EDBT 2026 Demo / reviewers in the wild / expert
Matheus E. Garbelini
dblp:270/8889
· DBLP profile ↗
12ranked-venue papers
5as first author
11since 2021 · last 2026
0000-0002-8169-9874ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 3 first-author · 7 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ORANClaw: Shredding E2 Nodes in O-RAN via Structure-aware MiTM FuzzingabstractThe open radio access network (O-RAN) standard provides a foundational move towards disaggregated RAN architecture, allowing flexibility and multi-vendor integration. For example, the Radio Intelligent Controller (RIC) may involve third-party applications (xApps) to dynamically control and monitor network behavior, facilitating significant opportunities for multi-party involvement, but allowing potentially untrusted integration with the RAN. In this paper, we propose, design and evaluate ORANClaw — a structure aware, man-in-the-middle fuzzing framework that takes full control over the E2 interface between the xApps and the RIC, and systematically mutates or duplicates packets communicated via this interface to disrupt the behavior of the base station (gNB). ORANClaw takes into account the structural and semantic constraints while systematically mutating the packets. Furthermore, it optimizes the mutation strategy based on the coverage of explored state transitions.We have implemented ORANClaw and evaluated it with FlexRIC, O-RAN SC RIC, OpenAirInterface, ns-3 simulator and commercical VIAVI TeraVM AI RAN Scenario Generator gNB/RIC. In total, ORANClaw has discovered 71 unique bugs (eight CVEs already assigned): 28 in FlexRIC, one in O-RAN SC RIC, 37 in the gNB implementations of OpenAirInterface and ns-3. Additionally, ORANClaw uncovered five distinct vulnerabilities in commercial VIAVI TeraVM AI RSG gNB/RIC. Our evaluation also reveals that structure and semantic-aware mutations within ORANClaw are key factors in revealing these bugs. Overall, ORANClaw provides an open platform to automatically validate both the RIC and gNB implementations via xApp manipulations. Geovani Benita, Matheus E. Garbelini, Sudipta Chattopadhyay 0001, Jianying Zhou 0001 |
WISEC | 2 |
| 2026 | AEVisionLab: Manipulating In-vehicle Ethernet Networks with All-round VisionabstractWith the increasing adoption of Advanced Driver Assistance Systems (ADAS) in modern cars, the use of vision systems for autonomous vehicles, driving assistance, and in-vehicle entertainment has introduced new risks and attack vectors to existing In-Vehicle Networks (IVNs), thus bringing considerable concerns to the automotive cybersecurity space. Prior works have focused on analyzing functional or partial security aspects of vision systems during ADAS simulation using specialized Automotive Ethernet (AE) equipment or requiring expensive vehicle-in-the-loop setups. These approaches are either inaccessible to independent security researchers or do not offer comprehensive insights to help researchers understand the practical implications of attacks in a realistic car employing Automotive Ethernet IVNs for vision-related use cases. AEVisionLab allows replication of driving test scenarios directly with COTS ECUs and collection of key network performance metrics, facilitating the design, evaluation, and impact analysis of concrete attacks in the laboratory. We demonstrate the capability of AEVisionLab by designing and evaluating concrete attacks scenarios including eavesdropping and hijacking of SOME/IP services, manipulation and delaying video feed, among others. We envision AEVisionLab as a flexible platform for designing and evaluating both attack and mitigation techniques (e.g., intrusion detection) on AE network, which can be easily extended to support other automotive ECUs, machine learning models for ADAS, or sensors for assisted driving. Anthony Kee Teck Yeo, Matheus E. Garbelini, Sai Sathiesh Rajan, Jianying Zhou 0001, Sudipta Chattopadhyay 0001 |
ACM Trans. Embed. Comput. Syst. | 2 |
| 2025 | SNI5GECT: A Practical Approach to Inject aNRchy into 5G NR
Matheus E. Garbelini, Sudipta Chattopadhyay 0001, Jianying Zhou 0001 |
USENIX Security Symposium | 2 |
| 2025 | 5Ghoul: Unleashing Chaos on 5G Edge Devices via Stateful Multi-Layer FuzzingabstractIn this paper, we present5Ghoul, a framework to systematically discover and replicate security vulnerabilities on arbitrary 5 G edge devices (UE). At the core of5Ghoulis a stateful fuzzing strategy that provides full control to arbitrarily manipulate any packet down to the data link layer. Moreover,5Ghoulautomatically constructs the protocol state machines to guide the fuzzing process and employs novel strategies to reliably exploit vulnerabilities on commercial-off-the-shelf (COTS) UEs over-the-air. The design choices in5Ghoulwere carefully taken to allow packet manipulation in real-time, which, in turn allowed us to fuzz down to data link layer. As of today, we have evaluated5Ghoulwith seven COTS 5 G UEs (smartphones and USB modems) and one open source framework (OpenAirInterface).5Ghoulhas uncovered 12 unknown security vulnerabilities (14 in total) out of which ten exist in COTS UEs (ten CVEs assigned) from major vendors (e.g., Qualcomm and MediaTek). Moreover, of these COTS UE vulnerabilities have been confirmed to have high severity. We also won a bug bounty of over 20 K USD from Qualcomm and MediaTek for discovering these vulnerabilities. We envision5Ghoulto open the door for 5G security testing at scale. Matheus E. Garbelini, Zewen Shang, Sudipta Chattopadhyay 0001, Sumei Sun, Ernest Kurniawan |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | VaktBLE: A Benevolent Man-in-the-Middle Bridge to Guard against Malevolent BLE ConnectionsabstractIn this paper, we conceptualize, design and evaluate VaktBLE, a novel framework to defend BLE peripherals against low-level BLE attacks. VaktBLE presents a novel, efficient and (almost) deterministic technique to silently hijack the connection between a potentially malicious BLE central and the target peripheral to be protected. This creates a benevolent man-in-the-middle (MiTM) bridge that allows us to validate each packet sent by the BLE central. For validation, we implement a flexible and extensible framework to detect a variety of attacks due to packets that are invalid, out-of-order or flooded. An appealing capability of VaktBLE is that it can validate all packets down to the link layer, thus allowing us to defend against complex BLE attacks that bypass state-of-the art binary patching frameworks. We have implemented VaktBLE and evaluated it with 25 state-of-the-art BLE attack vectors from offensive tools such as SweynTooth, CyRC and BLEDiff. Our evaluation shows that VaktBLE effectively detects all these attacks and the VaktBLE MitM bridge incurs only 10ms overhead. Moreover, we have evaluated the capability and robustness of VaktBLE against several adaptive attacks including fuzzing-based attacks. We also show the extensibility of VaktBLE to counteract protocol-level attacks and rogue peripherals. Our evaluation reveals that VaktBLE not only stops fuzzing-based attacks with high effectiveness (97.5%), but VaktBLE also does not incur false positives when attacks are randomly mixed with benign connection attempts. Geovani Benita, Leonardo Sestrem de Oliveira, Matheus E. Garbelini, Sudipta Chattopadhyay 0001, Sumei Sun, Ernest Kurniawan |
ACSAC | 3 |
| 2024 | AirBugCatcher: Automated Wireless Reproduction of IoT BugsabstractFuzzing has been proven to be an effective tool to find implementation bugs in a range of wireless Internet of Things (IoT) devices such as smartphones, trackers, smart wearables, routers, etc. However, reliable and automated reproduction of vulnerabilities reported by over-the-air (OTA) fuzzing pipelines remains an open problem. While bug reproduction is crucial for troubleshooting and fixing of security flaws, it remains a challenge due to the non-deterministic nature of wireless devices. In this context, we present AirBugCatcher, a hardware and protocol agnostic tool to automatically identify reliable OTA attack vectors and reproduce bugs in commercial-off-the-shelf (COTS) IoT devices. AirBugCatcher aims to address two fundamental challenges during reproduction of vulnerabilities: Reproduction of bugs under the non-deterministic communication of wireless devices and resolution of ambiguities during the attack vector analysis of bugs within fuzzing logs. AirBugCatcher accomplishes this by firstly analyzing packet traces and logs from an existing fuzzing pipeline and extracting a minimal set of fuzzing packets that might be responsible for triggering bugs in the target IoT device. Subsequently, AirBugCatcher reliably reproduces bugs by generating several proof of concept (PoC) codes (test cases) and executing them against the target to validate the root cause of bugs. AirBugCatcher has been evaluated against four COTS IoT devices employing wireless protocols such as 5G NR, Bluetooth and Wi-Fi. The results show that AirBugCatcher can reproduce 90.4% (40/44) of bugs (crashes or hangs) extracted from fuzzing logs and generate PoC code that contains minimal attack vectors. For instance, AirBugCatcher only generates up to three fuzzed packets (i.e., three attack vectors) from fuzzing logs that contain ≈47K fuzzed packets. Finally, we demonstrate that a standard replay-based approach (i.e., attempting to replay all packets from fuzzing logs) fail to reproduce most bugs (15 out of 16) due to the non-deterministic nature of wireless protocol implementations. Overall, we highlight that AirBugCatcher offers a valuable addition to IoT fuzz testing pipelines by automating the process of OTA bug reproduction and empowering researchers and developers to identify and fix security flaws in IoT devices more efficiently. Guoqiang Hua, Matheus E. Garbelini, Sudipta Chattopadhyay 0001 |
ACSAC | 2 |
| 2024 | U-Fuzz: Stateful Fuzzing of IoT Protocols on COTS DevicesabstractInternet-of-Things (IoT) devices have become widely popular and are being increasingly utilized in both home and industrial environments. Such devices use a variety of different protocols for communication. Considering the complex and stateful nature of these protocols, their implementations may contain security vulnerabilities and are subject to remote exploitation. To address this, we present U-Fuzz, a framework to systematically discover and replicate security vulnerabilities on arbitrary wired and wireless IoT protocol implementations. Given only a network capture file which contains the packet traces of normal (i.e., benign) communication, U-Fuzz automatically constructs a protocol state machine. Subsequently, this state machine is leveraged via a stateful fuzzing engine to arbitrarily manipulate and replay communicated packets. U-Fuzz carefully disintegrates the design of state machine construction from the fuzzing actions and optimizations, allowing U-Fuzz to work with an arbitrary number of protocols without any change in the stateful fuzzing engine. U-Fuzz does not require any access to the source code of the protocol and it also does not involve any instrumentation. This makes U-Fuzz to applicable out-of-the-box for fuzzing arbitrary IoT devices employing a variety of protocols. We implemented U-Fuzz and applied it against ten subject implementations including implementations on five commercial-off-the-shelf (COTS) devices employing three popular IoT protocols: 5G NR, Zigbee, and CoAP. As of today, U-Fuzz discovered a total of 11 new vulnerabilities (out of 16) and CVEs have already been assigned to all of them. Zewen Shang, Matheus E. Garbelini, Sudipta Chattopadhyay 0001 |
ICST | 2 |
| 2024 | U-Fuzz: A Tool Prototype for Stateful Fuzzing of IoT Protocols on COTS DevicesabstractInternet-of-Things (IoT) devices have become widely popular and are being increasingly utilized in both home and industrial environments. Such devices use a variety of protocols for communication. Considering the complex and stateful nature of these protocols, their implementations may contain security vulnerabilities. To address this, we present u-Fuzz, a framework to automatically generate state machine and systematically discover security vulnerabilities on arbitrary wired and wireless IoT protocol implementations. U- Fuzz only takes a network capture file, which contains the packet traces of normal (i.e., benign) communication for the state machine construction and it does not require any access to the source code of the protocol. U-Fuzz does not demand any instrumentation. This makes U-Fuzz to applicable out-of-the-box for constructing state machine for fuzzing arbitrary IoT devices employing a variety of protocols. Evaluation of U - Fuzz with three popular IoT protocols (5G NR, Zigbee, and CoAP) reveals 11 new vulnerabilities (11 CVEs) and a total of 16 security flaws. Zewen Shang, Matheus E. Garbelini, Sudipta Chattopadhyay 0001 |
ICST | 2 |
| 2022 | Towards Automated Fuzzing of 4G/5G Protocol Implementations Over the AirabstractRecent rise in the mobile network communication vulnerabilities highlights the need for systematic security testing frameworks for communication protocols. In this paper, we propose a real-time framework to fully manipulate the 4G and 5G data-link and network communication to the base station (eNB/gNB). This is for experimenting and testing the security of data-link protocols such as Media Access Control (MAC), Radio Link Control (RLC), Packet Data Convergence Protocol (PDCP) and network protocols such as Radio Resource Control (RRC) and Non-access stratum (NAS). Although we focus on the base station, our framework is equally applicable for manipulating the communication to the user equipment (UE). An appealing feature of our framework is that it automatically constructs the protocol state machine during normal communication. This allows us to validate the response from the base station when it is subjected to unexpected packet sequences. Our framework also exposes an application programming interfaces (APIs) for designers to install custom attack scenarios. We have implemented our framework and used it to generate several (adversarial) scenarios that include injection of malformed and out-of-order packets as well as flooding certain packets. Our evaluation revealed crashes in OpenAirInterface (OAI) UE and gNB, as well as in Open5GS core network. Additionally, we guide our validation via the automatically constructed state machine and have caught most adversarial scenarios during our evaluation. We envision our proposed framework to provide the foundation for automated security testing of 4G/5G data-link protocol implementation. Matheus E. Garbelini, Zewen Shang, Sudipta Chattopadhyay 0001, Sumei Sun, Ernest Kurniawan |
GLOBECOM | 1 |
| 2022 | BrakTooth: Causing Havoc on Bluetooth Link Manager via Directed Fuzzing
Matheus E. Garbelini, Vaibhav Bedi, Sudipta Chattopadhyay 0001, Sumei Sun, Ernest Kurniawan |
USENIX Security Symposium | 1 |
| 2022 | Greyhound: Directed Greybox Wi-Fi FuzzingabstractThe recent rise in complex Wi-Fi vulnerabilities, such as KRACK and Dragonslayer, indicates the critical need for effective Wi-Fi protocol testing tools. In this article, we conceptualize, design and implement a directed fuzzing methodology namedGreyhoundthat automatically tests the Wi-Fi client implementations against vulnerabilities such as crashes or non-compliant behaviors. Leveraging a holistic Wi-Fi protocol model,Greyhounddirects the fuzzer in specific states of target Wi-Fi client. By exchanging mutated packets with a Wi-Fi client,Greyhoundaims to induce the client to exhibit anomalous behaviors that badly deviate from Wi-Fi protocols. We have implementedGreyhoundand evaluated it on a variety of real-world Wi-Fi clients, including smartphone, Raspberry Pi, IoT device microcontrollers and a medical device. Our evaluation indicates thatGreyhoundnot only automatically discovers known vulnerabilities (including KRACK and Dragonslayer) that would require specialized verification otherwise, but, more importantly, it also has uncovered four new vulnerabilities in popular Wi-Fi client devices. All discovered vulnerabilities have been confirmed by manufacturers and they have been assigned three different common vulnerability exposure (CVE) IDs. We also win a bug bounty of 2,200 USD for discovering the security vulnerabilities. Furthermore, our evaluation with three existing Wi-Fi fuzz testing tools reveals that all such tools fail to discover any of the vulnerabilities (including crashes) uncovered byGreyhound. Last but not the least, we have deployedGreyhoundto test the Wi-Fi client implementation on automotive head units.Greyhoundautomatically discovers KRACK, Dragonslayer and other anomalies in these Wi-Fi implementations. Such a real world try-out justifies the necessity and efficacy ofGreyhound. Matheus E. Garbelini, Chundong Wang 0001, Sudipta Chattopadhyay 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | SweynTooth: Unleashing Mayhem over Bluetooth Low Energy
Matheus E. Garbelini, Chundong Wang 0001, Sudipta Chattopadhyay 0001, Sumei Sun, Ernest Kurniawan |
USENIX ATC | 1 |