ASI36 — Analyse de vulnérabilité (2020)
Software attacks are a common part of today's headlines. This course aims at demystifying them by giving the fundamentals to understand these attacks, what they consist in and how to mitigate them. We will mostly focus on software vulnerabilities.
We will cover the following topics:
- semantics and modelization of low-level languages
- classical attack and exploitation
- control-flow integrity techniques
- MATE attacks and reverse engineering
- code obfuscation
Note: These lectures will require a fair amount of hands-on experiments on the computer to make the concepts more practical.
Lectures
| # | Date | Title |
|---|---|---|
| 1 | 2020-01-16 | Introduction |
| 2 | 2020-01-23 | Basic attacks & exploitation |
| 3 | 2020-02-03 | Control-flow integrity |
| 4 | 2020-02-06 | MATE, attack & defense |
| 5 | 2020-02-13 | Fuzzing |
| 6 | 2020-02-27 | Semantic attacks (program analysis) |
| 7 | 2020-03-05 | Exam |
Introduction (2020-01-16)
Basic attacks & exploitation (2020-01-23)
Buffer overflows, heap overflows, format-string exploitation. Hands-on.
Materials :: Slides · Exercises · Tarball
References
- How to write Buffer Overflows
- Smashing The Stack For Fun And Profit
- Microcorruption
- 80x86 CodeTable
- X86 opcode/instruction reference
- Intel full ISA reference
- w00w00 on Heap Overflows
- Hacking: The Art of Exploitation (Ch. 0x200 & 0x300)
- Low-level Software Security by Example
- Reverse Engineering for Beginners
- Reverse Engineering Course (in progress)
Control-flow integrity (2020-02-03)
Stack canaries, DEP, ASLR; limitations + advanced CFI. Hands-on.
Materials :: Slides · Exercises · Tarball
References
- Exploiting OpenBSD
- Stack Smashing as of Today
- Bypassing PaX ASLR Protection
- The Frame Pointer Overwrite
- Bypassing StackGuard and StackShield
- Practical CFI & Randomization for Binary Executables
- Enforcing Forward-Edge CFI in GCC & LLVM
- The Geometry of Innocent Flesh on the Bone
- Framing Signals — A Return to Portable Shellcode
- ASLR Smack & Laugh Reference
- Bad Binder: Android In-The-Wild Exploit
- Preventing zero-day exploits with guard lines
- Smashing the Stack in 2011
MATE, attack & defense (2020-02-06)
Man-At-The-End scenario: attackers on your computer, read/write code, patch on the fly. State of known attacks and defenses; overview of this research area.
Materials :: Slides
Fuzzing (2020-02-13)
Semantic attacks (program analysis) (2020-02-27)
TBA.
Exam (2020-03-05)
Two parts:
- Research article presentation (groups of 2, 20 min + questions)
- Mini CTF (find the secret key!) + written solution report (5 p. max)
CTFs: https://github.com/rbonichon/asi36-ctf
References
- Hacking Blind
- Transparent ROP Exploit Mitigation using Indirect Branch Tracing
- Weird Machines in ELF
- Practical CFI & Randomization for Binary Executables
- Q: Exploit Hardening Made Easy
- Towards Paving the Way for Large-Scale Windows Malware Analysis
- Function Boundary Detection in Stripped Binaries
- Syntia: Synthesizing the Semantics of Obfuscated Code
- Grey-box Concolic Testing on Binary Code
- Preventing zero-day exploits with guard lines
- Learn&Fuzz: machine learning for input fuzzing
- Nibbler: Debloating Binary Shared Libraries
Student talks
| Time | Paper | Students |
|---|---|---|
| 9:15 | Preventing zero-day exploits with guard lines | Alexandre, Emeline |
| 9:45 | Nibbler: Debloating Binary Shared Libraries | Sébastien, Baptiste |
| 10:15 | Learn&Fuzz: machine learning for input fuzzing | Mehdi, Corentin |
| 10:45 | Hacking Blind | Isabelle, Soline |
| 11:15 | Syntia: Synthesizing the Semantics of Obfuscated Code | Paul, Antoine |
| TBD | Practical CFI & Randomization for Binary Executables | Pierrick, Julien |