{"id":"https://openalex.org/W4382396147","doi":"https://doi.org/10.1145/3558482.3590174","title":"Owfuzz: Discovering Wi-Fi Flaws in Modern Devices through Over-The-Air Fuzzing","display_name":"Owfuzz: Discovering Wi-Fi Flaws in Modern Devices through Over-The-Air Fuzzing","publication_year":2023,"publication_date":"2023-05-29","ids":{"openalex":"https://openalex.org/W4382396147","doi":"https://doi.org/10.1145/3558482.3590174"},"language":"en","primary_location":{"id":"doi:10.1145/3558482.3590174","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3558482.3590174","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 16th ACM Conference on Security and Privacy in Wireless and Mobile Networks","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5034616538","display_name":"Hui Quan Cao","orcid":"https://orcid.org/0009-0007-4842-2121"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Hongjian Cao","raw_affiliation_strings":["Ant Group, Beijing, China"],"raw_orcid":"https://orcid.org/0009-0007-4842-2121","affiliations":[{"raw_affiliation_string":"Ant Group, Beijing, China","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5041205504","display_name":"Lin Huang","orcid":"https://orcid.org/0009-0002-5659-1471"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Lin Huang","raw_affiliation_strings":["Ant Group, Beijing, China"],"raw_orcid":"https://orcid.org/0009-0002-5659-1471","affiliations":[{"raw_affiliation_string":"Ant Group, Beijing, China","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5063082602","display_name":"Shuwei Hu","orcid":"https://orcid.org/0000-0002-1819-3723"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Shuwei Hu","raw_affiliation_strings":["Ant Group, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0002-1819-3723","affiliations":[{"raw_affiliation_string":"Ant Group, Beijing, China","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5088295801","display_name":"Shangcheng Shi","orcid":"https://orcid.org/0000-0002-6887-1422"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Shangcheng Shi","raw_affiliation_strings":["Ant Group, Hangzhou, China"],"raw_orcid":"https://orcid.org/0000-0002-6887-1422","affiliations":[{"raw_affiliation_string":"Ant Group, Hangzhou, China","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5071228156","display_name":"Y. Liu","orcid":"https://orcid.org/0009-0005-6603-1592"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yujia Liu","raw_affiliation_strings":["Ant Group, Beijing, China"],"raw_orcid":"https://orcid.org/0009-0005-6603-1592","affiliations":[{"raw_affiliation_string":"Ant Group, Beijing, China","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":2.0862,"has_fulltext":false,"cited_by_count":11,"citation_normalized_percentile":{"value":0.87655218,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"263","last_page":"273"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11158","display_name":"Wireless Networks and Protocols","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11158","display_name":"Wireless Networks and Protocols","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11392","display_name":"Energy Harvesting in Wireless Networks","score":0.9987000226974487,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10080","display_name":"Energy Efficient Wireless Sensor Networks","score":0.9962999820709229,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/fuzz-testing","display_name":"Fuzz testing","score":0.9943256378173828},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.81253981590271},{"id":"https://openalex.org/keywords/firmware","display_name":"Firmware","score":0.6719090342521667},{"id":"https://openalex.org/keywords/emulation","display_name":"Emulation","score":0.618867039680481},{"id":"https://openalex.org/keywords/vendor","display_name":"Vendor","score":0.5089876651763916},{"id":"https://openalex.org/keywords/frame","display_name":"Frame (networking)","score":0.43797609210014343},{"id":"https://openalex.org/keywords/protocol","display_name":"Protocol (science)","score":0.4353470206260681},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3524113595485687},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.2091229259967804},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.16871672868728638},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.14736983180046082}],"concepts":[{"id":"https://openalex.org/C111065885","wikidata":"https://www.wikidata.org/wiki/Q1189053","display_name":"Fuzz testing","level":3,"score":0.9943256378173828},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.81253981590271},{"id":"https://openalex.org/C67212190","wikidata":"https://www.wikidata.org/wiki/Q104851","display_name":"Firmware","level":2,"score":0.6719090342521667},{"id":"https://openalex.org/C149810388","wikidata":"https://www.wikidata.org/wiki/Q5374873","display_name":"Emulation","level":2,"score":0.618867039680481},{"id":"https://openalex.org/C2777338717","wikidata":"https://www.wikidata.org/wiki/Q1762621","display_name":"Vendor","level":2,"score":0.5089876651763916},{"id":"https://openalex.org/C126042441","wikidata":"https://www.wikidata.org/wiki/Q1324888","display_name":"Frame (networking)","level":2,"score":0.43797609210014343},{"id":"https://openalex.org/C2780385302","wikidata":"https://www.wikidata.org/wiki/Q367158","display_name":"Protocol (science)","level":3,"score":0.4353470206260681},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3524113595485687},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.2091229259967804},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.16871672868728638},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.14736983180046082},{"id":"https://openalex.org/C162853370","wikidata":"https://www.wikidata.org/wiki/Q39809","display_name":"Marketing","level":1,"score":0.0},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.0},{"id":"https://openalex.org/C50522688","wikidata":"https://www.wikidata.org/wiki/Q189833","display_name":"Economic growth","level":1,"score":0.0},{"id":"https://openalex.org/C71924100","wikidata":"https://www.wikidata.org/wiki/Q11190","display_name":"Medicine","level":0,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0},{"id":"https://openalex.org/C142724271","wikidata":"https://www.wikidata.org/wiki/Q7208","display_name":"Pathology","level":1,"score":0.0},{"id":"https://openalex.org/C204787440","wikidata":"https://www.wikidata.org/wiki/Q188504","display_name":"Alternative medicine","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3558482.3590174","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3558482.3590174","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 16th ACM Conference on Security and Privacy in Wireless and Mobile Networks","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":14,"referenced_works":["https://openalex.org/W1548327136","https://openalex.org/W2014936340","https://openalex.org/W2123016006","https://openalex.org/W2144880325","https://openalex.org/W2165083187","https://openalex.org/W2167862664","https://openalex.org/W2810261900","https://openalex.org/W3043946492","https://openalex.org/W3048340936","https://openalex.org/W3101417019","https://openalex.org/W3177447580","https://openalex.org/W4247442619","https://openalex.org/W4289387434","https://openalex.org/W4299317891"],"related_works":["https://openalex.org/W2511770387","https://openalex.org/W3111743984","https://openalex.org/W3118666763","https://openalex.org/W4378976979","https://openalex.org/W4312439535","https://openalex.org/W3207216830","https://openalex.org/W3037057426","https://openalex.org/W4362015489","https://openalex.org/W4378373752","https://openalex.org/W1986252697"],"abstract_inverted_index":{"Fuzzing":[0],"is":[1],"a":[2,29,53,69],"practical":[3],"approach":[4],"to":[5,46,129,152,165,179,182],"discovering":[6],"flaws":[7,164],"in":[8,117],"the":[9,87,121,142,153,166,180],"design":[10],"and":[11,34,48,55,103,114,148],"implementation":[12],"of":[13,31,40,109,120,133,144,155,162],"Wi-Fi":[14,18,41,61,98,110,146],"protocols.":[15],"However,":[16],"existing":[17],"fuzzers":[19],"are":[20],"either":[21],"vendor-":[22],"or":[23,82],"ecosystem-specific.":[24],"Besides,":[25],"they":[26],"only":[27],"cover":[28],"subset":[30],"802.11":[32,122],"protocols":[33],"frame":[35],"types.":[36],"The":[37],"growing":[38],"complexity":[39],"protocols,":[42],"which":[43],"have":[44,140,159,176],"evolved":[45],"Wi-Fi6":[47],"WPA3":[49],"already,":[50],"calls":[51],"for":[52,59],"free":[54],"comprehensive":[56],"fuzzing":[57,70,81,89,94],"tool":[58,71],"modern":[60],"devices.":[62],"In":[63],"this":[64],"paper,":[65],"we":[66,139,175],"present":[67],"such":[68],"named":[72],"Owfuzz.":[73],"Unlike":[74],"previous":[75],"works":[76],"using":[77],"mostly":[78],"firmware":[79],"emulation":[80],"driver":[83],"fuzzing,":[84],"Owfuzz":[85,178],"takes":[86],"over-the-air":[88],"approach.":[90],"It":[91,124],"can":[92,104,125],"perform":[93],"tests":[95],"on":[96],"arbitrary":[97],"devices":[99],"from":[100],"any":[101],"vendor":[102],"fuzz":[105],"all":[106,118],"three":[107],"types":[108],"frames":[111],"(management,":[112],"control,":[113],"data)":[115],"defined":[116],"versions":[119],"standards.":[123],"be":[126],"easily":[127],"extended":[128],"support":[130],"interactive":[131],"testing":[132],"various":[134],"protocol":[135],"models.":[136],"With":[137],"Owfuzz,":[138],"tested":[141],"products":[143],"mainstream":[145],"chip":[147],"device":[149],"vendors,":[150],"leading":[151],"discovery":[154],"23":[156],"flaws.":[157],"We":[158],"reported":[160],"most":[161],"these":[163],"related":[167],"vendors":[168],"with":[169],"8":[170],"CVE":[171],"IDs":[172],"assigned.":[173],"Moreover,":[174],"open-sourced":[177],"community":[181],"facilitate":[183],"future":[184],"research.":[185]},"counts_by_year":[{"year":2026,"cited_by_count":3},{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":4},{"year":2023,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
