{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/121481"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/121481","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Emulation-based security measurement with applications in avionics, redaction, and industrial control","abstract":"Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2023-12-04 without embargo terms","abstract_html":"Submission original under an indefinite embargo labeled &#x27;Open Access&#x27;. The submission was exported from vireo on 2023-12-04 without embargo terms","abstract_has_math":false,"creators":["Bland, Maxwell"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Levchenko, Kirill","Bates, Adam","Schulman, Aaron","Wang, Gang"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2023,"date_issued":"2023-08","date_published":"2023-08","updated_at":"2026-07-22T22:24:57Z","subjects":["Emulation","Industrial Control","Rehosting","Information Leaks","Lifting","Security","Privacy","Redactions","Avionics"],"languages":["en","eng"],"rights":["Copyright 2023 Maxwell Bland"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/2142/121481","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Levchenko, Kirill","Bates, Adam","Schulman, Aaron","Wang, Gang"]},{"key":"dc:creator","label":"Author","values":["Bland, Maxwell"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2023-08","2023-07-12"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Emulation","Industrial Control","Rehosting","Information Leaks","Lifting","Security","Privacy","Redactions","Avionics"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en","eng"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2023 Maxwell Bland"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://hdl.handle.net/2142/121481"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2023-12-04 without embargo terms","The student, Maxwell Bland, accepted the attached license on 2023-07-08 at 22:03.","The student, Maxwell Bland, submitted this Dissertation for approval on 2023-07-08 at 22:11.","This Dissertation was approved for publication on 2023-07-12 at 16:28.","DSpace SAF Submission Ingestion Package generated from Vireo submission #19574 on 2023-12-04 at 17:01:06","The safety of critical systems and data is of paramount importance to society. Attacks on these systems can have catastrophic consequences, and the security of these systems is often difficult to measure. Existing methods often involve access to an operating version of the system, such as a physical device or executable specification, to provide ground-truth. However, access to a complete representation of the system is not always possible or practical. In this dissertation, we explore the use of emulation to measure the security of systems in the absence of this ground-truth information. Complex system emulation often requires sophisticated approaches to digital forensics and tactics for navigating undecidability resulting from uncertainty of the system's state. To address these challenges, we present intelligent guess-and-check strategies for deducing hidden information in executable code in the absence of original source code or other auxiliary information. Our core technical contributions are (1) the first symbolic execution based firmware rehosting system, used to generate emulations of embedded systems. (2) A novel system for the analysis and recovery of glyph positioning information in PDF documents. This system was used to recover redacted text information where the characters were removed in hundreds of sensitive documents. (3) A logic-based intermediate representation and framework for the extraction of lifted function summaries from binary firmware. This framework makes existing verification and synthesis techniques applicable to real-world systems by translating implemented code to mathematical models. Where appropriate, we justify our strategies through discussions of correctness, precision, and generalizability. Our results are never theoretical: we apply them to pre-existing, empirically validatable domain rather than models: among others, we study the Communication Management Unit used in Boeing 737 Aircraft, historically important redacted documents, and a programmable logic controller operating a Tennessee Eastman chemical plant reactor pressure valve."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Emulation-based security measurement with applications in avionics, redaction, and industrial control"]}]}],"canonical_facts":{"dc:contributor":["Levchenko, Kirill","Bates, Adam","Schulman, Aaron","Wang, Gang"],"dc:creator":["Bland, Maxwell"],"dc:date":["2023-08","2023-07-12"],"dc:description":["Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2023-12-04 without embargo terms","The student, Maxwell Bland, accepted the attached license on 2023-07-08 at 22:03.","The student, Maxwell Bland, submitted this Dissertation for approval on 2023-07-08 at 22:11.","This Dissertation was approved for publication on 2023-07-12 at 16:28.","DSpace SAF Submission Ingestion Package generated from Vireo submission #19574 on 2023-12-04 at 17:01:06","The safety of critical systems and data is of paramount importance to society. Attacks on these systems can have catastrophic consequences, and the security of these systems is often difficult to measure. Existing methods often involve access to an operating version of the system, such as a physical device or executable specification, to provide ground-truth. However, access to a complete representation of the system is not always possible or practical. In this dissertation, we explore the use of emulation to measure the security of systems in the absence of this ground-truth information. Complex system emulation often requires sophisticated approaches to digital forensics and tactics for navigating undecidability resulting from uncertainty of the system's state. To address these challenges, we present intelligent guess-and-check strategies for deducing hidden information in executable code in the absence of original source code or other auxiliary information. Our core technical contributions are (1) the first symbolic execution based firmware rehosting system, used to generate emulations of embedded systems. (2) A novel system for the analysis and recovery of glyph positioning information in PDF documents. This system was used to recover redacted text information where the characters were removed in hundreds of sensitive documents. (3) A logic-based intermediate representation and framework for the extraction of lifted function summaries from binary firmware. This framework makes existing verification and synthesis techniques applicable to real-world systems by translating implemented code to mathematical models. Where appropriate, we justify our strategies through discussions of correctness, precision, and generalizability. Our results are never theoretical: we apply them to pre-existing, empirically validatable domain rather than models: among others, we study the Communication Management Unit used in Boeing 737 Aircraft, historically important redacted documents, and a programmable logic controller operating a Tennessee Eastman chemical plant reactor pressure valve."],"dc:format":["application/pdf"],"dc:identifier":["https://hdl.handle.net/2142/121481"],"dc:language":["en","eng"],"dc:rights":["Copyright 2023 Maxwell Bland"],"dc:subject":["Emulation","Industrial Control","Rehosting","Information Leaks","Lifting","Security","Privacy","Redactions","Avionics"],"dc:title":["Emulation-based security measurement with applications in avionics, redaction, and industrial control"],"dc:type":["text"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:57Z"}