ASI36 — Analyse de vulnérabilité (2019)
Software attacks are a common part of today's headlines. This course aims at demystifying them by giving the fundamentals to understand these attacks, what they consist in and how to mitigate them. We will mostly focus on software vulnerabilities.
We will cover the following topics:
- semantics and modelization of low-level languages
- classical attack and exploitation
- control-flow integrity techniques
- MATE attacks and reverse engineering
- code obfuscation
Lectures
| # | Date | Title |
|---|---|---|
| 1 | 2019-01-17 | Introduction |
| 2 | 2019-01-25 | Basic attacks & exploitation |
| 3 | 2019-02-07 | MATE, attack & defense |
| 4 | 2019-02-14 | Control-flow integrity |
| 5 | 2019-02-21 | Semantic attacks (program analysis) |
Introduction (2019-01-17)
Basic attacks & exploitation (2019-01-25)
MATE, attack & defense (2019-02-07)
TBA.
Control-flow integrity (2019-02-14)
Stack canaries, DEP, ASLR; limitations + advanced CFI. Hands-on.
References
- Exploiting OpenBSD
- Stack Smashing as of Today
- Bypassing PaX ASLR Protection
- The Frame Pointer Overwrite
- Bypassing StackGuard and StackShield
- Practical CFI & Randomization for Binary Executables
- Enforcing Forward-Edge CFI in GCC & LLVM
- The Geometry of Innocent Flesh on the Bone
- Framing Signals — A Return to Portable Shellcode
- ASLR Smack & Laugh Reference
Semantic attacks (program analysis) (2019-02-21)
TBA.
Student talks
| Time | Paper | Students |
|---|---|---|
| 9:15 | Binary Code is not easy | Kaori, Willy |
| 9:45 | Compiler-Agnostic Function Detection in Binaries | Ali, Matthieu |
| 10:15 | The Geometry of Innocent Flesh on the Bone | Ignacio |
| 11:00 | Hacking Blind | François, Louis-Marie |
| 11:30 | SoK: (State of) The Art of War — Offensive Techniques in Binary Analysis | Benjamin, Cyrielle |
| 12:00 | All you Ever Wanted to Know About Dynamic Taint Analysis & Forward SE | Pierre, Léo |