Ryan Tsang

dblp:335/5778 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
7since 2021 · last 2024
0009-0006-8382-0099ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Interactive Framework for Cybersecurity Education and Future Workforce Development
abstract
This research-to-practice paper presents a novel pedagogical tool for hardware cybersecurity education and workforce development. The growing importance of hardware security has made it essential for individuals and organizations to understand hardware security principles and best practices. However, the current educational curriculum falls short of fulfilling these emerging demands due to the rapidly changing hardware security landscape and limited opportunities for hands-on training. To address these challenges, we propose and have developed the Interactive Hardware and Cybersecurity (I-HaC) Educational Framework, a pedagogical educational framework that supplements existing courses by leveraging generative AI for individualized instruction related to hardware and cybersecurity, data mining, and applied Machine Learning (ML), as well as data visualization to enhance cybersecurity education and workforce development. The framework is designed to be utilized by graduate and undergraduate Electrical and Computer Engineering (ECE) and Computer Science (CS) students for a comprehensive introduction to cybersecurity exploits and countermeasures in an interactive manner with hands-on components. Using I-HaC, we have developed tailored lab components for a diverse range of students and intend to release I-HaC as open-source for the benefit of the ECE and CS education community.
Sujan Ghimire, Md Muhtasim Alam Chowdhury, Ryan Tsang, Richard C. Yarnell, Emma Heckert, Jaeden Wolf Carpenter, Yu-Zheng Lin, Muntasir Mamun, Ronald F. DeMara, Setareh Rafatirad, Pratik Satam, Soheil Salehi
FIE3
2024 Retcon: Live Updates for Embedded Event-Driven Applications
abstract
Embedded systems are deeply integrated into critical applications but, despite their importance, lack an effective means to apply over-the-air software patches without significant downtime. Standard mechanisms for firmware updates require device reboots that wipe important in-memory state. Prior efforts have proposed "live" updates to address this problem, applying patches to an embedded application without a reset, but they tackle a limited set of applications or propose a clean-slate design. In this paper, we present Retcon, a live update toolchain for embedded systems that supports a familiar event-driven programming model and does not require application code changes. Retcon leverages static analysis at compile time to determine when it will be safe to update a device. To find safe update points in the presence of complex asynchronous behavior, we define a novel system state, asynchronous quiescence, in which an update can be applied. We evaluate Retcon on a set of embedded event-driven applications – a dual-chamber pacemaker model, a programmable logic controller runtime, an artificial pancreas system, and a sensing node – and demonstrate Retcon’s ability to make low-overhead updates in less than one millisecond.
Jean-Luc Watson, Saharsh Agrawal, Ryan Tsang, Sherry Luo, Raluca A. Popa, Prabal Dutta
IPSN3
2024 Fuzzing BusyBox: Leveraging LLM and Crash Reuse for Embedded Bug Unearthing
Asmita 0001, Yaroslav Oliinyk, Michael Scott, Ryan Tsang, Chongzhou Fang, Houman Homayoun
USENIX Security Symposium4
2024 Large Language Models for Code Analysis: Do LLMs Really Do Their Job?
Chongzhou Fang, Ning Miao, Shaurya Srivastav, Jialin Liu 0006, Ruoyu Zhang 0002, Ruijie Fang, Asmita 0001, Ryan Tsang, Najmeh Nazari, Han Wang 0020, Houman Homayoun
USENIX Security Symposium8
2024 FFXE: Dynamic Control Flow Graph Recovery for Embedded Firmware Binaries
Ryan Tsang, Asmita 0001, Doreen Joseph, Soheil Salehi, Prasant Mohapatra, Houman Homayoun
USENIX Security Symposium1
2023 Leveraging Firmware Reverse Engineering for Stealthy Sensor Attacks via Binary Modification
abstract
The number of Internet of Things (IoT) devices has increased dramatically to the point where they pervade our daily life. These connected devices are equipped with a variety of sensors for applications ranging from simple thermostats to critical medical devices. These devices often directly interact with people and usually lack proper security measures, thus they have become ideal targets for attackers. Herein, we propose Cunning Sensor Attack via Firmware Reverse-Engineering (unSAFE), which is a novel and stealthy sensor attack that attempts to corrupt sensor data by targeting the device’s Power Management IC (PMIC) configuration in firmware. The proposed unSAFE explores a class of vulnerabilities in which firmware is used to launch a physical attack against a device’s peripherals utilizing power management units as a vector. Our proposed technique consists of reverse-engineering the binary code running on bare-metal IoT devices and targeting the functions that control the PMIC configurations. We demonstrate our attack by modifying the firmware binary to alter the PMIC’s output voltage and evaluate it by measuring the changes in the output of the targeted sensors. We demonstrate that supplying a sensor with an incorrect voltage or current configuration can cause data corruption, which can go unnoticed and might have direct repercussions on real-world systems. Moreover, we discuss the stealthy nature of our attack and the fact that it can evade detection during functional testing as it does not change the overall functionality of IoT devices. Finally, we provide potential mitigation suggestions to address this vulnerability.
Sutej Kulkarni, Ryan Tsang, Asmita 0001, Houman Homayoun, Soheil Salehi
ICCD2
2022 FANDEMIC: Firmware Attack Construction and Deployment on Power Management Integrated Circuit and Impacts on IoT Applications
Ryan Tsang, Doreen Joseph, Asmita 0001, Soheil Salehi, Nadir Carreon, Prasant Mohapatra, Houman Homayoun
NDSS1