{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T15:49:54Z","timestamp":1783007394795,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":73,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"NSF and Office of the Under Secretary of Defense- Research and Engineering","award":["ITE 2326898"],"award-info":[{"award-number":["ITE 2326898"]}]},{"name":"NSF","award":["2145631, 2215017, 2226447"],"award-info":[{"award-number":["2145631, 2215017, 2226447"]}]},{"DOI":"10.13039\/501100006374","name":"Defense Advanced Research Projects Agency","doi-asserted-by":"publisher","award":["D22AP00148"],"award-info":[{"award-number":["D22AP00148"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]},{"name":"State University of New York's Empire Innovation Program"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1145\/3658644.3690312","type":"proceedings-article","created":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T12:19:20Z","timestamp":1733746760000},"page":"2102-2116","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["State Machine Mutation-based Testing Framework for Wireless Communication Protocols"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-2831-879X","authenticated-orcid":false,"given":"Syed Md Mukit","family":"Rashid","sequence":"first","affiliation":[{"name":"The Pennsylvania State University, University Park, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-7083-7991","authenticated-orcid":false,"given":"Tianwei","family":"Wu","sequence":"additional","affiliation":[{"name":"The Pennsylvania State University, University Park, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-8782-1686","authenticated-orcid":false,"given":"Kai","family":"Tu","sequence":"additional","affiliation":[{"name":"The Pennsylvania State University, University Park, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0629-2895","authenticated-orcid":false,"given":"Abdullah Al","family":"Ishtiaq","sequence":"additional","affiliation":[{"name":"The Pennsylvania State University, University Park, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-1931-1469","authenticated-orcid":false,"given":"Ridwanul Hasan","family":"Tanvir","sequence":"additional","affiliation":[{"name":"The Pennsylvania State University, University Park, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-5062-9493","authenticated-orcid":false,"given":"Yilu","family":"Dong","sequence":"additional","affiliation":[{"name":"The Pennsylvania State University, University Park, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1356-6279","authenticated-orcid":false,"given":"Omar","family":"Chowdhury","sequence":"additional","affiliation":[{"name":"Stony Brook University, Stony Brook, NY, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9222-8544","authenticated-orcid":false,"given":"Syed Rafiul","family":"Hussain","sequence":"additional","affiliation":[{"name":"The Pennsylvania State University, University Park, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"[n. d.]. Proteus. https:\/\/github.com\/SyNSec-den\/Proteus."},{"key":"e_1_3_2_1_2_1","unstructured":"[n. d.]. srsRAN. https:\/\/github.com\/srsran\/srsRAN_4G."},{"key":"e_1_3_2_1_3_1","volume-title":"d.]. Universal Mobile Telecommunications System (UMTS)","unstructured":"[n. d.]. Universal Mobile Telecommunications System (UMTS); LTE; 5G; Non-Access- Stratum (NAS) Protocol for Evolved Packet System (EPS); Stage 3 (3GPP TS 24.301 version 16.8.0 Release 16)."},{"key":"e_1_3_2_1_4_1","unstructured":"2013. American FUzzy Lop. https:\/\/github.com\/google\/AFL."},{"key":"e_1_3_2_1_5_1","unstructured":"2016. boofuzz: Network Protocol Fuzzing for Humans. https:\/\/github.com\/ jtpereyda\/boofuzz."},{"key":"e_1_3_2_1_6_1","unstructured":"2021. Bluetooth Special Interest Group Core Specification 5.3. https:\/\/www. bluetooth.com\/specifications\/specs\/core-specification-5--3\/."},{"key":"e_1_3_2_1_7_1","volume-title":"33rd USENIX Security Symposium.","author":"Ishtiaq A. Al","unstructured":"A. Al Ishtiaq, S. S. S. Das, S. M. M. Rashid, A. Ranjbar, K. Tu, T. Wu, Z. Song, W. Wang, M. Akon, R. Zhang, and S. R. Hussain. 2024. Hermes: Unlocking Security Analysis of Cellular Network Protocols by Synthesizing Finite State Machines from Natural Language Specifications. In 33rd USENIX Security Symposium."},{"key":"e_1_3_2_1_8_1","volume-title":"DY Fuzzing: Formal Dolev-Yao Models Meet Cryptographic Protocol Fuzz Testing. Cryptology ePrint Archive.","author":"Ammann M.","unstructured":"M. Ammann, L. Hirschi, and S. Kremer. 2023. DY Fuzzing: Formal Dolev-Yao Models Meet Cryptographic Protocol Fuzz Testing. Cryptology ePrint Archive."},{"key":"e_1_3_2_1_9_1","volume-title":"Bias: Bluetooth Impersonation Attacks. In IEEE symposium on security and privacy.","author":"Antonioli D.","unstructured":"D. Antonioli, N. O. Tippenhauer, and K. Rasmussen. 2020. Bias: Bluetooth Impersonation Attacks. In IEEE symposium on security and privacy."},{"key":"e_1_3_2_1_10_1","volume-title":"BLURtooth: Exploiting Cross-Transport Key Derivation in Bluetooth Classic and Bluetooth Low Energy. In ACM on Asia conference on computer and communications security.","author":"Antonioli D.","unstructured":"D. Antonioli, N. O. Tippenhauer, K. Rasmussen, and M. Payer. 2022. BLURtooth: Exploiting Cross-Transport Key Derivation in Bluetooth Classic and Bluetooth Low Energy. In ACM on Asia conference on computer and communications security."},{"key":"e_1_3_2_1_11_1","unstructured":"B. Blanchet et al. 2001. An Efficient Cryptographic Protocol Verifier Based on Prolog Rules.. In csfw Vol. 1."},{"key":"e_1_3_2_1_12_1","unstructured":"BlueKitchen. [n. d.]. BTstack: Dual-mode Bluetooth Stack with Small Memory Footprint. https:\/\/github.com\/bluekitchen\/btstack."},{"key":"e_1_3_2_1_13_1","volume-title":"51st Annual IEEE\/IFIP International Conference on Dependable Systems and Networks.","author":"Cayre R.","unstructured":"R. Cayre, F. Galtier, G. Auriol, V. Nicomette, M. Ka\u00e2niche, and G. Marconato. 2021. InjectaBLE: Injecting Malicious Traffic into Established Bluetooth Low Energy connections. In 51st Annual IEEE\/IFIP International Conference on Dependable Systems and Networks."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00046"},{"key":"e_1_3_2_1_15_1","volume-title":"32nd USENIX Security Symposium.","author":"Chen Y.","unstructured":"Y. Chen, D. Tang, Y. Yao, M. Zha, X.Wang, X. Liu, H. Tang, and B. Liu. 2023. Sherlock on Specs: Building LTE Conformance Tests through Automated Reasoning. In 32nd USENIX Security Symposium."},{"key":"e_1_3_2_1_16_1","volume-title":"IEEE Symposium on Security and Privacy.","author":"Chen Y.","unstructured":"Y. Chen, Y. Yao, X. Wang, D. Xu, C. Yue, X. Liu, K. Chen, H. Tang, and B. Liu. 2021. Bookworm Game: Automatic Discovery of LTE Vulnerabilities through Documentation Analysis. In IEEE Symposium on Security and Privacy."},{"key":"e_1_3_2_1_17_1","volume-title":"On The Challenges of Automata Reconstruction in LTE Networks. In 14th ACM Conference on Security and Privacy in Wireless and Mobile Networks.","author":"Chlosta M.","unstructured":"M. Chlosta, D. Rupprecht, and T. Holz. 2021. On The Challenges of Automata Reconstruction in LTE Networks. In 14th ACM Conference on Security and Privacy in Wireless and Mobile Networks."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"crossref","unstructured":"D. Dolev and A. Yao. 1983. On the Security of Public Key Protocols. IEEE Transactions on Information Theory 29 (1983).","DOI":"10.1109\/TIT.1983.1056650"},{"key":"e_1_3_2_1_19_1","volume-title":"ACM SIGSAC conference on computer and communications security.","author":"Feng X.","unstructured":"X. Feng, R. Sun, X. Zhu, M. Xue, S. Wen, D. Liu, S. Nepal, and Y. Xiang. 2021. Snipuzz: Black-box fuzzing of IoT Firmware via Message Snippet Inference. In ACM SIGSAC conference on computer and communications security."},{"key":"e_1_3_2_1_20_1","volume-title":"AFL: Combining Incremental Steps of Fuzzing Research. In 14th USENIX Workshop on Offensive Technologies.","author":"Fioraldi A.","unstructured":"A. Fioraldi, D. Maier, H. Ei\u00dffeldt, and M. Heuse. 2020. AFL: Combining Incremental Steps of Fuzzing Research. In 14th USENIX Workshop on Offensive Technologies."},{"key":"e_1_3_2_1_21_1","volume-title":"Automata-Based Automated Detection of State Machine Bugs in Protocol Implementations. In Network and Distributed Systems Security Symposium.","author":"Fiterau-Brostean P.","unstructured":"P. Fiterau-Brostean, B. Jonsson, K. Sagonas, and F. T\u00e5quist. 2023. Automata-Based Automated Detection of State Machine Bugs in Protocol Implementations. In Network and Distributed Systems Security Symposium."},{"key":"e_1_3_2_1_22_1","volume-title":"Collafl: Path Sensitive Fuzzing. In 2018 IEEE Symposium on Security and Privacy.","author":"Gan S.","unstructured":"S. Gan, C. Zhang, X. Qin, X. Tu, K. Li, Z. Pei, and Z. Chen. 2018. Collafl: Path Sensitive Fuzzing. In 2018 IEEE Symposium on Security and Privacy."},{"key":"e_1_3_2_1_23_1","volume-title":"2020 USENIX Annual Technical Conference.","author":"Garbelini M. E.","unstructured":"M. E. Garbelini, C. Wang, S. Chattopadhyay, S. Sumei, and E. Kurniawan. 2020. SweynTooth: Unleashing Mayhem over Bluetooth Low Energy. In 2020 USENIX Annual Technical Conference."},{"key":"e_1_3_2_1_24_1","volume-title":"Breaking Band: Reverse Engineering and Exploiting the Shannon Baseband. Recon","author":"Golde N.","year":"2016","unstructured":"N. Golde and D. Komaromy. 2016. Breaking Band: Reverse Engineering and Exploiting the Shannon Baseband. Recon (2016)."},{"key":"e_1_3_2_1_25_1","volume-title":"14th USENIX Workshop on Offensive Technologies.","author":"Heinze D.","unstructured":"D. Heinze, J. Classen, and M. Hollick. 2020. ToothPicker: Apple Picking in the iOS Bluetooth Stack. In 14th USENIX Workshop on Offensive Technologies."},{"key":"e_1_3_2_1_26_1","volume-title":"FIRMWIRE: Transparent Dynamic Analysis for Cellular Baseband Firmware. In Network and Distributed Systems Security Symposium.","author":"Hernandez G.","unstructured":"G. Hernandez, M. Muench, D. Maier, A. Milburn, S. Park, T. Scharnowski, T. Tucker, P. Traynor, and K. Butler. 2022. FIRMWIRE: Transparent Dynamic Analysis for Cellular Baseband Firmware. In Network and Distributed Systems Security Symposium."},{"key":"e_1_3_2_1_27_1","volume-title":"Analyzing Operational Behavior of Stateful Protocol Implementations for Detecting Semantic Bugs. In 47th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks.","author":"Hoque E.","unstructured":"E. Hoque, O. Chowdhury, S. Y. Chau, C. Nita-Rotaru, and N. Li. 2017. Analyzing Operational Behavior of Stateful Protocol Implementations for Detecting Semantic Bugs. In 47th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"crossref","unstructured":"S. Hussain O. Chowdhury S. Mehnaz and E. Bertino. 2018. LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTE. In Network and Distributed Systems Security.","DOI":"10.14722\/ndss.2018.23313"},{"key":"e_1_3_2_1_29_1","volume-title":"Network and Distributed Systems Security Symposium.","author":"Hussain S. R.","unstructured":"S. R. Hussain, M. Echeverria, O. Chowdhury, N. Li, and E. Bertino. 2019. Privacy Attacks to the 4G and 5G Cellular Paging Protocols using Side Channel Information. In Network and Distributed Systems Security Symposium."},{"key":"e_1_3_2_1_30_1","volume-title":"ACM SIGSAC Conference on Computer and Communications Security.","author":"Hussain S. R.","unstructured":"S. R. Hussain, M. Echeverria, I. Karim, O. Chowdhury, and E. Bertino. 2019. 5GReasoner: A Property-Directed Security and Privacy Analysis Framework for 5G Cellular Network Protocol. In ACM SIGSAC Conference on Computer and Communications Security."},{"key":"e_1_3_2_1_31_1","volume-title":"Insecure Connection Bootstrapping in Cellular Networks: The Root of All Evil. In 12th Conference on Security and Privacy in Wireless and Mobile Networks.","author":"Hussain S. R.","unstructured":"S. R. Hussain, M. Echeverria, A. Singla, O. Chowdhury, and E. Bertino. 2019. Insecure Connection Bootstrapping in Cellular Networks: The Root of All Evil. In 12th Conference on Security and Privacy in Wireless and Mobile Networks."},{"key":"e_1_3_2_1_32_1","volume-title":"ACM SIGSAC Conference on Computer and Communications Security.","author":"Hussain S. R.","unstructured":"S. R. Hussain, I. Karim, A. A. Ishtiaq, O. Chowdhury, and E. Bertino. 2021. Noncompliance as Deviant Behavior: An Automated Black-box Noncompliance Checker for 4G LTE Cellular Devices. In ACM SIGSAC Conference on Computer and Communications Security."},{"key":"e_1_3_2_1_33_1","unstructured":"IETF. 2022. RFC 9293: Transmission Control Protocol (TCP). https:\/\/datatracker. ietf.org\/doc\/html\/rfc9293."},{"key":"e_1_3_2_1_34_1","unstructured":"R. P. Jover. 2016. LTE Security Protocol Exploits and Location Tracking Experimentation with Low-cost Software Radio. (2016). arXiv:1607.05171 [cs.CR] https:\/\/arxiv.org\/abs\/1607.05171"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"crossref","unstructured":"R. P. Jover J. Lackey and A. Raghavan. 2014. Enhancing the Security of LTE Networks Against Jamming Attacks. EURASIP (2014).","DOI":"10.1186\/1687-417X-2014-7"},{"key":"e_1_3_2_1_36_1","volume-title":"BLEDiff: Scalable and Property-Agnostic Noncompliance Checking for BLE Implementations. In IEEE Symposium on Security and Privacy. IEEE.","author":"Karim I.","unstructured":"I. Karim, A. Al Ishtiaq, S. R. Hussain, and E. Bertino. 2023. BLEDiff: Scalable and Property-Agnostic Noncompliance Checking for BLE Implementations. In IEEE Symposium on Security and Privacy. IEEE."},{"key":"e_1_3_2_1_37_1","volume-title":"BASECOMP: A Comparative Analysis for Integrity Protection in Cellular Baseband Software. In 32nd USENIX Security Symposium.","author":"Kim E.","unstructured":"E. Kim, M. W. Baek, C. Park, D. Kim, Y. Kim, and I. Yun. 2023. BASECOMP: A Comparative Analysis for Integrity Protection in Cellular Baseband Software. In 32nd USENIX Security Symposium."},{"key":"e_1_3_2_1_38_1","volume-title":"Network and Distributed Systems Security Symposium.","author":"Kim E.","unstructured":"E. Kim, D. Kim, C. Park, I. Yun, and Y. Kim. 2021. BaseSpec: Comparative Analysis of Baseband Software and Cellular Specifications for L3 Protocols. In Network and Distributed Systems Security Symposium."},{"key":"e_1_3_2_1_39_1","volume-title":"Touching the Untouchables: Dynamic Security Analysis of the LTE Control Plane. In IEEE Symposium on Security and Privacy.","author":"Kim H.","unstructured":"H. Kim, J. Lee, E. Lee, and Y. Kim. 2019. Touching the Untouchables: Dynamic Security Analysis of the LTE Control Plane. In IEEE Symposium on Security and Privacy."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238176"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"crossref","unstructured":"M. Lichtman R. P. Jover M. Labib R. Rao V. Marojevic and J. H. Reed. 2016. LTE\/LTE-A Jamming Spoofing and Sniffing: Threat Assessment and Mitigation. IEEE Communications Magazine (2016).","DOI":"10.1109\/MCOM.2016.7452266"},{"key":"e_1_3_2_1_42_1","volume-title":"MOPT: Optimized Mutation Scheduling for Fuzzers. In 28th USENIX Security Symposium.","author":"Lyu C.","unstructured":"C. Lyu, S. Ji, C. Zhang, Y. Li, W.-H. Lee, Y. Song, and R. Beyah. 2019. MOPT: Optimized Mutation Scheduling for Fuzzers. In 28th USENIX Security Symposium."},{"key":"e_1_3_2_1_43_1","volume-title":"13th ACM Conference on Security and Privacy in Wireless and Mobile Networks.","author":"Maier D.","unstructured":"D. Maier, L. Seidel, and S. Park. 2020. BaseSAFE: Baseband Sanitized Fuzzing through Emulation. In 13th ACM Conference on Security and Privacy in Wireless and Mobile Networks."},{"key":"e_1_3_2_1_44_1","volume-title":"InternalBlue-Bluetooth Binary Patching and Experimentation Framework. In 17th Annual International Conference on Mobile Systems, Applications, and Services.","author":"Mantz D.","unstructured":"D. Mantz, J. Classen, M. Schulz, and M. Hollick. 2019. InternalBlue-Bluetooth Binary Patching and Experimentation Framework. In 17th Annual International Conference on Mobile Systems, Applications, and Services."},{"key":"e_1_3_2_1_45_1","volume-title":"IEEE Symposium on Security and Privacy.","author":"Pacheco M. L.","unstructured":"M. L. Pacheco, M. von Hippel, B. Weintraub, D. Goldwasser, and C. Nita-Rotaru. 2022. Automated Attack Synthesis by Extracting Finite State Machines from Protocol Specification Documents. In IEEE Symposium on Security and Privacy."},{"key":"e_1_3_2_1_46_1","volume-title":"DoLTEst: In-depth Downlink Negative Testing Framework for LTE Devices. In 31st USENIX Security Symposium.","author":"Park C.","unstructured":"C. Park, S. Bae, B. Oh, J. Lee, E. Lee, I. Yun, and Y. Kim. 2022. DoLTEst: In-depth Downlink Negative Testing Framework for LTE Devices. In 31st USENIX Security Symposium."},{"key":"e_1_3_2_1_47_1","volume-title":"White Rabbit in Mobile: Effect of Unsecured Clock Source in Smartphones. In 6th Workshop on Security and Privacy in Smartphones and Mobile Devices.","author":"Park S.","unstructured":"S. Park, A. Shaik, R. Borgaonkar, and J. Seifert. 2016. White Rabbit in Mobile: Effect of Unsecured Clock Source in Smartphones. In 6th Workshop on Security and Privacy in Smartphones and Mobile Devices."},{"key":"e_1_3_2_1_48_1","volume-title":"Formal Methods: 24th International Symposium. Springer-Verlag","author":"Pferscher A.","unstructured":"A. Pferscher and B. K. Aichernig. 2021. Fingerprinting Bluetooth Low Energy Devices via Active Automata Learning. In Formal Methods: 24th International Symposium. Springer-Verlag, Berlin, Heidelberg."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"crossref","unstructured":"A. Pferscher and B. K. Aichernig. 2022. Stateful Black-Box Fuzzing of Bluetooth Devices Using Automata Learning. In NASA Formal Methods J. V. Deshmukh K. Havelund and I. Perez (Eds.). Springer International Publishing.","DOI":"10.1007\/978-3-031-06773-0_20"},{"key":"e_1_3_2_1_50_1","volume-title":"AFLNet: A Greybox Fuzzer for Network Protocols. In 13th International Conference on Software Testing, Validation and Verification.","author":"Pham V.-T.","unstructured":"V.-T. Pham, M. B\u00f6hme, and A. Roychoudhury. 2020. AFLNet: A Greybox Fuzzer for Network Protocols. In 13th International Conference on Software Testing, Validation and Verification."},{"key":"e_1_3_2_1_51_1","volume-title":"Wireless Networks: A Comprehensive Survey","author":"Pirayesh H.","year":"2022","unstructured":"H. Pirayesh and H. Zeng. 2022. Jamming Attacks and Anti-jamming Strategies in Wireless Networks: A Comprehensive Survey. IEEE communications surveys & tutorials (2022)."},{"key":"e_1_3_2_1_52_1","unstructured":"NCC Group Plc. [n. d.]. fuzzowski. https:\/\/github.com\/nccgroup\/fuzzowski."},{"key":"e_1_3_2_1_53_1","volume-title":"Ridwanul Hasan Tanvir, Yilu Dong, Omar Chowdhury, and Syed Rafiul Hussain.","author":"Mukit Rashid Syed Md","year":"2024","unstructured":"Syed Md Mukit Rashid, TianweiWu, Kai Tu, Abdullah Al Ishtiaq, Ridwanul Hasan Tanvir, Yilu Dong, Omar Chowdhury, and Syed Rafiul Hussain. 2024. State Machine Mutation-based Testing Framework for Wireless Communication Protocols. (2024). arXiv:2409.02905 [cs.CR] https:\/\/arxiv.org\/abs\/2409.02905"},{"key":"e_1_3_2_1_54_1","volume-title":"29th USENIX Security Symposium.","author":"Ruge J.","unstructured":"J. Ruge, J. Classen, F. Gringoli, and M. Hollick. 2020. Frankenstein: Advanced Wireless Fuzzing to Exploit New Bluetooth Escalation Targets. In 29th USENIX Security Symposium."},{"key":"e_1_3_2_1_55_1","volume-title":"29th USENIX Security Symposium.","author":"Ruge J.","unstructured":"J. Ruge, J. Classen, F. Gringoli, and M. Hollick. 2020. Frankenstein: Advanced Wireless Fuzzing to Exploit New Bluetooth Escalation Targets. In 29th USENIX Security Symposium."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"crossref","unstructured":"D. Rupprecht A. Dabrowski T. Holz E.Weippl and C. P\u00f6pper. 2018. On Security Research Towards Future Mobile Network Generations. IEEE Communications Surveys & Tutorials 20 (2018).","DOI":"10.1109\/COMST.2018.2820728"},{"key":"e_1_3_2_1_57_1","volume-title":"10th USENIX Workshop on Offensive Technologies.","author":"Rupprecht D.","unstructured":"D. Rupprecht, K. Jansen, and C. P\u00f6pper. 2016. Putting LTE Security Functions to the Test: A Framework to Evaluate Implementation Correctness. In 10th USENIX Workshop on Offensive Technologies."},{"key":"e_1_3_2_1_58_1","volume-title":"Breaking LTE on Layer Two. In IEEE Symposium on Security and Privacy.","author":"Rupprecht D.","unstructured":"D. Rupprecht, K. Kohls, T. Holz, and C. P\u00f6pper. 2019. Breaking LTE on Layer Two. In IEEE Symposium on Security and Privacy."},{"key":"e_1_3_2_1_59_1","volume-title":"Nyx-net: Network Fuzzing with Incremental Snapshots. In 17th European Conference on Computer Systems.","author":"Schumilo S.","unstructured":"S. Schumilo, C. Aschermann, A. Jemmett, A. Abbasi, and T. Holz. 2022. Nyx-net: Network Fuzzing with Incremental Snapshots. In 17th European Conference on Computer Systems."},{"key":"e_1_3_2_1_60_1","volume-title":"Blueborne: The Dangers of Bluetooth Implementations: Unveiling Zero Day Vulnerabilities and Security Flaws in Modern Bluetooth Stacks. Tech. Rep. Department of Computer Science","author":"Seri B.","year":"2017","unstructured":"B. Seri and G. Vishnepolsky. 2017. Blueborne: The Dangers of Bluetooth Implementations: Unveiling Zero Day Vulnerabilities and Security Flaws in Modern Bluetooth Stacks. Tech. Rep. Department of Computer Science, Michigan State University."},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23236"},{"key":"e_1_3_2_1_62_1","volume-title":"32nd USENIX Security Symposium.","author":"Shi Q.","unstructured":"Q. Shi, X. Xu, and X. Zhang. 2023. Extracting Protocol Format as State Machine via Controlled Static Loop Analysis. In 32nd USENIX Security Symposium."},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.4304\/jnw.4.5.315-323"},{"key":"e_1_3_2_1_64_1","volume-title":"Exploiting Dissent: Towards Fuzzing-based Differential Black-box Testing of TLS Implementations","author":"Walz A.","year":"2017","unstructured":"A.Walz and A. Sikora. 2017. Exploiting Dissent: Towards Fuzzing-based Differential Black-box Testing of TLS Implementations. IEEE Transactions on Dependable and Secure Computing (2017)."},{"key":"e_1_3_2_1_65_1","volume-title":"31st USENIX Security Symposium.","author":"Wang F.","unstructured":"F.Wang, J.Wu, Y. Nan, Y. Aafer, X. Zhang, D. Xu, and M. Payer. 2022. ProFactory: Improving IoT Security via Formalized Protocol Customization. In 31st USENIX Security Symposium."},{"key":"e_1_3_2_1_66_1","volume-title":"Baseband Attacks: Remote Exploitation of Memory Corruptions in Cellular Protocol Stacks. In 6th USENIX Conference on Offensive Technologies.","author":"Weinmann R.-P.","year":"2012","unstructured":"R.-P. Weinmann. 2012. Baseband Attacks: Remote Exploitation of Memory Corruptions in Cellular Protocol Stacks. In 6th USENIX Conference on Offensive Technologies."},{"key":"e_1_3_2_1_67_1","volume-title":"ACM SIGSAC Conference on Computer and Communications Security.","author":"Wen H.","unstructured":"H.Wen, Z. Lin, and Y. Zhang. 2020. Firmxray: Detecting Bluetooth Link Layer Vulnerabilities from Bare-Metal Firmware. In ACM SIGSAC Conference on Computer and Communications Security."},{"key":"e_1_3_2_1_68_1","volume-title":"BLESA: Spoofing Attacks Against Reconnections in Bluetooth Low Energy. In 14th USENIX Workshop on Offensive Technologies.","author":"Wu J.","unstructured":"J. Wu, Y. Nan, V. Kumar, D. J. Tian, A. Bianchi, M. Payer, and D. Xu. 2020. BLESA: Spoofing Attacks Against Reconnections in Bluetooth Low Energy. In 14th USENIX Workshop on Offensive Technologies."},{"key":"e_1_3_2_1_69_1","volume-title":"Formal Model-driven Discovery of Bluetooth Protocol Design Vulnerabilities. In IEEE Symposium on Security and Privacy.","author":"Wu J.","unstructured":"J. Wu, R. Wu, D. Xu, D. J. Tian, and A. Bianchi. 2022. Formal Model-driven Discovery of Bluetooth Protocol Design Vulnerabilities. In IEEE Symposium on Security and Privacy."},{"key":"e_1_3_2_1_70_1","volume-title":"ACM SIGSAC conference on computer and communications security.","author":"Xu W.","unstructured":"W. Xu, S. Kashyap, C. Min, and T. Kim. 2017. Designing New Operating Primitives to Improve Fuzzing Performance. In ACM SIGSAC conference on computer and communications security."},{"key":"e_1_3_2_1_71_1","volume-title":"Hiding in Plain Signal: Physical Signal Overshadowing Attack on LTE. In 28th USENIX Security Symposium.","author":"Yang H.","unstructured":"H. Yang, S. Bae, M. Son, H. Kim, S. M. Kim, and Y. Kim. 2019. Hiding in Plain Signal: Physical Signal Overshadowing Attack on LTE. In 28th USENIX Security Symposium."},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/3324884.3416572"},{"key":"e_1_3_2_1_73_1","volume-title":"ACM SIGSAC Conference on Computer and Communications Security.","author":"Zuo C.","unstructured":"C. Zuo, H. Wen, Z. Lin, and Y. Zhang. 2019. Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile Apps. In ACM SIGSAC Conference on Computer and Communications Security."}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690312","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3690312","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T06:09:57Z","timestamp":1755842997000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690312"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":73,"alternative-id":["10.1145\/3658644.3690312","10.1145\/3658644"],"URL":"https:\/\/doi.org\/10.1145\/3658644.3690312","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}