Carlos Nkuba Kayembe

dblp:221/2039 · DBLP profile ↗
← Back
2ranked-venue papers
1as first author
2since 2021 · last 2025
0000-0002-6424-9054ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2025 ZCover: Uncovering Z-Wave Controller Vulnerabilities Through Systematic Security Analysis of Application Layer Implementation
abstract
The increasing use of smart home technologies has raised concerns about security vulnerabilities, particularly in Z-Wave systems. Existing approaches hold the promise of assessing Z-Wave security in slave devices but fall short of being effectively applied to discover vulnerabilities in Z-Wave controllers, which are central to Z-Wave systems. We present ZCover, a framework for systematically analyzing the application layer of Z-Wave controllers to uncover security vulnerabilities. By extracting the known and unknown properties of the Z-Wave controller and utilizing mutation that considers the correlations of the Z-Wave packet frame fields, ZCover can effectively discover unknown vulnerabilities in the target Z-Wave controller. Evaluation on nine real-world Z-Wave devices showed that ZCover outperformed existing Z-Wave security research, by discovering 15 previously unknown critical vulnerabilities with 12 new CVE IDs assigned. ZCover can be utilized as a resource for ensuring the security of Z-Wave controllers in building a secure Z-Wave smart home.
Carlos Nkuba Kayembe, Jimin Kang, Seunghoon Woo, Heejo Lee
DSN1
2022 L2Fuzz: Discovering Bluetooth L2CAP Vulnerabilities Using Stateful Fuzz Testing
abstract
Bluetooth Basic Rate/Enhanced Data Rate (BR/EDR) is a wireless technology used in billions of devices. Recently, several Bluetooth fuzzing studies have been conducted to detect vulnerabilities in Bluetooth devices, but they fall short of effectively generating malformed packets. In this paper, we propose L2FUZZ, a stateful fuzzer to detect vulnerabilities in Bluetooth BR/EDR Logical Link Control and Adaptation Protocol (L2CAP) layer. By selecting valid commands for each state and mutating only the core fields of packets, L2FUZZ can generate valid malformed packets that are less likely to be rejected by the target device. Our experimental results confirmed that: (1) L2FUZZ generates up to 46 times more malformed packets with a much less packet rejection ratio compared to the existing techniques, and (2) L2FUZZ detected five zero-day vulnerabilities from eight real-world Bluetooth devices.
Haram Park, Carlos Nkuba Kayembe, Seunghoon Woo, Heejo Lee
DSN2