Practical protection from firmware attacks in hardware supply chain | Sophia d’Antoine | Hardwear.io

  Рет қаралды 902

hardwear.io

hardwear.io

Күн бұрын

Presentation slides from the talk: bit.ly/FirmlyRootedinHardware
Talk Title:
---------------
Firmly Rooted in Hardware: Practical protection from firmware attacks in hardware supply chain
Talk Abstract:
---------------------
This talk reviews the practical risk from supply chain attacks, with a focus on those that may impact firmware integrity, either through hardware implants or other threats to firmware during manufacturing, provisioning, or deployment. Fresh styles and latest trends in hardware backdoors rarely make the news, with a few exceptions - such as the recent discovery of the CIA backdoor in Crypto AG Ciphering Machines. To remedy this, we review several newly documented types of attacks against trusted platform modules and system buses, which may compromise firmware integrity. We look at new methods being researched to detect these attacks and present a new tool as well as practical steps that engineers, product designers, and firms can use to both prevent supply chain attacks against firmware and automatically scan for these attacks.
About Speaker:
------------------------
Sophia d'Antoine has spoken at many global security conferences worldwide, including RECon Montreal, Blackhat, and CanSecWest on topics from automated exploitation, program analysis, machine learning, and hardware hacking. Her keynotes have included topics such as exploiting hardware CPU optimizations. She currently sits on the program committee for Usenix WOOT and has been on multiple peer review panels in the past (www.sophia.re). Her current work involves research and discovery of vulnerabilities in a spectrum of targets. In the past, she has worked extensively on embedded devices, surveillance equipment, SCADA systems, and unique architectures. Additionally, she is the "Hacker in Residence" at NYU and enjoys assisting in hosting CTFs and other hacking competitions. A graduate of Rensselaer Polytechnic Institute (RPI), Sophia earned her MS and BS in 2015 after completing her Master's thesis under Dr. Bülent Yener on exploiting CPU optimizations. While at RPI, Sophia helped create and teach RPISEC's Modern Binary Exploitation class as well as other training courses for topics such as malware reverse engineering.
#Hardware #Firmware #Security
----------------------------------------------------------------------------------
Website: hardwear.io
Twitter: / hardwear_io
Facebook: / hardwear.io
LinkedIn: / hardwear.io-hardwarese...
Instagram: / hardwear.io
KZbin: / @hardweario
-------------------------------------------------------------------------------------

Пікірлер
Extracting Firmware from Embedded Devices (SPI NOR Flash) ⚡
18:41
Flashback Team
Рет қаралды 557 М.
Now THIS is entertainment! 🤣
00:59
America's Got Talent
Рет қаралды 36 МЛН
Slow motion boy #shorts by Tsuriki Show
00:14
Tsuriki Show
Рет қаралды 4,7 МЛН
Playing hide and seek with my dog 🐶
00:25
Zach King
Рет қаралды 29 МЛН
Heartwarming moment as priest rescues ceremony with kindness #shorts
00:33
Fabiosa Best Lifehacks
Рет қаралды 37 МЛН
I Melted Wood With Friction
8:44
The Action Lab
Рет қаралды 672 М.
What Everyone Missed About The Linux Hack
20:24
Theo - t3․gg
Рет қаралды 282 М.
How to know if your PC is hacked? Suspicious Network Activity 101
10:19
The PC Security Channel
Рет қаралды 1,2 МЛН
Razer's new keyboard is basically cheating.
7:42
optimum
Рет қаралды 929 М.
How the Best Hackers Learn Their Craft
42:46
RSA Conference
Рет қаралды 2,5 МЛН
Generative AI in a Nutshell - how to survive and thrive in the age of AI
17:57
Battery  low 🔋 🪫
0:10
dednahype
Рет қаралды 11 МЛН
Смартфон УЛУЧШАЕТ ЗРЕНИЕ!?
0:41
ÉЖИ АКСЁНОВ
Рет қаралды 1,1 МЛН
АЙФОН 20 С ФУНКЦИЕЙ ВИДЕНИЯ ОГНЯ
0:59
КиноХост
Рет қаралды 1,1 МЛН
Как удвоить напряжение? #электроника #умножитель
1:00
Hi Dev! – Электроника
Рет қаралды 896 М.