---
title: "Publications - Red Balloon Security"
description: "RESOURCES PUBLICATIONS The collective vision, passion and hard work of the Red Balloon Security researchers has made universally compatible security for embedded systems a reality. // Featured Research Publications Members of the Red Balloon Security team have spearheaded DoD-funded research initiatives. SEE ALL > Siemens S7-1500: Critical Vulnerabilities Discovered Critical vulnerabilities researched in Siemens SIMATIC"
date: "2021-11-15T19:08:40+00:00"
language: "en-US"
canonical_url: "https://xckd6kzuxte054o.onstatic.studio/publications/"
source_url: "https://xckd6kzuxte054o.onstatic.studio/publications/"
content_type: "text/markdown"
---

[
			Skip to content		](#content)








											[
			![Red Balloon Security](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/2026/01/Client-Logos-RBS-Website-2025Asset-33.svg)				](https://xckd6kzuxte054o.onstatic.studio/)



										[

									CONTACT

					](https://xckd6kzuxte054o.onstatic.studio/contact/)














#
						RESOURCES


## PUBLICATIONS




The collective vision, passion and hard work of the Red Balloon Security researchers  has made universally compatible security for embedded systems a reality.










##
						// Featured Research Publications





Members of the Red Balloon Security team have spearheaded DoD-funded research initiatives.




										[

									SEE ALL >

					](https://xckd6kzuxte054o.onstatic.studio/research/)




					[![Siemens SIMATIC S7-1500 controller — Red Balloon Security vulnerability research](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/AF3I0415-e1673412681699.jpg)](https://xckd6kzuxte054o.onstatic.studio/siemens-discovery/)

### [Siemens S7-1500: Critical Vulnerabilities Discovered](https://xckd6kzuxte054o.onstatic.studio/siemens-discovery/)

Critical vulnerabilities researched in Siemens SIMATIC and SIPLUS S7-1500 series, bypassing protected boot features.





					[![DARPA RADICS program — power grid security research](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/2021/11/982a18_563ba8803b254d3d88501672e846f865_mv2.png-668x448-1.webp)](https://xckd6kzuxte054o.onstatic.studio/research/darpa-radics-program/)

### [DARPA RADICS PROGRAM:
Protecting The Power Grid](https://xckd6kzuxte054o.onstatic.studio/research/darpa-radics-program/)

Embedding defenses in relays, RTUs, and network equipment boosts security, detects attacks, and offers device-level forensics.





					[![PIADC facility network controller research](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/2022/02/PIADC_THUMB@4x.png)](https://xckd6kzuxte054o.onstatic.studio/research/piadc-facility/)

### [PIADC FACILITY:
Network Controllers](https://xckd6kzuxte054o.onstatic.studio/research/piadc-facility/)

U.S. Government funded research for advanced on-device security in network controllers.





					[![Thrangrycat — Cisco secure boot bypass research](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/2021/11/982a18_12e210ffb93e4a8aa2a516afa936ed42_mv2.png-668x448-1.webp)](https://xckd6kzuxte054o.onstatic.studio/research/thrangrycat/)

### [THRANGRYCAT:
Defeating Cisco's Secure Boot](https://xckd6kzuxte054o.onstatic.studio/research/thrangrycat/)

Uncovered vulnerability lets attackers bypass Cisco's secure boot and block updates.











## Research Findings





The team at Red Balloon has published seminal research papers in the fields of embedded security and established themselves as thought leaders in academic communities.









## Defeating Cisco trust anchor: a case-study of recent advancements in direct FPGA bitstream manipulation





Cui, Ang, Jatin Kataria, Rick Housley, and Joseph Pantoga. In 13th USENIX Workshop on Offensive Technologies (WOOT 19). USENIX Association. 2019.



										[





									DOWNLOAD

					](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/Defeating-Cisco-Trust-Anchor-A-Case-Study-of-Recent-Advancements-in-Direct-FPGA-Bitstream-Manipulation.pdf)








## From prey to hunter: transforming legacy embedded devices into exploitation sensor grids.



									Cui, Ang, Jatin Kataria, and Salvatore J. Stofo. In Proceedings of the 27th Annual Computer Security Applications Conference, pp. 393-402. ACM, 2011.



										[





									DOWNLOAD

					](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/From-Prey-to-Hunter-Transforming-Legacy-Embedded-Devices-Into-Exploitation-Sensor-Grids.pdf)








## BADFET: defeating modern secure boot using second-order pulsed electromagnetic fault injection.



									Cui, Ang, and Rick Housley. In 11th USENIX Workshop on Offensive Technologies (WOOT 17). USENIX Association, vol. 180. 2017.



										[





									DOWNLOAD

					](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/BADFET-Defeating-Modern-Secure-Boot-Using-Second-Order-Pulsed-Electromagnetic-Fault-Injection.pdf)








### [Utilizing electromagnetic emanations for out-of-band detection of unknown attack code in a programmable logic controller.](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/Utilizing-Electromagnetic-Emanations-for-Out-of-Band-Detection-of-Unknown-Attack-Code-in-a-Programmable-Logic-Controller.pdf)



									Boggs, Nathaniel, Jimmy C. Chau, and Ang Cui. Cyber Sensing 2018. Vol. 10630. International Society for Optics and Photonics, 2018.



										[





									DOWNLOAD

					](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/Utilizing-Electromagnetic-Emanations-for-Out-of-Band-Detection-of-Unknown-Attack-Code-in-a-Programmable-Logic-Controller.pdf)


									Copyright 2018 Society of Photo-Optical Instrumentation Engineers. One print or electronic copy may be made for personal use only. Systematic reproduction and distribution, duplication of any material in this paper for a fee or for commercial purposes, or modification of the content of the paper are prohibited.









### Automotive Exploitation Sandbox: A Hands-on Educational Introduction to Embedded Device Exploitation.





Boggs, Nathaniel; Cui, Ang; Kataria, Jatin; Laulheret, Philippe. escar USA: Embedded Security in Cars. 2018.



										[





									DOWNLOAD

					](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/Automotive-Exploitation-Sandbox-A-Hands-on-Educational-Introduction-to-Embedded-Device-Exploitation.pdf)








### [Symbiotes and defensive mutualism: Moving target defense.](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/Symbiotes-and-Defensive-Mutualism-Moving-Target-Defense.pdf)



									Cui, Ang, and Salvatore J. Stolfo. In Moving target defense, pp. 99-108. Springer, New York, NY, 2011.



										[





									DOWNLOAD

					](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/Symbiotes-and-Defensive-Mutualism-Moving-Target-Defense.pdf)








### [Concurrency Attacks.](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/Concurrency-Attacks.pdf)



									Yang, Junfeng, Ang Cui, Salvatore J. Stolfo, and Simha Sethumadhavan. HotPar 12 (2012): 15.



										[



									DOWNLOAD

					](https://xckd6kzuxte054o.onstatic.studio/wp-content/uploads/Concurrency-Attacks.pdf)













## PROTECT YOUR SYSTEMS
AGAINST EXPLOITATION



										[

									CONTACT US

					](https://xckd6kzuxte054o.onstatic.studio/contact/)










        115
