EDBT 2026 Demo / reviewers in the wild / expert
Beomseok Oh 0001
dblp:263/5973-1
· DBLP profile ↗
6ranked-venue papers
1as first author
6since 2021 · last 2025
0009-0009-0692-0899ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 1 first-author · 6 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | OTABase: Enhancing Over-the-Air Testing to Detect Memory Crashes in Cellular BasebandsabstractBaseband processors (BPs) in cellular devices implement complex radio protocols, and memory corruption vulnerabilities in these implementations can lead to critical security breaches, including remote code execution. Traditional approaches to detecting such vulnerabilities rely on reverse engineering or emulation. However, these methods face significant scalability challenges due to proprietary firmware and architectural complexities. Over-the-air (OTA) testing offers broader applicability but poses challenges in managing UE state, detecting crashes, and ensuring protocol coverage. We present OTABase, an OTA testing framework that enables efficient detection of memory crashes in LTE base-bands by leveraging protocol specifications. OTABase combines three key techniques: a network-side state control mechanism for efficient management of UE states and connections, a specification-guided test case generation targeting memory crashes in NAS and RRC protocols, and a two-phase crash detection oracle utilizing protocol-based liveness checks and manufacturer debug features. Evaluating OTABase on six commercial BPs from three major manufacturers, unearthed seven previously unpatched memory crashes. Among these, three were assigned CVEs, including one out-of-bounds write vulnerability that allows remote code execution. Additionally, we extend OTABase to 5G basebands for PoC, demonstrating its generalizability and practical utility. CheolJun Park, Marc Egli, Beomseok Oh 0001, Tuan Dinh Hoang, Suhwan Jeong, Martin Crettol, Insu Yun, Mathias Payer, Yongdae Kim |
ACSAC | 3 |
| 2025 | CITesting: Systematic Testing of Context Integrity Violations in LTE Core NetworksabstractCellular networks increasingly support critical infrastructure, yet their security remains an ongoing concern. While prior research has focused mainly on downlink vulnerabilities, uplink security—how user equipment (UE) affects the core network—has received limited attention. We study a class of uplink vulnerabilities, which we define as context integrity violations (CIVs), where an unauthenticated or improperly authenticated UE modifies the internal state of other subscribers. Prior work identified a few instances of CIVs, but the broader attack surface remains unexplored. We present CITesting, the first framework for systematically detecting CIVs in LTE core networks. CITesting explores diverse procedure chains, tests a broad range of Information Elements (IEs), and validates behavior across UE connection states. It introduces stateful dual-UE control testing to manage victim UE state and employs a behavioral oracle to detect context modifications in black-box networks. We evaluated CITesting on two open-source (Open5GS, srsRAN) and two commercial (Amarisoft, Nokia) LTE core network implementations, identifying 29, 22, 16, and 59 distinct CIVs after post-analysis. These findings enable remote attacks including UE detachment, IMSI exposure, and presence detection attacks. Note that traditional attack models such as fake base station and active SigOver require the active attacker to be co-located in the same cell. In contrast, our attacks require the active attacker to be in the same MME region (significantly broader than a cell) as the victim UE. All findings were responsibly disclosed, and patches were contributed to Amarisoft and Open5GS. Mincheol Son, Beomseok Oh 0001, CheolJun Park, Yongdae Kim |
CCS | 3 |
| 2025 | FirmState: Bringing Cellular Protocol States to Shannon Baseband EmulationabstractCellular baseband processors represent critical security components in modern mobile devices, yet they remain challenging to analyze due to their complexity and restricted access. Recent advances in baseband research introduced FirmWire, the state-of-the-art emulator enabling full-system baseband emulation with extensive features debugging capabilities. However, it lacks protocol state awareness, significantly limiting its coverage and fidenlity. While implementing such support demands substantial engineering effort, accurately modeling protocol states remains essential for comprehensive baseband security analysis. In this paper, we present FirmState, a state-aware methodology that augments baseband emulation, specifically targeting Samsung Shannon baseband. FirmState semi-automatically recovers and applies state information extracted from physical devices during actual network communication, enabling more complete code coverage and authentic behavior reproduction without extensive reverse engineering. Our evaluation demonstrates a significant improvement in code coverage, achieving 7.5% for RRC--2.7× higher than previous work. Additionally, our system newly supports NAS over FirmWire, with code coverage ranging from 4.5% to 9.2%, depending on the protocol state. Using our approach, we discovered and analyzed two 1-day vulnerabilities in Samsung's baseband implementation, demonstrating FirmState's effectiveness for baseband security. We make FirmState open-source to support further research in baseband security. Suhwan Jeong, Beomseok Oh 0001, Insu Yun, Yongdae Kim, CheolJun Park |
WISEC | 2 |
| 2023 | Preventing SIM Box Fraud Using Device Model Fingerprinting
Beomseok Oh 0001, Junho Ahn, Sangwook Bae, Mincheol Son, Yonghwa Lee, Min Suk Kang, Yongdae Kim |
NDSS | 1 |
| 2023 | LTESniffer: An Open-source LTE Downlink/Uplink EavesdropperabstractLTE sniffers are important for security and performance analysis because they can passively capture the wireless traffic of users in LTE network. However, existing open-source LTE sniffers have only limited functionality and cannot decode data traffic. This paper introduces LTESNIFFER, the first open-source LTE sniffer that can passively decode both uplink and downlink data traffic. Implementing a sniffer is not trivial because one needs to understand detailed configurations and parameters to successfully decode each user's traffic. Using multiple techniques, we found mechanisms to understand these, which improves our decoding performance. We evaluated the performance of LTESNIFFER on both testbed and commercial network environments. We also compare the performance of LTESNIFFER with AirScope, a popular commercial LTE sniffer. Additionally, LTESNIFFER provides a proof-of-concept API with three functions that can be used for security applications, including identity mapping, identity collecting, and device capability profiling. We release LTESNIFFER as open-source for future research. Tuan Dinh Hoang, CheolJun Park, Mincheol Son, Taekkyung Oh, Sangwook Bae, Junho Ahn, Beomseok Oh 0001, Yongdae Kim |
WISEC | 7 |
| 2022 | DoLTEst: In-depth Downlink Negative Testing Framework for LTE Devices
CheolJun Park, Sangwook Bae, Beomseok Oh 0001, Eun-Kyu Lee, Insu Yun, Yongdae Kim |
USENIX Security Symposium | 3 |