#HITB2024BKK

  Рет қаралды 131

Hack In The Box Security Conference

Hack In The Box Security Conference

Күн бұрын

In this talk we present novel methods for the use of Generative AI - specifically Large Language Models (LLMs) to enhance the ability of cybersecurity investigators to trace and deter unauthorized exfiltration of text data that involves an air gap (shift in transmission mediums that resists digital forensic analysis). We review the definition of an air gap in this context, and describe the current state of the art with regards with digital watermarking and DLP to frame the discussion.
We then introduce 2 practical applications - one simple/naive, one more sophisticated - that leverage an LLM (tested on Senku 70B, possibly others by the time of the presentation) to inject what we term “semantic watermarking” in such a way that regardless of the exfiltration method, the watermark can be both preserved with relatively high integrity as well as deterministically associated with an individual actor. This enables an investigative team to identify either malicious insider actors, or compromised users within their environment.
We also review tradeoffs in deployment of these applications, and then close with discussion of potentially more sophisticated implementations that would extend this capability to other forms of data such as audio or video.
===
Experienced 12+ year DFIR practitioner with a daub of red team work throughout. Currently specializing in insider threats and internal investigations. Bringing offensive minded solutions to blue teams!

Пікірлер
#HITB2024BKK #COMMSEC D1: Who’s the Author? How Automated Malware Attribution Engines Work
21:35
#HITB2024BKK D2 - Exploiting the In-Vehicle Browser: A Novel Attack Vector in Autonomous Vehicles
29:43
How to treat Acne💉
00:31
ISSEI / いっせい
Рет қаралды 108 МЛН
Mom Hack for Cooking Solo with a Little One! 🍳👶
00:15
5-Minute Crafts HOUSE
Рет қаралды 23 МЛН
We Attempted The Impossible 😱
00:54
Topper Guild
Рет қаралды 56 МЛН
小丑女COCO的审判。#天使 #小丑 #超人不会飞
00:53
超人不会飞
Рет қаралды 16 МЛН
#HITB2024BKK D1 Revealing Microphone Nonlinear Behavior and Building an Ultrasonic Jammer
49:35
Hack In The Box Security Conference
Рет қаралды 184
#HITB2024BKK #COMMSEC D2: Exploring Vulnerabilities in Flutter Mobile Apps
22:07
Hack In The Box Security Conference
Рет қаралды 317
#HITB2024BKK #COMMSEC D2: Breaking Fake Voice Detection with Speaker-Irrelative Features
44:08
Hack In The Box Security Conference
Рет қаралды 72
#HITB2024BKK #COMMSEC D1: Flash Loans: The Blessing or Curse of DeFi
41:12
Hack In The Box Security Conference
Рет қаралды 93
#HITB2024BKK #COMMSEC D1: My First and Last Shellcode Loader
1:10:43
Hack In The Box Security Conference
Рет қаралды 541
#HITB2024BKK #COMMSEC D1: How a Combination of Bugs in KakaoTalk Compromises User Privacy
36:42
Hack In The Box Security Conference
Рет қаралды 245
How to Travel Anywhere on Earth in 45 Minutes
9:38
StarTalk
Рет қаралды 9 М.
#HITB2024BKK #COMMSEC D2: Detecting Botnets via DNS Traffic Analysis Using Machine Learning
34:15
🐙 Lunch & Learn: AI Fundamentals for 2025
1:20:35
Tina Huang
Рет қаралды 5 М.
#HITB2024BKK #COMMSEC D2: BadUSB Attacks on MacOS: Beyond Using the Terminal and Shell Commands
21:03
How to treat Acne💉
00:31
ISSEI / いっせい
Рет қаралды 108 МЛН