- Load the baseband firmware to ida with the
idb-creation
directory. - Find the integrity protection function in the firmware with the
function-identification
directory. - Symbolic execution and automated comparative analysis can be done with the
symbolic-execution
directory.
Specific details are instructed in the README file of each directory.
- Eunsoo Kim (hahah@kaist.ac.kr)
- Min Woo Baek (qqqor@kaist.ac.kr)
- CheolJun Park (fermioncj@kaist.ac.kr)
- Dongkwan Kim (dkay@kaist.ac.kr)
- Yongdae Kim (yongdaek@kaist.ac.kr)
- Insu Yun (insuyun@kaist.ac.kr)
@proceedings{kim:basecomp,
address = {Anaheim, CA},
author = {Eunsoo Kim and Min Woo Baek and CheolJun Park and Dongkwan Kim and Yongdae Kim and Insu Yun},
booktitle = {Proceedings of the 32nd USENIX Security Symposium (Security)},
month = {August},
title = {{BaseComp: A Comparative Analysis for Integrity Protection in Cellular Baseband Software}},
year = {2023}
}