Resources Video

FCC Device Data

Dr. Bob Baxley, Chief Scientist at Bastille Networks discusses "FCC Device Data"

 

Every device sold in the United States that transmits wirelessly carries an FCC ID, and behind that ID sits a public file of certification test reports. Those reports exist to prove the device stays within legal emission limits — but they also document, in detail, exactly how the device uses the spectrum: which frequencies, which protocols, which packet formats, and how it behaves under test.

In this talk, Bastille Chief Engineer Dr. Bob Baxley walks through the FCC device database as a research resource: what’s in it, how security researchers have used it to reverse-engineer wireless protocols, and what emerges when the entire dataset is scraped, parsed, and plotted by frequency and equipment class.

The point is not that this data is secret — it is public domain, and anyone can read it. The point is that it dramatically lowers the effort required to understand and attack a wireless protocol, and it is equally valuable to the defenders building sensors that need to recognize those protocols in the field.

Key takeaways

  • FCC IDs are a certification record: to earn one, a manufacturer must have the device tested by a lab to confirm it stays within legal emission limits and transmits only in permitted bands.
  • The test reports are public domain: the FCC logs them in a searchable database that anyone can browse using the FCC ID printed on the device.
  • The filings are extraordinarily detailed: dozens of independent PDFs per device, covering every frequency it operates on, the radio standards it uses, and lab photos including emission-pattern testing in operating position.
  • They document protocol behavior: which protocols a device uses, packet structures, and formats — the same information an attacker or a researcher would otherwise have to reverse-engineer from scratch.
  • Patent filings are a parallel source: also public domain, and often equally revealing about how a proprietary wireless protocol works.
  • Real research has come out of it: Bastille researcher Logan Lamb used FCC documentation for home security systems to understand their wireless door-sensor protocol, then demonstrated spoofing a “door still closed” signal — walking in without triggering the alarm.
  • The whole database can be analyzed at once: scraped and categorized by frequency and equipment class, it becomes a map of which device types occupy which parts of the spectrum.
  • The map mostly matches expectations — until it doesn’t: 900 MHz shows cordless phones but also paging receivers and satellite gear; digging into specific classes and frequencies surfaces genuinely counterintuitive devices.

What an FCC ID actually represents

Open up almost any wireless device and you’ll find an FCC ID printed on the case or inside the battery compartment. To obtain that ID, the manufacturer had to submit the device to a certification lab. The certification confirms two things: that the device operates within the legal limits of wireless emissions — it doesn’t transmit too much power — and that it only transmits in permitted, unlicensed spectrum.

The test reports generated during that certification process are sent to the FCC, which logs them in a public database. Anyone can search it, view the filings, and use them.

Example: looking up an iPhone

An iPhone has its FCC ID printed clearly on the back. Type that ID into the database and you get a full record of the device’s radio behavior:

  • Every frequency it operates on — multiple cellular carrier bands, plus Bluetooth, Wi-Fi, and NFC. A modern phone uses a lot of radio standards, and all of them are enumerated.
  • Lab test photographs — including the handset held in operating position while the emission pattern is measured.
  • Dozens of independent PDFs — available for almost any device that transmits wirelessly.

Why this matters to researchers and attackers

For an IT security person, a researcher, or an attacker, the value is straightforward: those documents describe how the device uses the wireless spectrum. What protocols it speaks, what the packets look like, what the formats are. That is normally the hardest and slowest part of attacking a proprietary wireless system, and here it is handed over in a certification filing.

The same kind of information also turns up in patent filings, which are likewise public domain. Between the two sources, a proprietary protocol is often far less opaque than its vendor assumes.

Case study: home security system door sensors

Bastille security researcher Logan Lamb used exactly this approach against home security systems, which rely on wireless door sensors and other wireless components. By reading the FCC documentation, he was able to understand precisely how the protocol worked, which made it far easier to demonstrate its vulnerabilities.

The result was demonstrated on Good Morning America: using a software defined radio to spoof the wireless protocol, he transmitted a signal telling the alarm panel the door was still closed even as the door was opened. In practice, that means walking into a building without the alarm ever going off.

That’s one example of what the FCC dataset makes possible — and a reminder that “proprietary” is not a security property when the protocol is documented in a public filing.

Analyzing the whole database at once

Individual lookups are useful, but the database becomes something else entirely when you take all of it. Bastille scraped the full set of FCC device data, categorized it, and parsed it by frequency and by usage, then built a portal for slicing through it.

In that tool, the x-axis is frequency and the y-axis is the device equipment class as classified by the FCC. Supporting panels show device metadata as described by the FCC, the manufacturer, and related details. Highlight a frequency range and the tool filters to the device types that live there.

The 900 MHz band

Highlight 900 MHz and the expected devices appear — 900 MHz cordless phones, in several varieties. Less expected: paging receivers and satellite equipment also occupy that space. This is the kind of context that helps interpret what a sensor is actually seeing in the field.

The 300–500 MHz cluster

A visible cluster of devices with similar equipment classes sits between roughly 300 and 500 MHz. Highlight that region and it resolves into remote control transmitters: RC cars, key fobs, and automotive security system transmitters. The manufacturers are exactly who you’d expect — companies like Honeywell and Chamberlain.

The 2.4 GHz band

Highlight 2.4 GHz and everything else filters out, leaving Wi-Fi and Bluetooth devices: computers, tablets, phones, Bluetooth headsets, Bluetooth speakers. Zoom in on manufacturers and Apple and Samsung dominate — again, exactly what you’d expect.

The interesting findings come from spending more time in the data. Digging into particular equipment classes at particular frequencies starts surfacing counterintuitive devices — things you wouldn’t expect to be transmitting where they are.

The defensive value of public device data

For a wireless security team, the FCC dataset serves two purposes. It provides the protocol detail needed to build and validate detection for device families that ship no public specification — an essential input when a sensor has to recognize a proprietary protocol from the physical layer up. And it provides a map of the spectrum by device class, which helps interpret what a sensor observes: given an emitter at this frequency with this behavior, what class of device is it likely to be?

It is also a reminder about threat modeling. Any attacker targeting a wireless device in your environment starts with the same public filings. Obscurity buys nothing; visibility into what is actually transmitting in your facility is what matters.

Full Transcript

Hi, welcome to this talk on FCC device data. My name’s Bob Baxley and I’m the Chief Engineer at Bastille, where I lead the radio and data science teams. In this talk I want to give you a feeling for the kinds of data behind the FCC ID, and how that data can be used to do all kinds of things.

What’s in the FCC database

I’ve got a screenshot of the FCC’s website that lets you search for FCC device data. What you’re actually searching for — I’ll just use this wireless device as an example — is the FCC ID printed on the device. When I open up the back, there’s an FCC ID printed there.

For the manufacturer to get that FCC ID for this device, they had to have it certified by a lab. The certification says the device operates within the legal limits of wireless emissions — so it doesn’t transmit too much power, and it only transmits in unlicensed spectrum. The test reports from that certification process get sent to the FCC, and the FCC logs them in this database, where it’s public domain data. So you can view them; anyone can use them.

Here’s a picture of an iPhone, and the FCC ID is printed clearly on the back of the iPhone. If you type that FCC ID into the database, you get an interface that looks like this. In the screenshot on the left you can see all the frequencies that iPhone operates in, since the iPhone talks on several different cellular carrier frequencies, plus Bluetooth, Wi-Fi, NFC — there are lots of radio standards that it utilizes. And then you also see these really cool test pictures. That’s an iPhone held up in the operating position, and they’re assessing the emission pattern from the iPhone. So it’s super cool data. There are literally dozens and dozens of independent PDFs that you can get for almost any device that transmits wirelessly.

Why it’s interesting for security

One reason that’s interesting, if you’re an IT security person — or a hacker, or a researcher — is that in those documents it’s documented how this device uses the wireless spectrum. What protocols it uses, the packets, the formats, all those things. That kind of information can also be found in patent filings, which are also public domain.

We’ve got a picture of Logan Lamb, one of our security researchers. He was able to use the FCC documentation for home security systems, which have wireless door sensors and wireless components. He was able to look at the documents and understand exactly how the protocol worked, which made it much easier to demonstrate some of the vulnerabilities in this protocol.

There’s another screenshot of him on Good Morning America, where he demonstrated the ability to take a radio that was spoofing the wireless protocol of the wireless home security system and basically transmit the signal that says the door’s still closed, even as the door was open. What that means is he would be able to walk into the building without the alarm going off. So, super cool — and that’s just one example of the sorts of things that you can do with the FCC data.

Demo: slicing the full dataset

Another example: I want to show you a demo where we’ve scraped all this FCC data and categorized it, parsed it by frequency and by usage. We’ve got this really neat portal where we can slice and dice it. So let me show you that demo right now.

Again, we’ve scraped all the FCC device data. In the plot here, the x-axis is frequency and the y-axis is the device equipment class as classified by the FCC. In the lower left I have metadata about the devices as described by the FCC, the middle is the manufacturer, and the bottom right has additional detail.

What we can do with this tool is highlight certain frequency ranges and see what types of devices are in those ranges. So we highlight the 900 megahertz band here. What do we see? Well, we’d expect to see things like 900 megahertz cordless phones, and of course that’s what we see — on the lower left you can see several different types of cordless phones. What’s also interesting is to see paging receivers and satellites. This is the sort of tool that helps us understand what we’re seeing with our sensors.

When I click away from that and reset it, the next thing I’m going to highlight is this little cluster of devices. As you can see, they have similar equipment classes, and they’re from about 300 to 500 megahertz. If I highlight that region right there, we see remote control transmitters. This is where RC car remote controls live. This is where key fobs live, and automotive security system transmitters. All those sorts of things live in this little block of frequencies and classes, and you can see companies like Honeywell and Chamberlain make these sorts of devices — which is what you would expect.

For the last example, I’m going to highlight the 2.4 band. There we would expect to see devices that have Wi-Fi and Bluetooth, so those devices will be things like computers, and tablets, and phones. I’m going to highlight it, it’s going to filter everything out, and of course we see that — we see Bluetooth headsets, Bluetooth speakers, tablet PCs. If you zoom in on the manufacturers, you can see companies like Apple and Samsung make these devices. So exactly the sorts of things you would expect.

But if you spend a little bit more time with this, digging into the particular classes at particular frequencies, you start seeing kind of counterintuitive things — things you wouldn’t expect. So it’s a really, really neat tool. Thanks for listening. My name’s Bob Baxley and I’m with Bastille.

We’d love to show you around

Learn how Bastille can help you prepare you for today’s ever-growing wireless threat landscape, and schedule a demo and we’ll be in touch shortly.