Latest commit

History

6 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

BLEDiff

This repository contains the open source implementation of BLEDiff, an automated, scalable, property-agnostic, and black-box protocol noncompliance checking framework for Bluetooth Low Energy (BLE) devices.

System requirements

  • Ubuntu 18.04 machine (tested OS)
  • Python 2.7
  • nRF52480 dongle

Setup

Setup environment

sudo chmod +x ./setup.sh
sudo ./setup.sh
cd fsm_inference_module/ble_controller/bluetooth/smp_server/
/usr/bin/python2.7 setup.py build
sudo /usr/bin/python2.7 setup.py install
mkdir -p ~/.local/lib/python2.7/site-packages/
cp dist/BLESMPServer-1.0.1-py2.7-linux-x86_64.egg ~/.local/lib/python2.7/site-packages
cd ../../

Setup nRF52480

  • Install nRF Connect for Desktop from Nordic website
  • You will need to write the provided hex files to the nRF5280 dongle. You can do this on windows or ubuntu. Windows is more preferable.
  • To do this on ubuntu, run the nRF connect in sudo mode and add --no-sandbox flag
  • Run the Programmer app from nRF connect
  • Connect nRF52480 in DFU mode and write the two files from nRF52480_hex_files/
  • After writing the hex files, remove the device from workstation and reconnect it.
  • To test the Android device, you will need to install the nRF Connect for Mobile app on your device.

Setup configurations

  • If the device under test uses static address, change "SlaveAddress" and "SlaveAddressType" at fsm_inference_module/ble_controller/addr_config.json file.
  • Change device properties at fsm_inference_module/statelearner/src/ble.properties file.

Device specific changes

  • Add another switch case in fsm_inference_module/statelearner/src/main/java/ble/statelearner/ble/devices/Device_SUL_Factory.java and implement the corresponding file replicating fsm_inference_module/statelearner/src/main/java/ble/statelearner/ble/devices/Device_SUL_Factory.java.
  • Implement the reset and device interaction routines in fsm_inference_module/device_controller/controller.py following nexus6 case.

Run FSM Inference Module

  • Run the BLEController:
cd fsm_inference_module/ble_controller/
sudo /usr/bin/python2.7 ble_central.py
  • Run the device controller:
cd fsm_inference_module/device_controller/
sudo /usr/bin/python2.7 controller.py l <device>
  • Compile and run the statelearner:
cd fsm_inference_module/statelearner/
mvn package
sudo java -jar target/stateLearner-0.0.1-SNAPSHOT.jar src/ble.properties

Citation

@INPROCEEDINGS {blediff,
author = {I. Karim and A. Ishtiaq and S. Hussain and E. Bertino},
booktitle = {2023 2023 IEEE Symposium on Security and Privacy (SP) (SP)},
title = {BLEDiff : Scalable and Property-Agnostic Noncompliance Checking for BLE Implementations},
year = {2023},
volume = {},
issn = {},
pages = {1082-1100},
abstract = {In this work, we develop an automated, scalable, property-agnostic, and black-box protocol noncompliance checking framework called BLEDiff that can analyze and uncover noncompliant behavior in the Bluetooth Low Energy (BLE) protocol implementations. To overcome the enormous manual effort of extracting BLE protocol reference behavioral abstraction and security properties from a large and complex BLE specification, BLEDiff takes advantage of having access to multiple BLE devices and leverages the concept of differential testing to automatically identify deviant noncompliant behavior. In this regard, BLEDiff first automatically extracts the protocol FSM of a BLE implementation using the active automata learning approach. To improve the scalability of active automata learning for the large and complex BLE protocol, BLEDiff explores the idea of using a divide and conquer approach. BLEDiff essentially divides the BLE protocol into multiple sub-protocols, identifies their dependencies and extracts the FSM of each sub-protocol separately, and finally composes them to create the large protocol FSM. These FSMs are then pair-wise tested to automatically identify diverse deviations. We evaluate BLEDiff with 25 different commercial devices and demonstrate it can uncover 13 different deviant behaviors with 10 exploitable attacks.},
keywords = {bluetooth-low-energy;noncompliance-checking;implementation-security},
doi = {10.1109/SP46215.2023.00062},
url = {https://doi.ieeecomputersociety.org/10.1109/SP46215.2023.00062},
publisher = {IEEE Computer Society},
address = {Los Alamitos, CA, USA},
month = {may}
}

Acknowledgement

We acknowledge LearnLib for the active automata learning framework and SweynTooth for the implementation of BLE central.

About

BLEDiff is an automated, scalable, property-agnostic, and black-box protocol noncompliance checker for BLE devices.

Topics

Resources

Stars

13 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Latest commit

History

6 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

BLEDiff

This repository contains the open source implementation of BLEDiff, an automated, scalable, property-agnostic, and black-box protocol noncompliance checking framework for Bluetooth Low Energy (BLE) devices.

System requirements

  • Ubuntu 18.04 machine (tested OS)
  • Python 2.7
  • nRF52480 dongle

Setup

Setup environment

sudo chmod +x ./setup.sh
sudo ./setup.sh
cd fsm_inference_module/ble_controller/bluetooth/smp_server/
/usr/bin/python2.7 setup.py build
sudo /usr/bin/python2.7 setup.py install
mkdir -p ~/.local/lib/python2.7/site-packages/
cp dist/BLESMPServer-1.0.1-py2.7-linux-x86_64.egg ~/.local/lib/python2.7/site-packages
cd ../../

Setup nRF52480

  • Install nRF Connect for Desktop from Nordic website
  • You will need to write the provided hex files to the nRF5280 dongle. You can do this on windows or ubuntu. Windows is more preferable.
  • To do this on ubuntu, run the nRF connect in sudo mode and add --no-sandbox flag
  • Run the Programmer app from nRF connect
  • Connect nRF52480 in DFU mode and write the two files from nRF52480_hex_files/
  • After writing the hex files, remove the device from workstation and reconnect it.
  • To test the Android device, you will need to install the nRF Connect for Mobile app on your device.

Setup configurations

  • If the device under test uses static address, change "SlaveAddress" and "SlaveAddressType" at fsm_inference_module/ble_controller/addr_config.json file.
  • Change device properties at fsm_inference_module/statelearner/src/ble.properties file.

Device specific changes

  • Add another switch case in fsm_inference_module/statelearner/src/main/java/ble/statelearner/ble/devices/Device_SUL_Factory.java and implement the corresponding file replicating fsm_inference_module/statelearner/src/main/java/ble/statelearner/ble/devices/Device_SUL_Factory.java.
  • Implement the reset and device interaction routines in fsm_inference_module/device_controller/controller.py following nexus6 case.

Run FSM Inference Module

  • Run the BLEController:
cd fsm_inference_module/ble_controller/
sudo /usr/bin/python2.7 ble_central.py
  • Run the device controller:
cd fsm_inference_module/device_controller/
sudo /usr/bin/python2.7 controller.py l <device>
  • Compile and run the statelearner:
cd fsm_inference_module/statelearner/
mvn package
sudo java -jar target/stateLearner-0.0.1-SNAPSHOT.jar src/ble.properties

Citation

@INPROCEEDINGS {blediff,
author = {I. Karim and A. Ishtiaq and S. Hussain and E. Bertino},
booktitle = {2023 2023 IEEE Symposium on Security and Privacy (SP) (SP)},
title = {BLEDiff : Scalable and Property-Agnostic Noncompliance Checking for BLE Implementations},
year = {2023},
volume = {},
issn = {},
pages = {1082-1100},
abstract = {In this work, we develop an automated, scalable, property-agnostic, and black-box protocol noncompliance checking framework called BLEDiff that can analyze and uncover noncompliant behavior in the Bluetooth Low Energy (BLE) protocol implementations. To overcome the enormous manual effort of extracting BLE protocol reference behavioral abstraction and security properties from a large and complex BLE specification, BLEDiff takes advantage of having access to multiple BLE devices and leverages the concept of differential testing to automatically identify deviant noncompliant behavior. In this regard, BLEDiff first automatically extracts the protocol FSM of a BLE implementation using the active automata learning approach. To improve the scalability of active automata learning for the large and complex BLE protocol, BLEDiff explores the idea of using a divide and conquer approach. BLEDiff essentially divides the BLE protocol into multiple sub-protocols, identifies their dependencies and extracts the FSM of each sub-protocol separately, and finally composes them to create the large protocol FSM. These FSMs are then pair-wise tested to automatically identify diverse deviations. We evaluate BLEDiff with 25 different commercial devices and demonstrate it can uncover 13 different deviant behaviors with 10 exploitable attacks.},
keywords = {bluetooth-low-energy;noncompliance-checking;implementation-security},
doi = {10.1109/SP46215.2023.00062},
url = {https://doi.ieeecomputersociety.org/10.1109/SP46215.2023.00062},
publisher = {IEEE Computer Society},
address = {Los Alamitos, CA, USA},
month = {may}
}

Acknowledgement

We acknowledge LearnLib for the active automata learning framework and SweynTooth for the implementation of BLE central.

About

BLEDiff is an automated, scalable, property-agnostic, and black-box protocol noncompliance checker for BLE devices.

Topics

Resources

Stars

13 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

6 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

BLEDiff

This repository contains the open source implementation of BLEDiff, an automated, scalable, property-agnostic, and black-box protocol noncompliance checking framework for Bluetooth Low Energy (BLE) devices.

System requirements

  • Ubuntu 18.04 machine (tested OS)
  • Python 2.7
  • nRF52480 dongle

Setup

Setup environment

sudo chmod +x ./setup.sh
sudo ./setup.sh
cd fsm_inference_module/ble_controller/bluetooth/smp_server/
/usr/bin/python2.7 setup.py build
sudo /usr/bin/python2.7 setup.py install
mkdir -p ~/.local/lib/python2.7/site-packages/
cp dist/BLESMPServer-1.0.1-py2.7-linux-x86_64.egg ~/.local/lib/python2.7/site-packages
cd ../../

Setup nRF52480

  • Install nRF Connect for Desktop from Nordic website
  • You will need to write the provided hex files to the nRF5280 dongle. You can do this on windows or ubuntu. Windows is more preferable.
  • To do this on ubuntu, run the nRF connect in sudo mode and add --no-sandbox flag
  • Run the Programmer app from nRF connect
  • Connect nRF52480 in DFU mode and write the two files from nRF52480_hex_files/
  • After writing the hex files, remove the device from workstation and reconnect it.
  • To test the Android device, you will need to install the nRF Connect for Mobile app on your device.

Setup configurations

  • If the device under test uses static address, change "SlaveAddress" and "SlaveAddressType" at fsm_inference_module/ble_controller/addr_config.json file.
  • Change device properties at fsm_inference_module/statelearner/src/ble.properties file.

Device specific changes

  • Add another switch case in fsm_inference_module/statelearner/src/main/java/ble/statelearner/ble/devices/Device_SUL_Factory.java and implement the corresponding file replicating fsm_inference_module/statelearner/src/main/java/ble/statelearner/ble/devices/Device_SUL_Factory.java.
  • Implement the reset and device interaction routines in fsm_inference_module/device_controller/controller.py following nexus6 case.

Run FSM Inference Module

  • Run the BLEController:
cd fsm_inference_module/ble_controller/
sudo /usr/bin/python2.7 ble_central.py
  • Run the device controller:
cd fsm_inference_module/device_controller/
sudo /usr/bin/python2.7 controller.py l <device>
  • Compile and run the statelearner:
cd fsm_inference_module/statelearner/
mvn package
sudo java -jar target/stateLearner-0.0.1-SNAPSHOT.jar src/ble.properties

Citation

@INPROCEEDINGS {blediff,
author = {I. Karim and A. Ishtiaq and S. Hussain and E. Bertino},
booktitle = {2023 2023 IEEE Symposium on Security and Privacy (SP) (SP)},
title = {BLEDiff : Scalable and Property-Agnostic Noncompliance Checking for BLE Implementations},
year = {2023},
volume = {},
issn = {},
pages = {1082-1100},
abstract = {In this work, we develop an automated, scalable, property-agnostic, and black-box protocol noncompliance checking framework called BLEDiff that can analyze and uncover noncompliant behavior in the Bluetooth Low Energy (BLE) protocol implementations. To overcome the enormous manual effort of extracting BLE protocol reference behavioral abstraction and security properties from a large and complex BLE specification, BLEDiff takes advantage of having access to multiple BLE devices and leverages the concept of differential testing to automatically identify deviant noncompliant behavior. In this regard, BLEDiff first automatically extracts the protocol FSM of a BLE implementation using the active automata learning approach. To improve the scalability of active automata learning for the large and complex BLE protocol, BLEDiff explores the idea of using a divide and conquer approach. BLEDiff essentially divides the BLE protocol into multiple sub-protocols, identifies their dependencies and extracts the FSM of each sub-protocol separately, and finally composes them to create the large protocol FSM. These FSMs are then pair-wise tested to automatically identify diverse deviations. We evaluate BLEDiff with 25 different commercial devices and demonstrate it can uncover 13 different deviant behaviors with 10 exploitable attacks.},
keywords = {bluetooth-low-energy;noncompliance-checking;implementation-security},
doi = {10.1109/SP46215.2023.00062},
url = {https://doi.ieeecomputersociety.org/10.1109/SP46215.2023.00062},
publisher = {IEEE Computer Society},
address = {Los Alamitos, CA, USA},
month = {may}
}

Acknowledgement

We acknowledge LearnLib for the active automata learning framework and SweynTooth for the implementation of BLE central.

About

BLEDiff is an automated, scalable, property-agnostic, and black-box protocol noncompliance checker for BLE devices.

Topics

Resources

Stars

13 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

6 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

BLEDiff

This repository contains the open source implementation of BLEDiff, an automated, scalable, property-agnostic, and black-box protocol noncompliance checking framework for Bluetooth Low Energy (BLE) devices.

System requirements

  • Ubuntu 18.04 machine (tested OS)
  • Python 2.7
  • nRF52480 dongle

Setup

Setup environment

sudo chmod +x ./setup.sh
sudo ./setup.sh
cd fsm_inference_module/ble_controller/bluetooth/smp_server/
/usr/bin/python2.7 setup.py build
sudo /usr/bin/python2.7 setup.py install
mkdir -p ~/.local/lib/python2.7/site-packages/
cp dist/BLESMPServer-1.0.1-py2.7-linux-x86_64.egg ~/.local/lib/python2.7/site-packages
cd ../../

Setup nRF52480

  • Install nRF Connect for Desktop from Nordic website
  • You will need to write the provided hex files to the nRF5280 dongle. You can do this on windows or ubuntu. Windows is more preferable.
  • To do this on ubuntu, run the nRF connect in sudo mode and add --no-sandbox flag
  • Run the Programmer app from nRF connect
  • Connect nRF52480 in DFU mode and write the two files from nRF52480_hex_files/
  • After writing the hex files, remove the device from workstation and reconnect it.
  • To test the Android device, you will need to install the nRF Connect for Mobile app on your device.

Setup configurations

  • If the device under test uses static address, change "SlaveAddress" and "SlaveAddressType" at fsm_inference_module/ble_controller/addr_config.json file.
  • Change device properties at fsm_inference_module/statelearner/src/ble.properties file.

Device specific changes

  • Add another switch case in fsm_inference_module/statelearner/src/main/java/ble/statelearner/ble/devices/Device_SUL_Factory.java and implement the corresponding file replicating fsm_inference_module/statelearner/src/main/java/ble/statelearner/ble/devices/Device_SUL_Factory.java.
  • Implement the reset and device interaction routines in fsm_inference_module/device_controller/controller.py following nexus6 case.

Run FSM Inference Module

  • Run the BLEController:
cd fsm_inference_module/ble_controller/
sudo /usr/bin/python2.7 ble_central.py
  • Run the device controller:
cd fsm_inference_module/device_controller/
sudo /usr/bin/python2.7 controller.py l <device>
  • Compile and run the statelearner:
cd fsm_inference_module/statelearner/
mvn package
sudo java -jar target/stateLearner-0.0.1-SNAPSHOT.jar src/ble.properties

Citation

@INPROCEEDINGS {blediff,
author = {I. Karim and A. Ishtiaq and S. Hussain and E. Bertino},
booktitle = {2023 2023 IEEE Symposium on Security and Privacy (SP) (SP)},
title = {BLEDiff : Scalable and Property-Agnostic Noncompliance Checking for BLE Implementations},
year = {2023},
volume = {},
issn = {},
pages = {1082-1100},
abstract = {In this work, we develop an automated, scalable, property-agnostic, and black-box protocol noncompliance checking framework called BLEDiff that can analyze and uncover noncompliant behavior in the Bluetooth Low Energy (BLE) protocol implementations. To overcome the enormous manual effort of extracting BLE protocol reference behavioral abstraction and security properties from a large and complex BLE specification, BLEDiff takes advantage of having access to multiple BLE devices and leverages the concept of differential testing to automatically identify deviant noncompliant behavior. In this regard, BLEDiff first automatically extracts the protocol FSM of a BLE implementation using the active automata learning approach. To improve the scalability of active automata learning for the large and complex BLE protocol, BLEDiff explores the idea of using a divide and conquer approach. BLEDiff essentially divides the BLE protocol into multiple sub-protocols, identifies their dependencies and extracts the FSM of each sub-protocol separately, and finally composes them to create the large protocol FSM. These FSMs are then pair-wise tested to automatically identify diverse deviations. We evaluate BLEDiff with 25 different commercial devices and demonstrate it can uncover 13 different deviant behaviors with 10 exploitable attacks.},
keywords = {bluetooth-low-energy;noncompliance-checking;implementation-security},
doi = {10.1109/SP46215.2023.00062},
url = {https://doi.ieeecomputersociety.org/10.1109/SP46215.2023.00062},
publisher = {IEEE Computer Society},
address = {Los Alamitos, CA, USA},
month = {may}
}

Acknowledgement

We acknowledge LearnLib for the active automata learning framework and SweynTooth for the implementation of BLE central.

About

BLEDiff is an automated, scalable, property-agnostic, and black-box protocol noncompliance checker for BLE devices.

Topics

Resources

Stars

13 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Latest commit

History

6 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

BLEDiff

This repository contains the open source implementation of BLEDiff, an automated, scalable, property-agnostic, and black-box protocol noncompliance checking framework for Bluetooth Low Energy (BLE) devices.

System requirements

  • Ubuntu 18.04 machine (tested OS)
  • Python 2.7
  • nRF52480 dongle

Setup

Setup environment

sudo chmod +x ./setup.sh
sudo ./setup.sh
cd fsm_inference_module/ble_controller/bluetooth/smp_server/
/usr/bin/python2.7 setup.py build
sudo /usr/bin/python2.7 setup.py install
mkdir -p ~/.local/lib/python2.7/site-packages/
cp dist/BLESMPServer-1.0.1-py2.7-linux-x86_64.egg ~/.local/lib/python2.7/site-packages
cd ../../

Setup nRF52480

  • Install nRF Connect for Desktop from Nordic website
  • You will need to write the provided hex files to the nRF5280 dongle. You can do this on windows or ubuntu. Windows is more preferable.
  • To do this on ubuntu, run the nRF connect in sudo mode and add --no-sandbox flag
  • Run the Programmer app from nRF connect
  • Connect nRF52480 in DFU mode and write the two files from nRF52480_hex_files/
  • After writing the hex files, remove the device from workstation and reconnect it.
  • To test the Android device, you will need to install the nRF Connect for Mobile app on your device.

Setup configurations

  • If the device under test uses static address, change "SlaveAddress" and "SlaveAddressType" at fsm_inference_module/ble_controller/addr_config.json file.
  • Change device properties at fsm_inference_module/statelearner/src/ble.properties file.

Device specific changes

  • Add another switch case in fsm_inference_module/statelearner/src/main/java/ble/statelearner/ble/devices/Device_SUL_Factory.java and implement the corresponding file replicating fsm_inference_module/statelearner/src/main/java/ble/statelearner/ble/devices/Device_SUL_Factory.java.
  • Implement the reset and device interaction routines in fsm_inference_module/device_controller/controller.py following nexus6 case.

Run FSM Inference Module

  • Run the BLEController:
cd fsm_inference_module/ble_controller/
sudo /usr/bin/python2.7 ble_central.py
  • Run the device controller:
cd fsm_inference_module/device_controller/
sudo /usr/bin/python2.7 controller.py l <device>
  • Compile and run the statelearner:
cd fsm_inference_module/statelearner/
mvn package
sudo java -jar target/stateLearner-0.0.1-SNAPSHOT.jar src/ble.properties

Citation

@INPROCEEDINGS {blediff,
author = {I. Karim and A. Ishtiaq and S. Hussain and E. Bertino},
booktitle = {2023 2023 IEEE Symposium on Security and Privacy (SP) (SP)},
title = {BLEDiff : Scalable and Property-Agnostic Noncompliance Checking for BLE Implementations},
year = {2023},
volume = {},
issn = {},
pages = {1082-1100},
abstract = {In this work, we develop an automated, scalable, property-agnostic, and black-box protocol noncompliance checking framework called BLEDiff that can analyze and uncover noncompliant behavior in the Bluetooth Low Energy (BLE) protocol implementations. To overcome the enormous manual effort of extracting BLE protocol reference behavioral abstraction and security properties from a large and complex BLE specification, BLEDiff takes advantage of having access to multiple BLE devices and leverages the concept of differential testing to automatically identify deviant noncompliant behavior. In this regard, BLEDiff first automatically extracts the protocol FSM of a BLE implementation using the active automata learning approach. To improve the scalability of active automata learning for the large and complex BLE protocol, BLEDiff explores the idea of using a divide and conquer approach. BLEDiff essentially divides the BLE protocol into multiple sub-protocols, identifies their dependencies and extracts the FSM of each sub-protocol separately, and finally composes them to create the large protocol FSM. These FSMs are then pair-wise tested to automatically identify diverse deviations. We evaluate BLEDiff with 25 different commercial devices and demonstrate it can uncover 13 different deviant behaviors with 10 exploitable attacks.},
keywords = {bluetooth-low-energy;noncompliance-checking;implementation-security},
doi = {10.1109/SP46215.2023.00062},
url = {https://doi.ieeecomputersociety.org/10.1109/SP46215.2023.00062},
publisher = {IEEE Computer Society},
address = {Los Alamitos, CA, USA},
month = {may}
}

Acknowledgement

We acknowledge LearnLib for the active automata learning framework and SweynTooth for the implementation of BLE central.

About

BLEDiff is an automated, scalable, property-agnostic, and black-box protocol noncompliance checker for BLE devices.

Topics

Resources

Stars

13 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

6 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

BLEDiff

This repository contains the open source implementation of BLEDiff, an automated, scalable, property-agnostic, and black-box protocol noncompliance checking framework for Bluetooth Low Energy (BLE) devices.

System requirements

  • Ubuntu 18.04 machine (tested OS)
  • Python 2.7
  • nRF52480 dongle

Setup

Setup environment

sudo chmod +x ./setup.sh
sudo ./setup.sh
cd fsm_inference_module/ble_controller/bluetooth/smp_server/
/usr/bin/python2.7 setup.py build
sudo /usr/bin/python2.7 setup.py install
mkdir -p ~/.local/lib/python2.7/site-packages/
cp dist/BLESMPServer-1.0.1-py2.7-linux-x86_64.egg ~/.local/lib/python2.7/site-packages
cd ../../

Setup nRF52480

  • Install nRF Connect for Desktop from Nordic website
  • You will need to write the provided hex files to the nRF5280 dongle. You can do this on windows or ubuntu. Windows is more preferable.
  • To do this on ubuntu, run the nRF connect in sudo mode and add --no-sandbox flag
  • Run the Programmer app from nRF connect
  • Connect nRF52480 in DFU mode and write the two files from nRF52480_hex_files/
  • After writing the hex files, remove the device from workstation and reconnect it.
  • To test the Android device, you will need to install the nRF Connect for Mobile app on your device.

Setup configurations

  • If the device under test uses static address, change "SlaveAddress" and "SlaveAddressType" at fsm_inference_module/ble_controller/addr_config.json file.
  • Change device properties at fsm_inference_module/statelearner/src/ble.properties file.

Device specific changes

  • Add another switch case in fsm_inference_module/statelearner/src/main/java/ble/statelearner/ble/devices/Device_SUL_Factory.java and implement the corresponding file replicating fsm_inference_module/statelearner/src/main/java/ble/statelearner/ble/devices/Device_SUL_Factory.java.
  • Implement the reset and device interaction routines in fsm_inference_module/device_controller/controller.py following nexus6 case.

Run FSM Inference Module

  • Run the BLEController:
cd fsm_inference_module/ble_controller/
sudo /usr/bin/python2.7 ble_central.py
  • Run the device controller:
cd fsm_inference_module/device_controller/
sudo /usr/bin/python2.7 controller.py l <device>
  • Compile and run the statelearner:
cd fsm_inference_module/statelearner/
mvn package
sudo java -jar target/stateLearner-0.0.1-SNAPSHOT.jar src/ble.properties

Citation

@INPROCEEDINGS {blediff,
author = {I. Karim and A. Ishtiaq and S. Hussain and E. Bertino},
booktitle = {2023 2023 IEEE Symposium on Security and Privacy (SP) (SP)},
title = {BLEDiff : Scalable and Property-Agnostic Noncompliance Checking for BLE Implementations},
year = {2023},
volume = {},
issn = {},
pages = {1082-1100},
abstract = {In this work, we develop an automated, scalable, property-agnostic, and black-box protocol noncompliance checking framework called BLEDiff that can analyze and uncover noncompliant behavior in the Bluetooth Low Energy (BLE) protocol implementations. To overcome the enormous manual effort of extracting BLE protocol reference behavioral abstraction and security properties from a large and complex BLE specification, BLEDiff takes advantage of having access to multiple BLE devices and leverages the concept of differential testing to automatically identify deviant noncompliant behavior. In this regard, BLEDiff first automatically extracts the protocol FSM of a BLE implementation using the active automata learning approach. To improve the scalability of active automata learning for the large and complex BLE protocol, BLEDiff explores the idea of using a divide and conquer approach. BLEDiff essentially divides the BLE protocol into multiple sub-protocols, identifies their dependencies and extracts the FSM of each sub-protocol separately, and finally composes them to create the large protocol FSM. These FSMs are then pair-wise tested to automatically identify diverse deviations. We evaluate BLEDiff with 25 different commercial devices and demonstrate it can uncover 13 different deviant behaviors with 10 exploitable attacks.},
keywords = {bluetooth-low-energy;noncompliance-checking;implementation-security},
doi = {10.1109/SP46215.2023.00062},
url = {https://doi.ieeecomputersociety.org/10.1109/SP46215.2023.00062},
publisher = {IEEE Computer Society},
address = {Los Alamitos, CA, USA},
month = {may}
}

Acknowledgement

We acknowledge LearnLib for the active automata learning framework and SweynTooth for the implementation of BLE central.

About

BLEDiff is an automated, scalable, property-agnostic, and black-box protocol noncompliance checker for BLE devices.

Topics

Resources

Stars

13 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

6 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

BLEDiff

This repository contains the open source implementation of BLEDiff, an automated, scalable, property-agnostic, and black-box protocol noncompliance checking framework for Bluetooth Low Energy (BLE) devices.

System requirements

  • Ubuntu 18.04 machine (tested OS)
  • Python 2.7
  • nRF52480 dongle

Setup

Setup environment

sudo chmod +x ./setup.sh
sudo ./setup.sh
cd fsm_inference_module/ble_controller/bluetooth/smp_server/
/usr/bin/python2.7 setup.py build
sudo /usr/bin/python2.7 setup.py install
mkdir -p ~/.local/lib/python2.7/site-packages/
cp dist/BLESMPServer-1.0.1-py2.7-linux-x86_64.egg ~/.local/lib/python2.7/site-packages
cd ../../

Setup nRF52480

  • Install nRF Connect for Desktop from Nordic website
  • You will need to write the provided hex files to the nRF5280 dongle. You can do this on windows or ubuntu. Windows is more preferable.
  • To do this on ubuntu, run the nRF connect in sudo mode and add --no-sandbox flag
  • Run the Programmer app from nRF connect
  • Connect nRF52480 in DFU mode and write the two files from nRF52480_hex_files/
  • After writing the hex files, remove the device from workstation and reconnect it.
  • To test the Android device, you will need to install the nRF Connect for Mobile app on your device.

Setup configurations

  • If the device under test uses static address, change "SlaveAddress" and "SlaveAddressType" at fsm_inference_module/ble_controller/addr_config.json file.
  • Change device properties at fsm_inference_module/statelearner/src/ble.properties file.

Device specific changes

  • Add another switch case in fsm_inference_module/statelearner/src/main/java/ble/statelearner/ble/devices/Device_SUL_Factory.java and implement the corresponding file replicating fsm_inference_module/statelearner/src/main/java/ble/statelearner/ble/devices/Device_SUL_Factory.java.
  • Implement the reset and device interaction routines in fsm_inference_module/device_controller/controller.py following nexus6 case.

Run FSM Inference Module

  • Run the BLEController:
cd fsm_inference_module/ble_controller/
sudo /usr/bin/python2.7 ble_central.py
  • Run the device controller:
cd fsm_inference_module/device_controller/
sudo /usr/bin/python2.7 controller.py l <device>
  • Compile and run the statelearner:
cd fsm_inference_module/statelearner/
mvn package
sudo java -jar target/stateLearner-0.0.1-SNAPSHOT.jar src/ble.properties

Citation

@INPROCEEDINGS {blediff,
author = {I. Karim and A. Ishtiaq and S. Hussain and E. Bertino},
booktitle = {2023 2023 IEEE Symposium on Security and Privacy (SP) (SP)},
title = {BLEDiff : Scalable and Property-Agnostic Noncompliance Checking for BLE Implementations},
year = {2023},
volume = {},
issn = {},
pages = {1082-1100},
abstract = {In this work, we develop an automated, scalable, property-agnostic, and black-box protocol noncompliance checking framework called BLEDiff that can analyze and uncover noncompliant behavior in the Bluetooth Low Energy (BLE) protocol implementations. To overcome the enormous manual effort of extracting BLE protocol reference behavioral abstraction and security properties from a large and complex BLE specification, BLEDiff takes advantage of having access to multiple BLE devices and leverages the concept of differential testing to automatically identify deviant noncompliant behavior. In this regard, BLEDiff first automatically extracts the protocol FSM of a BLE implementation using the active automata learning approach. To improve the scalability of active automata learning for the large and complex BLE protocol, BLEDiff explores the idea of using a divide and conquer approach. BLEDiff essentially divides the BLE protocol into multiple sub-protocols, identifies their dependencies and extracts the FSM of each sub-protocol separately, and finally composes them to create the large protocol FSM. These FSMs are then pair-wise tested to automatically identify diverse deviations. We evaluate BLEDiff with 25 different commercial devices and demonstrate it can uncover 13 different deviant behaviors with 10 exploitable attacks.},
keywords = {bluetooth-low-energy;noncompliance-checking;implementation-security},
doi = {10.1109/SP46215.2023.00062},
url = {https://doi.ieeecomputersociety.org/10.1109/SP46215.2023.00062},
publisher = {IEEE Computer Society},
address = {Los Alamitos, CA, USA},
month = {may}
}

Acknowledgement

We acknowledge LearnLib for the active automata learning framework and SweynTooth for the implementation of BLE central.

About

BLEDiff is an automated, scalable, property-agnostic, and black-box protocol noncompliance checker for BLE devices.

Topics

Resources

Stars

13 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Latest commit

History

6 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

BLEDiff

This repository contains the open source implementation of BLEDiff, an automated, scalable, property-agnostic, and black-box protocol noncompliance checking framework for Bluetooth Low Energy (BLE) devices.

System requirements

  • Ubuntu 18.04 machine (tested OS)
  • Python 2.7
  • nRF52480 dongle

Setup

Setup environment

sudo chmod +x ./setup.sh
sudo ./setup.sh
cd fsm_inference_module/ble_controller/bluetooth/smp_server/
/usr/bin/python2.7 setup.py build
sudo /usr/bin/python2.7 setup.py install
mkdir -p ~/.local/lib/python2.7/site-packages/
cp dist/BLESMPServer-1.0.1-py2.7-linux-x86_64.egg ~/.local/lib/python2.7/site-packages
cd ../../

Setup nRF52480

  • Install nRF Connect for Desktop from Nordic website
  • You will need to write the provided hex files to the nRF5280 dongle. You can do this on windows or ubuntu. Windows is more preferable.
  • To do this on ubuntu, run the nRF connect in sudo mode and add --no-sandbox flag
  • Run the Programmer app from nRF connect
  • Connect nRF52480 in DFU mode and write the two files from nRF52480_hex_files/
  • After writing the hex files, remove the device from workstation and reconnect it.
  • To test the Android device, you will need to install the nRF Connect for Mobile app on your device.

Setup configurations

  • If the device under test uses static address, change "SlaveAddress" and "SlaveAddressType" at fsm_inference_module/ble_controller/addr_config.json file.
  • Change device properties at fsm_inference_module/statelearner/src/ble.properties file.

Device specific changes

  • Add another switch case in fsm_inference_module/statelearner/src/main/java/ble/statelearner/ble/devices/Device_SUL_Factory.java and implement the corresponding file replicating fsm_inference_module/statelearner/src/main/java/ble/statelearner/ble/devices/Device_SUL_Factory.java.
  • Implement the reset and device interaction routines in fsm_inference_module/device_controller/controller.py following nexus6 case.

Run FSM Inference Module

  • Run the BLEController:
cd fsm_inference_module/ble_controller/
sudo /usr/bin/python2.7 ble_central.py
  • Run the device controller:
cd fsm_inference_module/device_controller/
sudo /usr/bin/python2.7 controller.py l <device>
  • Compile and run the statelearner:
cd fsm_inference_module/statelearner/
mvn package
sudo java -jar target/stateLearner-0.0.1-SNAPSHOT.jar src/ble.properties

Citation

@INPROCEEDINGS {blediff,
author = {I. Karim and A. Ishtiaq and S. Hussain and E. Bertino},
booktitle = {2023 2023 IEEE Symposium on Security and Privacy (SP) (SP)},
title = {BLEDiff : Scalable and Property-Agnostic Noncompliance Checking for BLE Implementations},
year = {2023},
volume = {},
issn = {},
pages = {1082-1100},
abstract = {In this work, we develop an automated, scalable, property-agnostic, and black-box protocol noncompliance checking framework called BLEDiff that can analyze and uncover noncompliant behavior in the Bluetooth Low Energy (BLE) protocol implementations. To overcome the enormous manual effort of extracting BLE protocol reference behavioral abstraction and security properties from a large and complex BLE specification, BLEDiff takes advantage of having access to multiple BLE devices and leverages the concept of differential testing to automatically identify deviant noncompliant behavior. In this regard, BLEDiff first automatically extracts the protocol FSM of a BLE implementation using the active automata learning approach. To improve the scalability of active automata learning for the large and complex BLE protocol, BLEDiff explores the idea of using a divide and conquer approach. BLEDiff essentially divides the BLE protocol into multiple sub-protocols, identifies their dependencies and extracts the FSM of each sub-protocol separately, and finally composes them to create the large protocol FSM. These FSMs are then pair-wise tested to automatically identify diverse deviations. We evaluate BLEDiff with 25 different commercial devices and demonstrate it can uncover 13 different deviant behaviors with 10 exploitable attacks.},
keywords = {bluetooth-low-energy;noncompliance-checking;implementation-security},
doi = {10.1109/SP46215.2023.00062},
url = {https://doi.ieeecomputersociety.org/10.1109/SP46215.2023.00062},
publisher = {IEEE Computer Society},
address = {Los Alamitos, CA, USA},
month = {may}
}

Acknowledgement

We acknowledge LearnLib for the active automata learning framework and SweynTooth for the implementation of BLE central.

About

BLEDiff is an automated, scalable, property-agnostic, and black-box protocol noncompliance checker for BLE devices.

Topics

Resources

Stars

13 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages