EMBEDDED DEVICES SECURITY AND FIRMWARE REVERSE ENGINEERING

Black Hat USA 2013

Presented by: Andrei Costin, Jonas Zaddach
Date: Wednesday July 31, 2013
Time: 14:15 - 18:00
Location: Pompeian

Embedded devices have become the "usual presence" in the network of (m)any household(s), SOHO, enterprise or critical infrastructure.

The preached Internet of Things promises to "gazillion"uple their number and heterogeneity in the next few years.

However, embedded devices are becoming lately the "usual suspects" in security breaches and security advisories and thus become the "Achilles' heel" of one's overall infrastructure security.

An important aspect is that embedded devices run on what's commonly known as firmwares.

To understand how to secure embedded devices, one needs to understand their firmware and how it works.

This workshop aims at presenting a quick-start at how to inspect firmwares and a hands-on presentation with exercises on real firmwares from a security analysis standpoint.

Andrei Costin

Andrei is a Computer Science graduate of the Politehnica University of Bucharest where he did his thesis work in Biometrics and Image Processing. While starting out his IT-career in the Computer Games industry, he has worked in the Telecom field and also was a senior developer at a specialized firm programming various GSM/UMTS/GPS sub-systems. He is the author of the MiFare Classic Universal toolKit (MFCUK), the first publicly available (FOSS) card-only key cracking tool for the MiFare Classic RFID card family and is known as the "printer guy" for his "Hacking MFPs" and "Hacking PostScript" series of hacks & talks at various international conferences. Lately he was spotted security-harassing airplanes with ADS-B hacks, though no planes were harmed during the experiments. He is passionate about security in a holistic fashion. Currently he is a PhD candidate with EURECOM in field of "Security of embedded devices."

Jonas Zaddach

Jonas Zaddach is a Computer Science graduate of the Technische Universitaet Muenchen and Telecom ParisTech, where he wrote his thesis on securing infrastructure-as-a-service clouds in a double-degree program. Results from this research is at basis of the well-received presentation "SatanCloud:A Journey Into the Privacy and Security Risks of Cloud Computing." In his youth he spent his time making his Lego Mindstorms robot do things it was not supposed to do by hacking its firmware. Since then he has shifted his attention to hard drives, and is currently a PhD candidate with EURECOM in the field of dynamic analysis of embedded devices' firmware.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats