RESOURCES

PUBLICATIONS

The collective vision, passion and hard work of the Red Balloon Security researchers  has made universally compatible security for embedded systems a reality.

// Featured Research Publications

Members of the Red Balloon Security team have spearheaded DoD-funded research initiatives.

Siemens SIMATIC S7-1500 controller — Red Balloon Security vulnerability research

Siemens S7-1500: Critical Vulnerabilities Discovered

Critical vulnerabilities researched in Siemens SIMATIC and SIPLUS S7-1500 series, bypassing protected boot features.

DARPA RADICS program — power grid security research

DARPA RADICS PROGRAM:
Protecting The Power Grid

Embedding defenses in relays, RTUs, and network equipment boosts security, detects attacks, and offers device-level forensics.

PIADC facility network controller research

PIADC FACILITY:
Network Controllers

U.S. Government funded research for advanced on-device security in network controllers.

Thrangrycat — Cisco secure boot bypass research

THRANGRYCAT:
Defeating Cisco's Secure Boot

Uncovered vulnerability lets attackers bypass Cisco's secure boot and block updates.

Research Findings

The team at Red Balloon has published seminal research papers in the fields of embedded security and established themselves as thought leaders in academic communities.

Defeating Cisco trust anchor: a case-study of recent advancements in direct FPGA bitstream manipulation

Cui, Ang, Jatin Kataria, Rick Housley, and Joseph Pantoga. In 13th USENIX Workshop on Offensive Technologies (WOOT 19). USENIX Association. 2019.

From prey to hunter: transforming legacy embedded devices into exploitation sensor grids.

Cui, Ang, Jatin Kataria, and Salvatore J. Stofo. In Proceedings of the 27th Annual Computer Security Applications Conference, pp. 393-402. ACM, 2011.

BADFET: defeating modern secure boot using second-order pulsed electromagnetic fault injection.

Cui, Ang, and Rick Housley. In 11th USENIX Workshop on Offensive Technologies (WOOT 17). USENIX Association, vol. 180. 2017.

Boggs, Nathaniel, Jimmy C. Chau, and Ang Cui. Cyber Sensing 2018. Vol. 10630. International Society for Optics and Photonics, 2018.

Copyright 2018 Society of Photo-Optical Instrumentation Engineers. One print or electronic copy may be made for personal use only. Systematic reproduction and distribution, duplication of any material in this paper for a fee or for commercial purposes, or modification of the content of the paper are prohibited.

Automotive Exploitation Sandbox: A Hands-on Educational Introduction to Embedded Device Exploitation.

Boggs, Nathaniel; Cui, Ang; Kataria, Jatin; Laulheret, Philippe. escar USA: Embedded Security in Cars. 2018.

Cui, Ang, and Salvatore J. Stolfo. In Moving target defense, pp. 99-108. Springer, New York, NY, 2011.

Yang, Junfeng, Ang Cui, Salvatore J. Stolfo, and Simha Sethumadhavan. HotPar 12 (2012): 15.

PROTECT YOUR SYSTEMS
AGAINST EXPLOITATION