ASI36 — Analyse de vulnérabilité (2018)
Software attacks are a common part of today's headlines. This course aims at demystifying them by giving the fundamentals to understand these attacks, what they consist in and how to mitigate them. We will mostly focus on software vulnerabilities.
We will cover the following topics:
- semantics and modelization of low-level languages
- classical attack and exploitation
- control-flow integrity techniques
- MATE attacks and reverse engineering
- code obfuscation
Lectures
| # | Date | Title |
|---|---|---|
| 1 | 2018-01-11 | Introduction |
| 2 | 2018-01-18 | Basic attacks & exploitation |
| 3 | 2018-01-25 | Control-flow integrity |
| 4 | 2018-02-12 | MATE, attack & defense |
| 5 | 2018-02-15 | Semantic attacks (program analysis) |
| 6 | 2018-02-22 | Exam |
Introduction (2018-01-11)
Basic attacks & exploitation (2018-01-18)
Buffer overflows, heap overflows, format-string exploitation. Hands-on.
Materials :: Slides · Exercises · Tarball · Solutions (partial)
References
Control-flow integrity (2018-01-25)
Stack canaries, DEP, ASLR; limitations + advanced CFI. Hands-on.
Materials :: Slides · Exercises · Tarball · Solutions (partial)
References
MATE, attack & defense (2018-02-12)
Materials :: Slides
Semantic attacks (program analysis) (2018-02-15)
Materials :: Slides