Graduation Year

2024

Document Type

Thesis

Degree

M.S.C.S.

Degree Name

MS in Computer Science (M.S.C.S.)

Degree Granting Department

Computer Science and Engineering

Major Professor

Robert Karam, Ph.D.

Committee Member

Jarred Ligatti, Ph.D.

Committee Member

Yao Liu, Ph.D.

Keywords

Analysis, Cyber, Emulation, Fuzzing, Security

Abstract

System-on-chip (SoC) devices in the form of routers, access points, and smart appliances have become an increasingly prevalent aspect of our infrastructure. Performing vulnerability research on these devices may be exceptionally difficult given the on-hardware limitations, inability to guarantee certain aspects of the system, and lack of information when the appliance’s source code is not available.In this thesis, we present Broadfeather, a QEMU-based emulation target, and framework for dynamic analysis and instrumentation. While Broadfeather supports data types shared across many chips under the Broadcom umbrella, it is primarily geared towards the BCM6755 Wi-Fi 6E capable chipset. Broadfeather also features the ability to simulate received packets on the device’s side in the form of Linux network buffers. Paired with the ability to remap the PCI register locations, almost any Broadcom compatible wireless chipset can be targeted with the appropriate drivers. Through Broadfeather, we were able to discover several crashes in the internal Broadcom wireless packet frame handling that are outside the purview of a normal attacker.

Share

COinS