Graduation Year
2024
Document Type
Thesis
Degree
M.S.C.S.
Degree Name
MS in Computer Science (M.S.C.S.)
Degree Granting Department
Computer Science and Engineering
Major Professor
Robert Karam, Ph.D.
Committee Member
Jarred Ligatti, Ph.D.
Committee Member
Yao Liu, Ph.D.
Keywords
Analysis, Cyber, Emulation, Fuzzing, Security
Abstract
System-on-chip (SoC) devices in the form of routers, access points, and smart appliances have become an increasingly prevalent aspect of our infrastructure. Performing vulnerability research on these devices may be exceptionally difficult given the on-hardware limitations, inability to guarantee certain aspects of the system, and lack of information when the appliance’s source code is not available.In this thesis, we present Broadfeather, a QEMU-based emulation target, and framework for dynamic analysis and instrumentation. While Broadfeather supports data types shared across many chips under the Broadcom umbrella, it is primarily geared towards the BCM6755 Wi-Fi 6E capable chipset. Broadfeather also features the ability to simulate received packets on the device’s side in the form of Linux network buffers. Paired with the ability to remap the PCI register locations, almost any Broadcom compatible wireless chipset can be targeted with the appropriate drivers. Through Broadfeather, we were able to discover several crashes in the internal Broadcom wireless packet frame handling that are outside the purview of a normal attacker.
Scholar Commons Citation
Little, Christian Shane Douglas, "Vulnerability Discovery on Broadcom Devices with QEMU" (2024). USF Tampa Graduate Theses and Dissertations.
https://digitalcommons.usf.edu/etd/11188
