0

Function-Level Fuzzing for RTOS Kernels with RTCon

Real-Time Operating Systems (RTOS) are widely used in embedded systems to support functionalities such as Bluetooth and Wi-Fi. As RTOS kernels grow in functionality, their attack surface also expands, increasing the need for effective security …

RTCon: Context-Adaptive Function-Level Fuzzing for RTOS Kernels

Real-Time Operating System (RTOS) is widely used in embedded systems with its various subsystems such as Bluetooth and Wi-Fi. As its functionalities grow, its attack surface also expands, exposing it to more security threats. To address this, dynamic …

OTABase: Enhancing Over-the-Air Testing to Detect Memory Crashes in Cellular Basebands

Bridging the Gap between Real-World and Formal Binary Lifting through Filtered-Simulation

CROSS-X: Generalized and Stable Cross-Cache Attack on the Linux Kernel

The cross-cache attack is a fundamental component of modern Linux kernel exploits, spanning real-world attacks and recent research. Despite its importance, it is often regarded as unreliable due to its complex setup, and existing studies lack …

Windows plays Jenga: Uncovering Design Weaknesses in Windows File System Security

File systems are essential components of modern operating systems, with Windows being one of the most dominant platforms. Recently, a series of attacks have exploited the Windows file system to trigger serious security threats such as privilege …

ATLANTIS: AI-driven Threat Localization, Analysis, and Triage Intelligence System

LLFuzz: An Over-the-Air Dynamic Testing Framework for Cellular Baseband Lower Layers

Memory corruptions in cellular basebands are critical because they can be remotely exploited over-the-air, resulting in severe consequences such as remote code execution, denial of service, and information leakage. While previous research has made …

Too Much of a Good Thing: (In-)Security of Mandatory Security Software for Financial Services in South Korea

Automated Attack Synthesis for Constant Product Market Makers

Decentralized Finance (DeFi) enables many novel applications that were impossible in traditional finances. However, it also introduces new types of vulnerabilities. An example of such vulnerabilities is a composability bug between token contracts and …