{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:D7CT36BN3CUKJRYA4WCYY6P4FA","short_pith_number":"pith:D7CT36BN","canonical_record":{"source":{"id":"1708.09114","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-30T04:47:56Z","cross_cats_sorted":[],"title_canon_sha256":"8195e59cd94f8ed2898ded541761d6ea9d692cfb07f4ae5d0dfb89fb5f94f082","abstract_canon_sha256":"8c6612b4cd35723b1ab81f44dc10492e06757ed06f6ff9af6a6a317b5d5baab3"},"schema_version":"1.0"},"canonical_sha256":"1fc53df82dd8a8a4c700e5858c79fc282d726cee3b4deb846b0bcc6d4dcb2611","source":{"kind":"arxiv","id":"1708.09114","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1708.09114","created_at":"2026-05-18T00:07:56Z"},{"alias_kind":"arxiv_version","alias_value":"1708.09114v1","created_at":"2026-05-18T00:07:56Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1708.09114","created_at":"2026-05-18T00:07:56Z"},{"alias_kind":"pith_short_12","alias_value":"D7CT36BN3CUK","created_at":"2026-05-18T12:31:10Z"},{"alias_kind":"pith_short_16","alias_value":"D7CT36BN3CUKJRYA","created_at":"2026-05-18T12:31:10Z"},{"alias_kind":"pith_short_8","alias_value":"D7CT36BN","created_at":"2026-05-18T12:31:10Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:D7CT36BN3CUKJRYA4WCYY6P4FA","target":"record","payload":{"canonical_record":{"source":{"id":"1708.09114","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-30T04:47:56Z","cross_cats_sorted":[],"title_canon_sha256":"8195e59cd94f8ed2898ded541761d6ea9d692cfb07f4ae5d0dfb89fb5f94f082","abstract_canon_sha256":"8c6612b4cd35723b1ab81f44dc10492e06757ed06f6ff9af6a6a317b5d5baab3"},"schema_version":"1.0"},"canonical_sha256":"1fc53df82dd8a8a4c700e5858c79fc282d726cee3b4deb846b0bcc6d4dcb2611","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:07:56.371072Z","signature_b64":"aQko3R06B+6UfOeanbS/bxCJNivwveXKJ9CuP8tEtQH/iErJoc3p11/dlmRE9MXaljFQjuELw1YrRd1JnVO9Cg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"1fc53df82dd8a8a4c700e5858c79fc282d726cee3b4deb846b0bcc6d4dcb2611","last_reissued_at":"2026-05-18T00:07:56.370434Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:07:56.370434Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1708.09114","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:07:56Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"h6zK2uiPna+x2JfSK5ZgsvbhGKrVuk+1QcAnG4lCzgkZ91eYh9JjnpLKt6JFVhMTG8407glSe1ChGNU/iyBsDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-27T02:33:53.951026Z"},"content_sha256":"2895726235e07254dcef5dff4df9c1cffb6a78a40414a8d72c141f3e6bfa801d","schema_version":"1.0","event_id":"sha256:2895726235e07254dcef5dff4df9c1cffb6a78a40414a8d72c141f3e6bfa801d"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:D7CT36BN3CUKJRYA4WCYY6P4FA","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"FirmUSB: Vetting USB Device Firmware using Domain Informed Symbolic Execution","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Dave Tian, Farhaan Fowze, Grant Hernandez, Kevin R. B. Butler, Tuba Yavuz","submitted_at":"2017-08-30T04:47:56Z","abstract_excerpt":"The USB protocol has become ubiquitous, supporting devices from high-powered computing devices to small embedded devices and control systems. USB's greatest feature, its openness and expandability, is also its weakness, and attacks such as BadUSB exploit the unconstrained functionality afforded to these devices as a vector for compromise. Fundamentally, it is virtually impossible to know whether a USB device is benign or malicious. This work introduces FirmUSB, a USB-specific firmware analysis framework that uses domain knowledge of the USB protocol to examine firmware images and determine the"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1708.09114","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:07:56Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"h5bGlzf2YXrBrUwUgZPeCMXncj2ELC8ctEHkFaVt9Ct5US1rzZifCPuGUu/po55qSHBm/D8y00/PNbY+jLIoCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-27T02:33:53.951380Z"},"content_sha256":"7763120b85cf4b654c577cc009613f9c20a1cf36ea1385eac110d2dfc1b7f92f","schema_version":"1.0","event_id":"sha256:7763120b85cf4b654c577cc009613f9c20a1cf36ea1385eac110d2dfc1b7f92f"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/D7CT36BN3CUKJRYA4WCYY6P4FA/bundle.json","state_url":"https://pith.science/pith/D7CT36BN3CUKJRYA4WCYY6P4FA/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/D7CT36BN3CUKJRYA4WCYY6P4FA/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-27T02:33:53Z","links":{"resolver":"https://pith.science/pith/D7CT36BN3CUKJRYA4WCYY6P4FA","bundle":"https://pith.science/pith/D7CT36BN3CUKJRYA4WCYY6P4FA/bundle.json","state":"https://pith.science/pith/D7CT36BN3CUKJRYA4WCYY6P4FA/state.json","well_known_bundle":"https://pith.science/.well-known/pith/D7CT36BN3CUKJRYA4WCYY6P4FA/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:D7CT36BN3CUKJRYA4WCYY6P4FA","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"8c6612b4cd35723b1ab81f44dc10492e06757ed06f6ff9af6a6a317b5d5baab3","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-30T04:47:56Z","title_canon_sha256":"8195e59cd94f8ed2898ded541761d6ea9d692cfb07f4ae5d0dfb89fb5f94f082"},"schema_version":"1.0","source":{"id":"1708.09114","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1708.09114","created_at":"2026-05-18T00:07:56Z"},{"alias_kind":"arxiv_version","alias_value":"1708.09114v1","created_at":"2026-05-18T00:07:56Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1708.09114","created_at":"2026-05-18T00:07:56Z"},{"alias_kind":"pith_short_12","alias_value":"D7CT36BN3CUK","created_at":"2026-05-18T12:31:10Z"},{"alias_kind":"pith_short_16","alias_value":"D7CT36BN3CUKJRYA","created_at":"2026-05-18T12:31:10Z"},{"alias_kind":"pith_short_8","alias_value":"D7CT36BN","created_at":"2026-05-18T12:31:10Z"}],"graph_snapshots":[{"event_id":"sha256:7763120b85cf4b654c577cc009613f9c20a1cf36ea1385eac110d2dfc1b7f92f","target":"graph","created_at":"2026-05-18T00:07:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"The USB protocol has become ubiquitous, supporting devices from high-powered computing devices to small embedded devices and control systems. USB's greatest feature, its openness and expandability, is also its weakness, and attacks such as BadUSB exploit the unconstrained functionality afforded to these devices as a vector for compromise. Fundamentally, it is virtually impossible to know whether a USB device is benign or malicious. This work introduces FirmUSB, a USB-specific firmware analysis framework that uses domain knowledge of the USB protocol to examine firmware images and determine the","authors_text":"Dave Tian, Farhaan Fowze, Grant Hernandez, Kevin R. B. Butler, Tuba Yavuz","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-30T04:47:56Z","title":"FirmUSB: Vetting USB Device Firmware using Domain Informed Symbolic Execution"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1708.09114","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:2895726235e07254dcef5dff4df9c1cffb6a78a40414a8d72c141f3e6bfa801d","target":"record","created_at":"2026-05-18T00:07:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"8c6612b4cd35723b1ab81f44dc10492e06757ed06f6ff9af6a6a317b5d5baab3","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2017-08-30T04:47:56Z","title_canon_sha256":"8195e59cd94f8ed2898ded541761d6ea9d692cfb07f4ae5d0dfb89fb5f94f082"},"schema_version":"1.0","source":{"id":"1708.09114","kind":"arxiv","version":1}},"canonical_sha256":"1fc53df82dd8a8a4c700e5858c79fc282d726cee3b4deb846b0bcc6d4dcb2611","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"1fc53df82dd8a8a4c700e5858c79fc282d726cee3b4deb846b0bcc6d4dcb2611","first_computed_at":"2026-05-18T00:07:56.370434Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:07:56.370434Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"aQko3R06B+6UfOeanbS/bxCJNivwveXKJ9CuP8tEtQH/iErJoc3p11/dlmRE9MXaljFQjuELw1YrRd1JnVO9Cg==","signature_status":"signed_v1","signed_at":"2026-05-18T00:07:56.371072Z","signed_message":"canonical_sha256_bytes"},"source_id":"1708.09114","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:2895726235e07254dcef5dff4df9c1cffb6a78a40414a8d72c141f3e6bfa801d","sha256:7763120b85cf4b654c577cc009613f9c20a1cf36ea1385eac110d2dfc1b7f92f"],"state_sha256":"420748ef25af68d37dbcdbbeb5163ba3d6d3021c45a356a04552cb9a6cb50376"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"iUAYbjkpFZnWRPjjTZMrS9zyPaO8XxwgJ0xB+7keoKanRweudSZS6ROpBi+oLzAuSz8uVD/8/hfIFYE6azq/Dw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-27T02:33:53.953201Z","bundle_sha256":"f08b4d69e9d80dac8034b930971fc507d09fa060210c50bf283c6a629728fa6b"}}