Tuan Dinh Hoang

dblp:350/4689 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
4since 2021 · last 2025
0009-0000-2229-6533ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 3 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2025 OTABase: Enhancing Over-the-Air Testing to Detect Memory Crashes in Cellular Basebands
abstract
Baseband processors (BPs) in cellular devices implement complex radio protocols, and memory corruption vulnerabilities in these implementations can lead to critical security breaches, including remote code execution. Traditional approaches to detecting such vulnerabilities rely on reverse engineering or emulation. However, these methods face significant scalability challenges due to proprietary firmware and architectural complexities. Over-the-air (OTA) testing offers broader applicability but poses challenges in managing UE state, detecting crashes, and ensuring protocol coverage. We present OTABase, an OTA testing framework that enables efficient detection of memory crashes in LTE base-bands by leveraging protocol specifications. OTABase combines three key techniques: a network-side state control mechanism for efficient management of UE states and connections, a specification-guided test case generation targeting memory crashes in NAS and RRC protocols, and a two-phase crash detection oracle utilizing protocol-based liveness checks and manufacturer debug features. Evaluating OTABase on six commercial BPs from three major manufacturers, unearthed seven previously unpatched memory crashes. Among these, three were assigned CVEs, including one out-of-bounds write vulnerability that allows remote code execution. Additionally, we extend OTABase to 5G basebands for PoC, demonstrating its generalizability and practical utility.
CheolJun Park, Marc Egli, Beomseok Oh 0001, Tuan Dinh Hoang, Suhwan Jeong, Martin Crettol, Insu Yun, Mathias Payer, Yongdae Kim
ACSAC4
2025 LLFuzz: An Over-the-Air Dynamic Testing Framework for Cellular Baseband Lower Layers
Tuan Dinh Hoang, Taekkyung Oh, CheolJun Park, Insu Yun, Yongdae Kim
USENIX Security Symposium1
2024 Enabling Physical Localization of Uncooperative Cellular Devices
abstract
In cellular networks, authorities may need to physically locate user devices to track criminals or illegal equipment. This process involves authorized agents tracing devices by monitoring uplink signals with cellular operator assistance. However, tracking uncooperative uplink signal sources remains challenging, even for operators and authorities. Three key challenges persist for fine-grained localization: i) devices must generate sufficient, consistent uplink traffic over time, ii) target devices may transmit uplink signals at very low power, and iii) signals from cellular repeaters may hinder localization of the target device. While these challenges pose significant practical obstacles to localization, they have been largely overlooked in existing research.
Taekkyung Oh, Sangwook Bae, Junho Ahn, Yonghwa Lee, Tuan Dinh Hoang, Min Suk Kang, Nils Ole Tippenhauer, Yongdae Kim
MobiCom5
2023 LTESniffer: An Open-source LTE Downlink/Uplink Eavesdropper
abstract
LTE sniffers are important for security and performance analysis because they can passively capture the wireless traffic of users in LTE network. However, existing open-source LTE sniffers have only limited functionality and cannot decode data traffic. This paper introduces LTESNIFFER, the first open-source LTE sniffer that can passively decode both uplink and downlink data traffic. Implementing a sniffer is not trivial because one needs to understand detailed configurations and parameters to successfully decode each user's traffic. Using multiple techniques, we found mechanisms to understand these, which improves our decoding performance. We evaluated the performance of LTESNIFFER on both testbed and commercial network environments. We also compare the performance of LTESNIFFER with AirScope, a popular commercial LTE sniffer. Additionally, LTESNIFFER provides a proof-of-concept API with three functions that can be used for security applications, including identity mapping, identity collecting, and device capability profiling. We release LTESNIFFER as open-source for future research.
Tuan Dinh Hoang, CheolJun Park, Mincheol Son, Taekkyung Oh, Sangwook Bae, Junho Ahn, Beomseok Oh 0001, Yongdae Kim
WISEC1