{"id":"https://openalex.org/W2990286122","doi":"https://doi.org/10.1145/3359789.3359833","title":"Opening Pandora's box through ATFuzzer","display_name":"Opening Pandora's box through ATFuzzer","publication_year":2019,"publication_date":"2019-11-22","ids":{"openalex":"https://openalex.org/W2990286122","doi":"https://doi.org/10.1145/3359789.3359833","mag":"2990286122"},"language":"en","primary_location":{"id":"doi:10.1145/3359789.3359833","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3359789.3359833","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3359789.3359833","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 35th Annual Computer Security Applications Conference","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3359789.3359833","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5055415819","display_name":"Imtiaz Karim","orcid":"https://orcid.org/0009-0000-8680-9932"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Imtiaz Karim","raw_affiliation_strings":["Purdue University"],"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5056918306","display_name":"Fabrizio Cicala","orcid":null},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Fabrizio Cicala","raw_affiliation_strings":["Purdue University"],"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5053169357","display_name":"Syed Rafiul Hussain","orcid":"https://orcid.org/0000-0001-9222-8544"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Syed Rafiul Hussain","raw_affiliation_strings":["Purdue University"],"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5070136662","display_name":"Omar Chowdhury","orcid":"https://orcid.org/0000-0002-1356-6279"},"institutions":[{"id":"https://openalex.org/I126307644","display_name":"University of Iowa","ror":"https://ror.org/036jqmy94","country_code":"US","type":"education","lineage":["https://openalex.org/I126307644"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Omar Chowdhury","raw_affiliation_strings":["University of Iowa"],"affiliations":[{"raw_affiliation_string":"University of Iowa","institution_ids":["https://openalex.org/I126307644"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5061694501","display_name":"Elisa Bertino","orcid":"https://orcid.org/0000-0002-4029-7051"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Elisa Bertino","raw_affiliation_strings":["Purdue University"],"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5055415819"],"corresponding_institution_ids":["https://openalex.org/I219193219"],"apc_list":null,"apc_paid":null,"fwci":1.5027,"has_fulltext":true,"cited_by_count":12,"citation_normalized_percentile":{"value":0.83737066,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"529","last_page":"543"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9980000257492065,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9980000257492065,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12801","display_name":"Bluetooth and Wireless Communication Technologies","score":0.9979000091552734,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":0.9900000095367432,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8192524909973145},{"id":"https://openalex.org/keywords/fuzz-testing","display_name":"Fuzz testing","score":0.6294283270835876},{"id":"https://openalex.org/keywords/bluetooth","display_name":"Bluetooth","score":0.5681434869766235},{"id":"https://openalex.org/keywords/android","display_name":"Android (operating system)","score":0.4742126762866974},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.44353970885276794},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.42652595043182373},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.37734436988830566},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.33893024921417236},{"id":"https://openalex.org/keywords/wireless","display_name":"Wireless","score":0.2113570272922516}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8192524909973145},{"id":"https://openalex.org/C111065885","wikidata":"https://www.wikidata.org/wiki/Q1189053","display_name":"Fuzz testing","level":3,"score":0.6294283270835876},{"id":"https://openalex.org/C546215728","wikidata":"https://www.wikidata.org/wiki/Q39531","display_name":"Bluetooth","level":3,"score":0.5681434869766235},{"id":"https://openalex.org/C557433098","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android (operating system)","level":2,"score":0.4742126762866974},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.44353970885276794},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.42652595043182373},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.37734436988830566},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.33893024921417236},{"id":"https://openalex.org/C555944384","wikidata":"https://www.wikidata.org/wiki/Q249","display_name":"Wireless","level":2,"score":0.2113570272922516},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3359789.3359833","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3359789.3359833","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3359789.3359833","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 35th Annual Computer Security Applications Conference","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3359789.3359833","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3359789.3359833","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3359789.3359833","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 35th Annual Computer Security Applications Conference","raw_type":"proceedings-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.6800000071525574}],"awards":[{"id":"https://openalex.org/G1519062775","display_name":null,"funder_award_id":"CNS-1719369","funder_id":"https://openalex.org/F4320309036","funder_display_name":"Purdue University"},{"id":"https://openalex.org/G2593570677","display_name":null,"funder_award_id":"1719369","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G5734778976","display_name":null,"funder_award_id":"CNS-1657124 and CNS-1719369","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G6163323745","display_name":null,"funder_award_id":"1657124","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G7648038792","display_name":null,"funder_award_id":"CNS-1719369","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320309036","display_name":"Purdue University","ror":"https://ror.org/02dqehb95"},{"id":"https://openalex.org/F4320309667","display_name":"Purdue Research Foundation","ror":"https://ror.org/007n03h88"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2990286122.pdf","grobid_xml":"https://content.openalex.org/works/W2990286122.grobid-xml"},"referenced_works_count":31,"referenced_works":["https://openalex.org/W30083809","https://openalex.org/W1509550796","https://openalex.org/W1531203382","https://openalex.org/W2002934700","https://openalex.org/W2122653500","https://openalex.org/W2181314567","https://openalex.org/W2323346483","https://openalex.org/W2507581487","https://openalex.org/W2514248757","https://openalex.org/W2515735900","https://openalex.org/W2519952770","https://openalex.org/W2558800662","https://openalex.org/W2613534458","https://openalex.org/W2701225458","https://openalex.org/W2741068848","https://openalex.org/W2751509862","https://openalex.org/W2752340395","https://openalex.org/W2757104921","https://openalex.org/W2766540688","https://openalex.org/W2792636363","https://openalex.org/W2794670092","https://openalex.org/W2865298191","https://openalex.org/W2883222613","https://openalex.org/W2899781671","https://openalex.org/W2908016018","https://openalex.org/W2932741641","https://openalex.org/W2947003210","https://openalex.org/W2964241064","https://openalex.org/W3104664063","https://openalex.org/W4289038676","https://openalex.org/W4302445198"],"related_works":["https://openalex.org/W2511770387","https://openalex.org/W3120811337","https://openalex.org/W3203597304","https://openalex.org/W4385301282","https://openalex.org/W2990186179","https://openalex.org/W4248424560","https://openalex.org/W3023977444","https://openalex.org/W4210660460","https://openalex.org/W1565885216","https://openalex.org/W2386849235"],"abstract_inverted_index":{"This":[0],"paper":[1],"focuses":[2],"on":[3,104],"checking":[4],"the":[5,10,16,39,91,146,160],"correctness":[6],"and":[7,22,69,119,157,169],"robustness":[8],"of":[9,90,96,129,159],"AT":[11,36,92,98,114,148],"command":[12,93,115,149],"interface":[13,30,55],"exposed":[14],"by":[15,59],"cellular":[17,44,130],"baseband":[18,40],"processor":[19,27,41],"through":[20],"Bluetooth":[21,61,118],"USB.":[23],"A":[24],"device's":[25],"application":[26],"uses":[28,80],"this":[29,54],"for":[31,42],"issuing":[32],"high-level":[33],"commands":[34],"(or,":[35],"commands)":[37],"to":[38,63,136,138,154],"performing":[43],"network":[45],"operations":[46],"(e.g.,":[47,133],"placing":[48],"a":[49,81],"phone":[50],"call).":[51],"Vulnerabilities":[52],"in":[53],"can":[56],"be":[57],"leveraged":[58],"malicious":[60],"peripherals":[62],"launch":[64],"pernicious":[65],"attacks":[66],"including":[67],"DoS":[68],"privacy":[70,140],"attacks.":[71],"To":[72],"identify":[73],"such":[74],"vulnerabilities,":[75],"we":[76],"propose":[77],"ATFuzzer":[78,103],"that":[79],"grammar-guided":[82],"evolutionary":[83],"fuzzing":[84],"approach":[85],"which":[86],"mutates":[87],"production":[88],"rules":[89],"grammar":[94],"instead":[95],"concrete":[97],"commands.":[99],"Empirical":[100],"evaluation":[101],"with":[102,123,145],"10":[105],"Android":[106],"smartphones":[107],"from":[108,126,134],"6":[109],"vendors":[110,156],"revealed":[111],"4":[112],"invalid":[113,147],"grammars":[116,150],"over":[117,121],"13":[120],"USB":[122],"implications":[124],"ranging":[125],"DoS,":[127],"downgrade":[128],"protocol":[131],"version":[132],"4G":[135],"3G/2G)":[137],"severe":[139],"leaks.":[141],"The":[142],"vulnerabilities":[143,162],"along":[144],"were":[151],"responsibly":[152],"disclosed":[153],"affected":[155],"two":[158],"reported":[161],"have":[163],"been":[164],"already":[165],"assigned":[166],"CVEs":[167],"(CVE-2019-16400":[168],"CVE-2019-16401).":[170]},"counts_by_year":[{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":1},{"year":2022,"cited_by_count":3},{"year":2021,"cited_by_count":3},{"year":2020,"cited_by_count":3}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2025-10-10T00:00:00"}
