{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,8]],"date-time":"2024-09-08T05:23:49Z","timestamp":1725773029050},"publisher-location":"New York, NY, USA","reference-count":75,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,6,18]]},"DOI":"10.1145\/3581791.3596857","type":"proceedings-article","created":{"date-parts":[[2023,6,16]],"date-time":"2023-06-16T17:52:21Z","timestamp":1686937941000},"page":"205-218","update-policy":"http:\/\/dx.doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["No More Companion Apps Hacking but One Dongle: Hub-Based Blackbox Fuzzing of IoT Firmware"],"prefix":"10.1145","author":[{"ORCID":"http:\/\/orcid.org\/0009-0003-3205-9605","authenticated-orcid":false,"given":"Xiaoyue","family":"Ma","sequence":"first","affiliation":[{"name":"George Mason University, Fairfax, Virginia, USA"}]},{"ORCID":"http:\/\/orcid.org\/0000-0001-9432-6017","authenticated-orcid":false,"given":"Qiang","family":"Zeng","sequence":"additional","affiliation":[{"name":"George Mason University, Fairfax, Virginia, United States"}]},{"ORCID":"http:\/\/orcid.org\/0000-0002-0222-4660","authenticated-orcid":false,"given":"Haotian","family":"Chi","sequence":"additional","affiliation":[{"name":"Shanxi University, Taiyuan, Shanxi, China"}]},{"ORCID":"http:\/\/orcid.org\/0000-0003-2476-7831","authenticated-orcid":false,"given":"Lannan","family":"Luo","sequence":"additional","affiliation":[{"name":"George Mason University, Fairfax, Virginia, United States"}]}],"member":"320","published-online":{"date-parts":[[2023,6,18]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2022. Matter (standard). https:\/\/en.wikipedia.org\/wiki\/Matter_(standard). 2022. Matter (standard). https:\/\/en.wikipedia.org\/wiki\/Matter_(standard)."},{"key":"e_1_3_2_1_2_1","unstructured":"2022. Your home is getting more helpful with Matter and Thread. https:\/\/store.google.com\/intl\/en\/ideas\/articles\/matter-thread-for-your-smart-home\/. 2022. Your home is getting more helpful with Matter and Thread. https:\/\/store.google.com\/intl\/en\/ideas\/articles\/matter-thread-for-your-smart-home\/."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCWS48432.2020.9292382"},{"key":"e_1_3_2_1_4_1","unstructured":"Apple. 2023. Developing Apps and accessories for the home. https:\/\/developer.apple.com\/apple-home\/. Apple. 2023. Developing Apps and accessories for the home. https:\/\/developer.apple.com\/apple-home\/."},{"key":"e_1_3_2_1_5_1","unstructured":"Home Assistant. 2022. Z-Wave JS. https:\/\/www.home-assistant.io\/integrations\/zwave_js\/. Home Assistant. 2022. Z-Wave JS. https:\/\/www.home-assistant.io\/integrations\/zwave_js\/."},{"key":"e_1_3_2_1_6_1","unstructured":"Lina Berzinskas. 2020. Obfuscating Android Apps: Do you know your choices for protection? https:\/\/proandroiddev.com\/obfuscation-is-important-do-you-know-your-options-30b3ef396dfe. Lina Berzinskas. 2020. Obfuscating Android Apps: Do you know your choices for protection? https:\/\/proandroiddev.com\/obfuscation-is-important-do-you-know-your-options-30b3ef396dfe."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427280"},{"volume-title":"Network and Distributed System Security Symposium (NDSS).","year":"2016","author":"Woo Maverick","key":"e_1_3_2_1_8_1","unstructured":"DamingDChen, Maverick Woo , David Brumley , and Manuel Egele . 2016 . Towards automated dynamic analysis for Linux-based embedded firmware . In Network and Distributed System Security Symposium (NDSS). DamingDChen, Maverick Woo, David Brumley, and Manuel Egele. 2016. Towards automated dynamic analysis for Linux-based embedded firmware. In Network and Distributed System Security Symposium (NDSS)."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23159"},{"volume-title":"Network and Distributed System Security Symposium (NDSS).","year":"2021","author":"Chi Haotian","key":"e_1_3_2_1_10_1","unstructured":"Haotian Chi , Qiang Zeng , Xiaojiang Du , and Lannan Luo . 2021 . PFirewall: Semantics-aware customizable data flow control for home automation systems . In Network and Distributed System Security Symposium (NDSS). Haotian Chi, Qiang Zeng, Xiaojiang Du, and Lannan Luo. 2021. PFirewall: Semantics-aware customizable data flow control for home automation systems. In Network and Distributed System Security Symposium (NDSS)."},{"key":"e_1_3_2_1_11_1","unstructured":"Connectivity Standards Alliance. 2022. Building the foundation and future of the IoT. https:\/\/csa-iot.org. Connectivity Standards Alliance. 2022. Building the foundation and future of the IoT. https:\/\/csa-iot.org."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2897845.2897900"},{"volume-title":"USENIX Security Symposium (USENIX Security).","year":"2013","author":"Davidson Drew","key":"e_1_3_2_1_13_1","unstructured":"Drew Davidson , Benjamin Moench , Thomas Ristenpart , and Somesh Jha . 2013 . FIE on firmware: Finding vulnerabilities in embedded systems using symbolic execution . In USENIX Security Symposium (USENIX Security). Drew Davidson, Benjamin Moench, Thomas Ristenpart, and Somesh Jha. 2013. FIE on firmware: Finding vulnerabilities in embedded systems using symbolic execution. In USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"Shuaike Dong Menghao Li Wenrui Diao Xiangyu Liu Jian Liu Zhou Li Fenghao Xu Kai Chen Xiaofeng Wang and Kehuan Zhang. 2018. Understanding Android obfuscation techniques: A large-scale investigation in the wild. In Security and Privacy in Communication Networks. Shuaike Dong Menghao Li Wenrui Diao Xiangyu Liu Jian Liu Zhou Li Fenghao Xu Kai Chen Xiaofeng Wang and Kehuan Zhang. 2018. Understanding Android obfuscation techniques: A large-scale investigation in the wild. In Security and Privacy in Communication Networks.","DOI":"10.1007\/978-3-030-01701-9_10"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2022.3215637"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102889"},{"volume-title":"What is Z-Wave and why is it important for your smart home?","year":"2022","author":"Wave","key":"e_1_3_2_1_17_1","unstructured":"Z- Wave explained : What is Z-Wave and why is it important for your smart home? 2022 . https:\/\/www.the-ambient.com\/guides\/zwave-z-wave-smart-home-guide-281. Z-Wave explained: What is Z-Wave and why is it important for your smart home? 2022. https:\/\/www.the-ambient.com\/guides\/zwave-z-wave-smart-home-guide-281."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978370"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484543"},{"key":"e_1_3_2_1_20_1","unstructured":"GoControl CECOMINOD016164 HUSBZB-1 USB Dongle. 2023. https:\/\/www.amazon.com\/GoControl-CECOMINOD016164-HUSBZB-1-USB-Hub\/dp\/B01GJ826F. GoControl CECOMINOD016164 HUSBZB-1 USB Dongle. 2023. https:\/\/www.amazon.com\/GoControl-CECOMINOD016164-HUSBZB-1-USB-Hub\/dp\/B01GJ826F."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2973043"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSESS49938.2020.9237719"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.011.2000450"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2022.3152364"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134050"},{"key":"e_1_3_2_1_26_1","unstructured":"Home Assistant. 2022. Home Assistant. https:\/\/www.home-assistant.iol. Home Assistant. 2022. Home Assistant. https:\/\/www.home-assistant.iol."},{"key":"e_1_3_2_1_27_1","unstructured":"Home Assistant. 2022. Zigbee Home Automation. https:\/\/www.home-assistant.io\/integrations\/zha\/. Home Assistant. 2022. Zigbee Home Automation. https:\/\/www.home-assistant.io\/integrations\/zha\/."},{"key":"e_1_3_2_1_28_1","unstructured":"Homebridge. 2021. Homebridge HomeKit Control. https:\/\/github.com\/minamoanes\/homebridge-homekit-control. Homebridge. 2021. Homebridge HomeKit Control. https:\/\/github.com\/minamoanes\/homebridge-homekit-control."},{"volume-title":"IoT Gateway Devices Market Revenue to Cross USD 20 Bn by","year":"2027","author":"Global Market Insights Inc. 2021.","key":"e_1_3_2_1_29_1","unstructured":"Global Market Insights Inc. 2021. IoT Gateway Devices Market Revenue to Cross USD 20 Bn by 2027 . https:\/\/www.prnewswire.com\/news-releases\/iot-gateway-devices-market-revenue-to-cross-usd-20-bn-by-2027-global-market-insights-inc-301336087.html. Global Market Insights Inc. 2021. IoT Gateway Devices Market Revenue to Cross USD 20 Bn by 2027. https:\/\/www.prnewswire.com\/news-releases\/iot-gateway-devices-market-revenue-to-cross-usd-20-bn-by-2027-global-market-insights-inc-301336087.html."},{"key":"e_1_3_2_1_30_1","unstructured":"Fortune Business Insights. 2022. Internet of Things Market Size [2022--2029] Worth USD 2465.26 Billion. https:\/\/www.globenewswire.com\/en\/news-release\/2022\/04\/04\/2415728\/0\/en\/Internet-of-Things-Market-Size-2022-2029-Worth-USD-2465-26-Billion-Exhibiting-a-CAGR-of-26-4.html. Fortune Business Insights. 2022. Internet of Things Market Size [2022--2029] Worth USD 2465.26 Billion. https:\/\/www.globenewswire.com\/en\/news-release\/2022\/04\/04\/2415728\/0\/en\/Internet-of-Things-Market-Size-2022-2029-Worth-USD-2465-26-Billion-Exhibiting-a-CAGR-of-26-4.html."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484592"},{"volume-title":"Boofuzz: Network protocol fuzzing for humans. https:\/\/boofuzz.readthedocs.io\/en\/stable\/.","year":"2017","author":"Pereyda Joshua","key":"e_1_3_2_1_32_1","unstructured":"Joshua Pereyda . 2017 . Boofuzz: Network protocol fuzzing for humans. https:\/\/boofuzz.readthedocs.io\/en\/stable\/. Joshua Pereyda. 2017. Boofuzz: Network protocol fuzzing for humans. https:\/\/boofuzz.readthedocs.io\/en\/stable\/."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427294"},{"volume-title":"USENIX Workshop on Offensive Technologies.","year":"2018","author":"Kleber Stephan","key":"e_1_3_2_1_34_1","unstructured":"Stephan Kleber , Henning Kopp , and Frank Kargl . 2018 . NEMESYS: Network message syntax reverse engineering by analysis of the intrinsic structure of individual messages . In USENIX Workshop on Offensive Technologies. Stephan Kleber, Henning Kopp, and Frank Kargl. 2018. NEMESYS: Network message syntax reverse engineering by analysis of the intrinsic structure of individual messages. In USENIX Workshop on Offensive Technologies."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510208"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417286"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-89500-0_28"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/2889160.2889202"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3081333.3081361"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2019.2936561"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3488022"},{"key":"e_1_3_2_1_42_1","unstructured":"Global Z-Wave Automation Market. 2022. https:\/\/www.prophecymarketinsights.com\/market_insight\/Global-Z-Wave-Automation-Market-4593. Global Z-Wave Automation Market. 2022. https:\/\/www.prophecymarketinsights.com\/market_insight\/Global-Z-Wave-Automation-Market-4593."},{"key":"e_1_3_2_1_43_1","unstructured":"Matter-Smarthome. 2023. Benefits of Matter #1: Local connection. https:\/\/matter-smarthome.de\/en\/benefits\/benefits-of-matter-1-local-connection\/. Matter-Smarthome. 2023. Benefits of Matter #1: Local connection. https:\/\/matter-smarthome.de\/en\/benefits\/benefits-of-matter-1-local-connection\/."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00018"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW.2019.00011"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3568562.3568628"},{"key":"e_1_3_2_1_47_1","unstructured":"OpenHAB. 2022. openhab-features-introduction. http:\/\/www.openhab.org\/features\/introduction.html. OpenHAB. 2022. openhab-features-introduction. http:\/\/www.openhab.org\/features\/introduction.html."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00066"},{"key":"e_1_3_2_1_49_1","unstructured":"Sandler Research. 2016. ZigBee Home Automation Market to Grow at 26% CAGR to 202. https:\/\/prn.to\/3jLYLmk. Sandler Research. 2016. ZigBee Home Automation Market to Grow at 26% CAGR to 202. https:\/\/prn.to\/3jLYLmk."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3341105.3373930"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2022.3182589"},{"key":"e_1_3_2_1_52_1","unstructured":"Smartthings. 2022. Z-Wave Command Classes. https:\/\/graph.api.smartthings.com\/ide\/doc\/zwave-utils.html. Smartthings. 2022. Z-Wave Command Classes. https:\/\/graph.api.smartthings.com\/ide\/doc\/zwave-utils.html."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338507.3358616"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN48063.2020.00053"},{"volume-title":"IoT Cyberattacks Escalate","year":"2021","author":"Today T World","key":"e_1_3_2_1_55_1","unstructured":"Io T World Today . 2021. IoT Cyberattacks Escalate in 2021 , According to Kaspersky . https:\/\/www.iotworldtoday.com\/2021\/09\/17\/iot-cyberattacks-escalate-in-2021-according-to-kaspersky\/. IoT World Today. 2021. IoT Cyberattacks Escalate in 2021, According to Kaspersky. https:\/\/www.iotworldtoday.com\/2021\/09\/17\/iot-cyberattacks-escalate-in-2021-according-to-kaspersky\/."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN-W54100.2022.00025"},{"key":"e_1_3_2_1_57_1","unstructured":"Webthings. 2022. https:\/\/webthings.io. Webthings. 2022. https:\/\/webthings.io."},{"key":"e_1_3_2_1_58_1","unstructured":"wireghoul. 2019. Doona. https:\/\/github.com\/wireghoul\/doona. wireghoul. 2019. Doona. https:\/\/github.com\/wireghoul\/doona."},{"key":"e_1_3_2_1_59_1","unstructured":"Wltd. 2020. How to Easily Use a Raspberry Pi as a Homekit Hub. https:\/\/wltd.org\/posts\/how-to-easily-use-a-raspberry-pi-as-a-homekit-hub. Wltd. 2020. How to Easily Use a Raspberry Pi as a Homekit Hub. https:\/\/wltd.org\/posts\/how-to-easily-use-a-raspberry-pi-as-a-homekit-hub."},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIS54925.2022.9882418"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-29959-0_31"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.3390\/app11199094"},{"volume-title":"Which Is Better For Your Smart Home?","year":"2022","author":"ZigBee Z Wave Vs","key":"e_1_3_2_1_63_1","unstructured":"Z Wave Vs ZigBee : Which Is Better For Your Smart Home? 2022 . https:\/\/thesmartcave.com\/z-wave-vs-zigbee-home-automation\/. Z Wave Vs ZigBee: Which Is Better For Your Smart Home? 2022. https:\/\/thesmartcave.com\/z-wave-vs-zigbee-home-automation\/."},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23229"},{"volume-title":"Proc. ACM International Symposium on Code Generation and Optimization (CGO).","year":"2018","author":"Zeng Qiang","key":"e_1_3_2_1_65_1","unstructured":"Qiang Zeng , Lannan Luo , Zhiyun Qian , Xiaojiang Du , and Zhoujun Li . 2018 . Resilient decentralized Android application repackaging detection using logic bombs . In Proc. ACM International Symposium on Code Generation and Optimization (CGO). Qiang Zeng, Lannan Luo, Zhiyun Qian, Xiaojiang Du, and Zhoujun Li. 2018. Resilient decentralized Android application repackaging detection using logic bombs. In Proc. ACM International Symposium on Code Generation and Optimization (CGO)."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243820"},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-022-00120-1"},{"volume-title":"USENIX Security Symposium (USENIX Security).","year":"2019","author":"Zheng Yaowen","key":"e_1_3_2_1_68_1","unstructured":"Yaowen Zheng , Ali Davanian , Heng Yin , Chengyu Song , Hongsong Zhu , and Limin Sun . 2019 . FIRM-AFL: High-throughput greybox fuzzing of IoT firmware via augmented process emulation . In USENIX Security Symposium (USENIX Security). Yaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song, Hongsong Zhu, and Limin Sun. 2019. FIRM-AFL: High-throughput greybox fuzzing of IoT firmware via augmented process emulation. In USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/3533767.3534414"},{"volume-title":"USENIX Security Symposium (USENIX Security).","year":"2021","author":"Zhou Wei","key":"e_1_3_2_1_70_1","unstructured":"Wei Zhou , Le Guan , Peng Liu , and Yuqing Zhang . 2021 . Automatic firmware emulation through invalidity-guided knowledge inference . In USENIX Security Symposium (USENIX Security). Wei Zhou, Le Guan, Peng Liu, and Yuqing Zhang. 2021. Automatic firmware emulation through invalidity-guided knowledge inference. In USENIX Security Symposium (USENIX Security)."},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559386"},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom\/BigDataSE.2019.00041"},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/3512345"},{"key":"e_1_3_2_1_74_1","unstructured":"ZigBee. 2022. ZigBee Cluster Library Specification. https:\/\/zigbeealliance.org\/wp-content\/uploads\/2019\/12\/07-5123-06-zigbee-cluster-library-specification.pdf. ZigBee. 2022. ZigBee Cluster Library Specification. https:\/\/zigbeealliance.org\/wp-content\/uploads\/2019\/12\/07-5123-06-zigbee-cluster-library-specification.pdf."},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23492"}],"event":{"name":"MobiSys '23: 21st Annual International Conference on Mobile Systems, Applications and Services","sponsor":["SIGMOBILE ACM Special Interest Group on Mobility of Systems, Users, Data and Computing","SIGOPS ACM Special Interest Group on Operating Systems"],"location":"Helsinki Finland","acronym":"MobiSys '23"},"container-title":["Proceedings of the 21st Annual International Conference on Mobile Systems, Applications and Services"],"original-title":[],"deposited":{"date-parts":[[2023,6,18]],"date-time":"2023-06-18T00:48:07Z","timestamp":1687049287000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3581791.3596857"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,6,18]]},"references-count":75,"alternative-id":["10.1145\/3581791.3596857","10.1145\/3581791"],"URL":"https:\/\/doi.org\/10.1145\/3581791.3596857","relation":{},"subject":[],"published":{"date-parts":[[2023,6,18]]},"assertion":[{"value":"2023-06-18","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}