{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T00:05:28Z","timestamp":1755907528985,"version":"3.44.0"},"publisher-location":"New York, NY, USA","reference-count":67,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"ARO (Association for Research in Otolaryngology)","award":["W911NF2110081"],"award-info":[{"award-number":["W911NF2110081"]}]},{"DOI":"10.13039\/501100006374","name":"Defense Advanced Research Projects Agency","doi-asserted-by":"publisher","award":["N6600120C4020"],"award-info":[{"award-number":["N6600120C4020"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100006374","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["CNS-2112471,ITE-2326882"],"award-info":[{"award-number":["CNS-2112471,ITE-2326882"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1145\/3658644.3690254","type":"proceedings-article","created":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T12:19:20Z","timestamp":1733746760000},"page":"2311-2325","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["<scp>BaseMirror:<\/scp>\n            Automatic Reverse Engineering of Baseband Commands from Android's Radio Interface Layer"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1083-2842","authenticated-orcid":false,"given":"Wenqiang","family":"Li","sequence":"first","affiliation":[{"name":"The Ohio State University, Columbus, Ohio, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2753-0250","authenticated-orcid":false,"given":"Haohuang","family":"Wen","sequence":"additional","affiliation":[{"name":"The Ohio State University, Columbus, Ohio, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6527-5994","authenticated-orcid":false,"given":"Zhiqiang","family":"Lin","sequence":"additional","affiliation":[{"name":"The Ohio State University, Columbus, Ohio, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"doi-asserted-by":"crossref","unstructured":"Frances E Allen. 1970. Control flow analysis. In ACM Sigplan Notices.","key":"e_1_3_2_1_1_1","DOI":"10.1145\/390013.808479"},{"unstructured":"Android. 2022. RIL Refactoring | Android Open Source Project. https:\/\/source.android.com\/devices\/tech\/connect\/ril.","key":"e_1_3_2_1_2_1"},{"unstructured":"Android. 2024. Android Interface Definition Language (AIDL). https:\/\/developer.android.com\/guide\/components\/aidl.","key":"e_1_3_2_1_3_1"},{"unstructured":"Android. 2024. Android Open Source Project. https:\/\/source.android.com\/.","key":"e_1_3_2_1_4_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_5_1","DOI":"10.1145\/236337.236371"},{"key":"e_1_3_2_1_6_1","volume-title":"Information and Communication Technology Security Symposium (SSTIC).","author":"Berard David","year":"2020","unstructured":"David Berard and Vincent Fargues. 2020. How to design a baseband debugger. In Information and Communication Technology Security Symposium (SSTIC)."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_7_1","DOI":"10.1109\/SP40001.2021.00095"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_8_1","DOI":"10.1145\/3133956.3134020"},{"unstructured":"Denis 'GNUtoo' Carikli. 2021. Samsung-ipc. https:\/\/redmine.replicant.us\/projects\/replicant\/wiki\/Samsung-ipc.","key":"e_1_3_2_1_9_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_10_1","DOI":"10.1145\/3460120.3485374"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_11_1","DOI":"10.1145\/3052973.3052976"},{"key":"e_1_3_2_1_12_1","volume-title":"29th USENIX Security Symposium (USENIX Security).","author":"Elsabagh Mohamed","year":"2020","unstructured":"Mohamed Elsabagh, Ryan Johnson, Angelos Stavrou, Chaoshun Zuo, Qingchuan Zhao, and Zhiqiang Lin. 2020. FIRMSCOPE: Automatic uncovering of Privilege-Escalation vulnerabilities in Pre-Installed apps in android firmware. In 29th USENIX Security Symposium (USENIX Security)."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_13_1","DOI":"10.1145\/3321705.3329833"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_14_1","DOI":"10.1145\/3372297.3417251"},{"key":"e_1_3_2_1_15_1","volume-title":"14th USENIX Conference on Offensive Technologies (WOOT).","author":"Fioraldi Andrea","year":"2020","unstructured":"Andrea Fioraldi, Dominik Maier, Heiko Ei\u00dffeldt, and Marc Heuse. 2020. AFL: Combining incremental steps of fuzzing research. In 14th USENIX Conference on Offensive Technologies (WOOT)."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_16_1","DOI":"10.1109\/WCRE.2011.49"},{"unstructured":"Ghidra. 2024. P-Code. https:\/\/ghidra.re\/ghidra_docs\/api\/ghidra\/program\/model\/pcode\/package-summary.html.","key":"e_1_3_2_1_17_1"},{"unstructured":"Nico Golde and Daniel Komaromy. 2016. Breaking Band: reverse engineering and exploiting the shannon baseband. In 2016 Recon.","key":"e_1_3_2_1_18_1"},{"unstructured":"Marco Grassi and Xingyu Chen. 2021. Over The Air Baseband Exploit: Gaining Remote Code Execution on 5G Smartphones. In BlackHat USA.","key":"e_1_3_2_1_19_1"},{"unstructured":"Marco Grassi Muqing Liu and Tianyi Xie. 2018. Exploitation Of A Modern Smartphone Baseband. In BlackHat USA.","key":"e_1_3_2_1_20_1"},{"unstructured":"Skanda Hazarika. 2023. Android hidden codes: All the custom dialer codes and what they do. https:\/\/www.xda-developers.com\/android-secret-codes\/.","key":"e_1_3_2_1_21_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_22_1","DOI":"10.1145\/3317549.3326310"},{"volume-title":"FirmWire: Transparent Dynamic Analysis for Cellular Baseband Firmware. In 29th Network and Distributed System Security Symposium (NDSS).","author":"Hernandez Grant","unstructured":"Grant Hernandez, Marius Muench, Dominik Maier, Alyssa Milburn, Shinjo Park, Tobias Scharnowski, Tyler Tucker, Patrick Traynor, and Kevin R. B. Butler. 2022. FirmWire: Transparent Dynamic Analysis for Cellular Baseband Firmware. In 29th Network and Distributed System Security Symposium (NDSS).","key":"e_1_3_2_1_23_1"},{"key":"e_1_3_2_1_24_1","volume-title":"BigMAC:Fine-Grained Policy Analysis of Android Firmware. In 29th USENIX Security Symposium (USENIX Security).","author":"Hernandez Grant","year":"2020","unstructured":"Grant Hernandez, Dave Jing Tian, Anurag Swarnim Yadav, Byron J Williams, and Kevin RB Butler. 2020. BigMAC:Fine-Grained Policy Analysis of Android Firmware. In 29th USENIX Security Symposium (USENIX Security)."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_25_1","DOI":"10.1145\/3510003.3510072"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_26_1","DOI":"10.1145\/3460120.3485388"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_27_1","DOI":"10.1145\/2556464.2556465"},{"unstructured":"Paul K. 2014. Replicant developers find and close Samsung Galaxy backdoor. https:\/\/www.fsf.org\/blogs\/community\/replicant-developers-find-andclose- samsung-galaxy-backdoor.","key":"e_1_3_2_1_28_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_29_1","DOI":"10.1145\/3359789.3359833"},{"key":"e_1_3_2_1_30_1","volume-title":"BASECOMP: A Comparative Analysis for Integrity Protection in Cellular Baseband Software. In 32nd USENIX Security Symposium (USENIX Security).","author":"Kim Eunsoo","year":"2023","unstructured":"Eunsoo Kim, Min Woo Baek, CheolJun Park, Dongkwan Kim, Yongdae Kim, and Insu Yun. 2023. BASECOMP: A Comparative Analysis for Integrity Protection in Cellular Baseband Software. In 32nd USENIX Security Symposium (USENIX Security)."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_31_1","DOI":"10.14722\/ndss.2021.24365"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_32_1","DOI":"10.1007\/978-3-030-88418-5_7"},{"unstructured":"laforge. 2019. Qualcomm Linux Modems by Quectel & Co. https:\/\/osmocom.org\/ projects\/quectel-modems\/wiki\/QMI.","key":"e_1_3_2_1_33_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_34_1","DOI":"10.14722\/ndss.2021.24308"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_35_1","DOI":"10.1145\/3510003.3510208"},{"unstructured":"Wenqiang Li Haohuang Wen and Zhiqiang Lin. 2024. BaseMirror: Automatic Reverse Engineering of Baseband Commands from Android's Radio Interface Layer. In axXiv preprint arXiv:2409.00475.","key":"e_1_3_2_1_36_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_37_1","DOI":"10.1145\/2973750.2973751"},{"key":"e_1_3_2_1_38_1","volume-title":"Semantic-Enhanced Static Vulnerability Detection in Baseband Firmware. In 46th International Conference on Software Engineering (ICSE).","author":"Liu Yiming","year":"2024","unstructured":"Yiming Liu, Cen Zhang, Feng Li, Yeting Li, Jianhua Zhou, Jian Wang, Lanlan Zhan, Yang Liu, and Wei Huo. 2024. Semantic-Enhanced Static Vulnerability Detection in Baseband Firmware. In 46th International Conference on Software Engineering (ICSE)."},{"key":"e_1_3_2_1_39_1","volume-title":"26th ACM SIGSAC Conference on Computer and Communications Security (CCS).","author":"Lu Kangjie","year":"2019","unstructured":"Kangjie Lu and Hong Hu. 2019. Where does it go? refining indirect-call targets with multi-layer type analysis. In 26th ACM SIGSAC Conference on Computer and Communications Security (CCS)."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_40_1","DOI":"10.1145\/3395351.3399360"},{"key":"e_1_3_2_1_41_1","volume-title":"9th International Conference on Information Security and Cryptology (ICISC).","author":"Ming Jiang","year":"2012","unstructured":"Jiang Ming, Meng Pan, and Debin Gao. 2012. iBinHunt: Binary hunting with inter-procedural control flow. In 9th International Conference on Information Security and Cryptology (ICISC)."},{"unstructured":"NSA. 2024. Ghidra. https:\/\/ghidra-sre.org\/.","key":"e_1_3_2_1_42_1"},{"unstructured":"Roberto Paleari. 2024. Interacting with Samsung radio layer (RILD). http:\/\/ roberto.greyhats.it\/2016\/05\/samsung-access-rild.html.","key":"e_1_3_2_1_43_1"},{"volume-title":"24th Network and Distributed System Security Symposium (NDSS).","author":"Pawlowski Andre","unstructured":"Andre Pawlowski, Moritz Contag, Victor van der Veen, Chris Ouwehand, Thorsten Holz, Herbert Bos, Elias Athanasopoulos, and Cristiano Giuffrida. 2017. MARX: Uncovering Class Hierarchies in C Programs.. In 24th Network and Distributed System Security Symposium (NDSS).","key":"e_1_3_2_1_44_1"},{"volume-title":"35th Annual Computer Security Applications Conference (ACSAC).","author":"Pawlowski Andre","unstructured":"Andre Pawlowski, Victor van der Veen, Dennis Andriesse, Erik van der Kouwe, Thorsten Holz, Cristiano Giuffrida, and Herbert Bos. 2019. VPS: excavating highlevel C constructs from low-level binaries to protect dynamic dispatching. In 35th Annual Computer Security Applications Conference (ACSAC).","key":"e_1_3_2_1_45_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_46_1","DOI":"10.1109\/SP40001.2021.00074"},{"unstructured":"Ole Andr\u00e9 Vadla Ravn\u00e5s. 2024. Frida - A world-class dynamic instrumentation toolkit. https:\/\/frida.re\/.","key":"e_1_3_2_1_47_1"},{"unstructured":"Hex Rays. 2024. IDA Pro. https:\/\/www.hex-rays.com\/idapro.","key":"e_1_3_2_1_48_1"},{"unstructured":"SAMMOBILE. 2024. SamMobile - Your source for all Samsung news. https: \/\/www.sammobile.com\/.","key":"e_1_3_2_1_49_1"},{"key":"e_1_3_2_1_50_1","volume-title":"25th International Conference on Tools and Algorithms for the Construction and Analysis of Systems (TACAS).","author":"Schubert Philipp Dominik","year":"2019","unstructured":"Philipp Dominik Schubert, Ben Hermann, and Eric Bodden. 2019. Phasar: An interprocedural static analysis framework for C\/C. In 25th International Conference on Tools and Algorithms for the Construction and Analysis of Systems (TACAS)."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_51_1","DOI":"10.1145\/3243734.3243793"},{"key":"e_1_3_2_1_52_1","volume-title":"Kratos: Discovering Inconsistent Security Policy Enforcement in the Android Framework. In 23th Network and Distributed System Security Symposium (NDSS).","author":"Shao Yuru","year":"2016","unstructured":"Yuru Shao, Qi Alfred Chen, Zhuoqing Morley Mao, Jason Ott, and Zhiyun Qian. 2016. Kratos: Discovering Inconsistent Security Policy Enforcement in the Android Framework. In 23th Network and Distributed System Security Symposium (NDSS)."},{"key":"e_1_3_2_1_53_1","volume-title":"Facilitating Non-Intrusive In-Vivo Firmware Testing with Stateless Instrumentation. In 31st Network and Distributed System Security Symposium (NDSS).","author":"Shi Jiameng","year":"2024","unstructured":"Jiameng Shi, Wenqiang Li, Wenwen Wang, and Le Guan. 2024. Facilitating Non-Intrusive In-Vivo Firmware Testing with Stateless Instrumentation. In 31st Network and Distributed System Security Symposium (NDSS)."},{"key":"e_1_3_2_1_54_1","volume-title":"37th IEEE Symposium on Security and Privacy (SP).","author":"Shoshitaishvili Yan","year":"2016","unstructured":"Yan Shoshitaishvili, RuoyuWang, Christopher Salls, Nick Stephens, Mario Polino, Andrew Dutcher, John Grosen, Siji Feng, Christophe Hauser, Christopher Kruegel, et al. 2016. SOK:(State of) The Art ofWar: Offensive techniques in binary analysis. In 37th IEEE Symposium on Security and Privacy (SP)."},{"key":"e_1_3_2_1_55_1","volume-title":"27th USENIX Security Symposium (USENIX Security).","author":"Tian Dave Jing","year":"2018","unstructured":"Dave Jing Tian, Grant Hernandez, Joseph I Choi, Vanessa Frost, Christie Raules, Patrick Traynor, Hayawardh Vijayakumar, Lee Harrison, Amir Rahmati, Michael Grace, et al. 2018. Attention spanned: Comprehensive vulnerability analysis of AT commands within the android ecosystem. In 27th USENIX Security Symposium (USENIX Security)."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_56_1","DOI":"10.1145\/2504730.2504764"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_57_1","DOI":"10.1109\/SP.2016.60"},{"key":"e_1_3_2_1_58_1","volume-title":"28th USENIX Security Symposium (USENIX Security).","author":"Wang Xueqiang","year":"2019","unstructured":"Xueqiang Wang, Yuqiong Sun, Susanta Nanda, and XiaoFeng Wang. 2019. Looking from the mirror: Evaluating IoT device security through mobile companion apps. In 28th USENIX Security Symposium (USENIX Security)."},{"volume-title":"Baseband Attacks: Remote Exploitation of Memory Corruptions in Cellular Protocol Stacks. In 6th USENIX conference on Offensive Technologies (WOOT).","year":"2012","unstructured":"Ralf-PhilippWeinmann. 2012. Baseband Attacks: Remote Exploitation of Memory Corruptions in Cellular Protocol Stacks. In 6th USENIX conference on Offensive Technologies (WOOT).","key":"e_1_3_2_1_59_1"},{"key":"e_1_3_2_1_60_1","volume-title":"29th USENIX Security Symposium (USENIX Security).","author":"Wen Haohuang","year":"2020","unstructured":"Haohuang Wen, Qi Alfred Chen, and Zhiqiang Lin. 2020. Plug-N-Pwned: Comprehensive vulnerability analysis of OBD-II dongles as a new Over-the-Air attack surface in automotive IoT. In 29th USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_61_1","volume-title":"32nd USENIX Security Symposium (USENIX Security).","author":"Wen Haohuang","year":"2023","unstructured":"Haohuang Wen and Zhiqiang Lin. 2023. Egg hunt in Tesla infotainment: a first look at reverse engineering of Qt binaries. In 32nd USENIX Security Symposium (USENIX Security)."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_62_1","DOI":"10.1145\/3372297.3423344"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_63_1","DOI":"10.14722\/ndss.2023.24432"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_64_1","DOI":"10.14722\/ndss.2020.24231"},{"unstructured":"wishihab. 2018. Remote Access Tool Trojan List - Android. https:\/\/github.com\/wishihab\/Android-RATList.","key":"e_1_3_2_1_65_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_66_1","DOI":"10.1109\/WCSE.2012.26"},{"key":"e_1_3_2_1_67_1","volume-title":"5th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec).","author":"Zeng Yuanyuan","year":"2012","unstructured":"Yuanyuan Zeng, Kang G Shin, and Xin Hu. 2012. Design of SMS commandedand-controlled and P2P-structured mobile botnets. In 5th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec)."}],"event":{"sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"acronym":"CCS '24","name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA"},"container-title":["Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690254","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3690254","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T06:16:39Z","timestamp":1755843399000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690254"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":67,"alternative-id":["10.1145\/3658644.3690254","10.1145\/3658644"],"URL":"https:\/\/doi.org\/10.1145\/3658644.3690254","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}