unstructured":"Nguyen\u00a0Anh Quynh. 2020. Capstone: The Ultimate Disassembler. https:\/\/www.capstone-engine.org."},{"key":"e_1_3_2_1_63_1","volume-title":"Unicorn The Ultimate CPU emulator. Available: https:\/\/www.unicorn-engine.org [Accessed:25","author":"Quynh Nguyen\u00a0Anh","year":"2020","unstructured":"Nguyen\u00a0Anh Quynh. 2020. Unicorn The Ultimate CPU emulator. Available: https:\/\/www.unicorn-engine.org [Accessed:25 Oct 2020]."},{"key":"e_1_3_2_1_64_1","volume-title":"Results In PDoS Attack. Available: https:\/\/security.radware.com\/ddos-threats-attacks\/brickerbot-pdos-permanent-denial-of-service\/. [Accessed","year":"2020","unstructured":"Radware. 2006. \u2018BrickerBot\u2019 Results In PDoS Attack. Available: https:\/\/security.radware.com\/ddos-threats-attacks\/brickerbot-pdos-permanent-denial-of-service\/. [Accessed: 11 June 2020]."},{"key":"e_1_3_2_1_65_1","unstructured":"Giridhar Ravipati Andrew\u00a0R Bernat Nate Rosenblum Barton\u00a0P Miller and Jeffrey\u00a0K Hollingsworth. 2007. Toward the deconstruction of Dyninst. Univ. of Wisconsin technical report(2007) 32."},{"key":"e_1_3_2_1_66_1","unstructured":"Nathan\u00a0E Rosenblum Xiaojin Zhu Barton\u00a0P Miller and Karen Hunt. 2008. Learning to Analyze Binary Computer Code.. In AAAI. 798\u2013804."},{"key":"e_1_3_2_1_67_1","article-title":"Spill the Beans: Extrospection of Internet of Things by Exploiting Denial of Service","volume":"6","author":"Sachidananda Vinay","year":"2019","unstructured":"Vinay Sachidananda, Suhas Bhairav, and Yuval Elovici. 2019. Spill the Beans: Extrospection of Internet of Things by Exploiting Denial of Service. EAI Endorsed Transactions on Security and Safety 6, 20 (2019).","journal-title":"EAI Endorsed Transactions on Security and Safety"},{"key":"e_1_3_2_1_68_1","volume-title":"24th USENIX Security Symposium (USENIX Security 15)","author":"Chul\u00a0Richard Shin Eui","year":"2015","unstructured":"Eui Chul\u00a0Richard Shin, Dawn Song, and Reza Moazzezi. 2015. Recognizing functions in binaries with neural networks. In 24th USENIX Security Symposium (USENIX Security 15). 611\u2013626."},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"crossref","unstructured":"Yan Shoshitaishvili Ruoyu Wang Christophe Hauser Christopher Kruegel and Giovanni Vigna. 2015. Firmalice-automatic detection of authentication bypass vulnerabilities in binary firmware.. In NDSS.","DOI":"10.14722\/ndss.2015.23294"},{"key":"e_1_3_2_1_70_1","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Sivakumaran Pallavi","year":"2019","unstructured":"Pallavi Sivakumaran and Jorge Blasco. 2019. A Study of the Feasibility of Co-located App Attacks against BLE and a Large-Scale Analysis of the Current Application-Layer Security Landscape. In 28th USENIX Security Symposium (USENIX Security 19). 1\u201318."},{"key":"e_1_3_2_1_71_1","unstructured":"Pallavi Sivakumaran and Jorge Blasco\u00a0Alis. 2017. ATT Profiler. https:\/\/github.com\/projectbtle\/att-profiler."},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/3176258.3176945"},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338507.3358616"},{"key":"e_1_3_2_1_74_1","unstructured":"Mark Stanislav and Tod Beardsley. 2015. Hacking IoT: A Case Study on Baby Monitor Exposures and Vulnerabilities. Available: https:\/\/www.rapid7.com\/globalassets\/external\/docs\/Hacking-IoT-A-Case-Study-on-Baby-Monitor-Exposures-and-Vulnerabilities.pdf. [Accessed: 11 June 2020]."},{"key":"e_1_3_2_1_75_1","volume-title":"IoT connected devices worldwide","author":"Statista Research Department","year":"2030","unstructured":"Statista Research Department. 2019. IoT connected devices worldwide 2030. Available: https:\/\/www.statista.com\/statistics\/802690\/worldwide-connected-devices-by-access-technology\/. [Accessed: 29 June 2020]."},{"key":"e_1_3_2_1_76_1","unstructured":"STMicroelectronics. 2018. AN4869: The BlueNRG-1 BlueNRG-2 BLE OTA (over-the-air) firmware upgrade."},{"key":"e_1_3_2_1_77_1","unstructured":"STMicroelectronics. 2019. PM0257: BlueNRG-1 BlueNRG-2 BLE stack v2.x programming guidelines."},{"key":"e_1_3_2_1_78_1","volume-title":"Bluetooth Low Energy software stack. Available: https:\/\/www.ti.com\/tool\/BLE-STACK [Accessed","author":"Instruments Texas","year":"2020","unstructured":"Texas Instruments. 2020. Bluetooth Low Energy software stack. Available: https:\/\/www.ti.com\/tool\/BLE-STACK [Accessed: 02 July 2020]."},{"key":"e_1_3_2_1_79_1","volume-title":"A fully compliant Zigbee 3.x solution: Z-Stack. Available: https:\/\/www.ti.com\/tool\/Z-STACK [Accessed","author":"Instruments Texas","year":"2020","unstructured":"Texas Instruments. 2020. A fully compliant Zigbee 3.x solution: Z-Stack. Available: https:\/\/www.ti.com\/tool\/Z-STACK [Accessed: 02 July 2020]."},{"key":"e_1_3_2_1_80_1","volume-title":"Wi-Fi baby heart monitor may have the worst IoT security of","author":"Thomson Iain","year":"2016","unstructured":"Iain Thomson. 2016. Wi-Fi baby heart monitor may have the worst IoT security of 2016. Available: https:\/\/www.theregister.com\/2016\/10\/13\/possibly_worst_iot_security_failure_yet. [Accessed: 11 June 2020]."},{"key":"e_1_3_2_1_81_1","volume-title":"What is Thread. Available: https:\/\/www.threadgroup.org\/what-Is-thread[Accessed","author":"Thread Group","year":"2020","unstructured":"Thread Group. 2019. What is Thread. Available: https:\/\/www.threadgroup.org\/what-Is-thread[Accessed: 27 July 2020]."},{"key":"e_1_3_2_1_82_1","volume-title":"Firmware Insider: Bluetooth Randomness is Mostly Random. In 14th {USENIX} Workshop on Offensive Technologies ({WOOT} 20).","author":"Tillmanns J\u00f6rn","year":"2020","unstructured":"J\u00f6rn Tillmanns, Jiska Classen, Felix Rohrbach, and Matthias Hollick. 2020. Firmware Insider: Bluetooth Randomness is Mostly Random. In 14th {USENIX} Workshop on Offensive Technologies ({WOOT} 20)."},{"key":"e_1_3_2_1_83_1","volume-title":"Angr-the next generation of binary analysis. In 2017 IEEE Cybersecurity Development (SecDev)","author":"Wang Fish","unstructured":"Fish Wang and Yan Shoshitaishvili. 2017. Angr-the next generation of binary analysis. In 2017 IEEE Cybersecurity Development (SecDev). IEEE, 8\u20139."},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1145\/3386901.3389025"},{"key":"e_1_3_2_1_85_1","volume-title":"Embedded and Real-Time Operating Systems","author":"Wang KC","unstructured":"KC Wang. 2017. Embedded real-time operating systems. In Embedded and Real-Time Operating Systems. Springer, 401\u2013475."},{"key":"e_1_3_2_1_86_1","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Wang Xueqiang","unstructured":"Xueqiang Wang, Yuqiong Sun, Susanta Nanda, and XiaoFeng Wang. [n. d.]. Looking from the mirror: evaluating IoT device security through mobile companion apps. In 28th USENIX Security Symposium (USENIX Security 19)."},{"key":"e_1_3_2_1_87_1","unstructured":"Haohuang Wen Zhiqiang Lin and Yinqian Zhang. 2020. FirmXRay: Detecting Bluetooth Link Layer Vulnerabilities From Bare-Metal Firmware. (2020)."},{"key":"e_1_3_2_1_88_1","volume-title":"Proceedings of the USENIX Security Symposium (USENIX Security).","author":"Wu Jianliang","year":"2021","unstructured":"Jianliang Wu, Ruoyu Wu, Daniele Antonioli, Mathias Payer, Nils\u00a0Ole Tippenhauer, Dongyan Xu, Dave\u00a0Jing Tian, and Antonio Bianchi. 2021. LIGHTBLUE: Automatic Profile-Aware Debloating of Bluetooth Stacks. In Proceedings of the USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_89_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134018"},{"key":"e_1_3_2_1_90_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2883973"},{"key":"e_1_3_2_1_91_1","volume-title":"Hackers Can Seize Control of Electric Skateboards and Toss Riders. Available: https:\/\/www.wired.com\/2015\/08\/hackers-can-seize-control-of-electric-skateboards-and-toss-riders-boosted-revo\/[Accessed","author":"Zetter Kim","year":"2020","unstructured":"Kim Zetter. 2015. Hackers Can Seize Control of Electric Skateboards and Toss Riders. Available: https:\/\/www.wired.com\/2015\/08\/hackers-can-seize-control-of-electric-skateboards-and-toss-riders-boosted-revo\/[Accessed: 27 July 2020]."},{"key":"e_1_3_2_1_92_1","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Zhou Wei","year":"2019","unstructured":"Wei Zhou, Yan Jia, Yao Yao, Lipeng Zhu, Le Guan, Yuhang Mao, Peng Liu, and Yuqing Zhang. 2019. Discovering and Understanding the Security Hazards in the Interactions between IoT Devices, Mobile Apps, and Clouds on Smart Home Platforms. In 28th USENIX Security Symposium (USENIX Security 19). USENIX Association, Santa Clara, CA, 1133\u20131150."},{"key":"e_1_3_2_1_93_1","volume-title":"What is Zigbee?Available: https:\/\/Zigbeealliance.org\/solution\/Zigbee\/[Accessed","author":"Alliance Zigbee","year":"2020","unstructured":"Zigbee Alliance. 2019. What is Zigbee?Available: https:\/\/Zigbeealliance.org\/solution\/Zigbee\/[Accessed: 27 July 2020]."},{"key":"e_1_3_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354240"}],"event":{"name":"ACSAC '21: Annual Computer Security Applications Conference","location":"Virtual Event USA","acronym":"ACSAC '21"},"container-title":["Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3488007","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3485832.3488007","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T19:18:52Z","timestamp":1755890332000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3488007"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,12,6]]},"references-count":94,"alternative-id":["10.1145\/3485832.3488007","10.1145\/3485832"],"URL":"https:\/\/doi.org\/10.1145\/3485832.3488007","relation":{},"subject":[],"published":{"date-parts":[[2021,12,6]]},"assertion":[{"value":"2021-12-06","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}