ASI36 — Analyse de vulnérabilité (2020)

Software attacks are a common part of today's headlines. This course aims at demystifying them by giving the fundamentals to understand these attacks, what they consist in and how to mitigate them. We will mostly focus on software vulnerabilities.

We will cover the following topics:

Note: These lectures will require a fair amount of hands-on experiments on the computer to make the concepts more practical.

Lectures

# Date Title
1 2020-01-16 Introduction
2 2020-01-23 Basic attacks & exploitation
3 2020-02-03 Control-flow integrity
4 2020-02-06 MATE, attack & defense
5 2020-02-13 Fuzzing
6 2020-02-27 Semantic attacks (program analysis)
7 2020-03-05 Exam

Introduction (2020-01-16)

Overview of the course, security in general and low-level vulnerability analysis. Reminders regarding compilation and code analysis.

Materials :: Slides-I · Slides-II

References

MATE, attack & defense (2020-02-06)

Man-At-The-End scenario: attackers on your computer, read/write code, patch on the fly. State of known attacks and defenses; overview of this research area.

Materials :: Slides

Semantic attacks (program analysis) (2020-02-27)

TBA.

Student talks

Time Paper Students
9:15 Preventing zero-day exploits with guard lines Alexandre, Emeline
9:45 Nibbler: Debloating Binary Shared Libraries Sébastien, Baptiste
10:15 Learn&Fuzz: machine learning for input fuzzing Mehdi, Corentin
10:45 Hacking Blind Isabelle, Soline
11:15 Syntia: Synthesizing the Semantics of Obfuscated Code Paul, Antoine
TBD Practical CFI & Randomization for Binary Executables Pierrick, Julien