ASI36 — Analyse de vulnérabilité (2021)

Software attacks are a common part of today's headlines. This course aims at demystifying them by giving the fundamentals to understand these attacks, what they consist in and how to mitigate them. We will mostly focus on software vulnerabilities.

We will cover the following topics:

Note: These lectures will require a fair amount of hands-on experiments on the computer to make the concepts more practical. They also involve supplementary reading material as part of the contents.

Lectures

# Date Title
1 2021-01-05 Introduction
2 2021-01-12 Basic attacks & exploitation
3 2021-01-19 MATE, attack & defense
4 2021-01-26 Control-flow integrity
5 2021-02-02 Semantic attacks (program analysis)
6 2021-02-09 Fuzzing
7 2021-02-16 Exam

Introduction (2021-01-05)

Overview of the contents, the issues surrounding security in general, the more restricted issue of analyzing vulnerabilities in low-level code, as well as reminders regarding compilation and code analysis.

Materials :: Slides-I · Slides-II

References

MATE, attack & defense (2021-01-19)

Discussion of the Man-At-The-End (MATE) scenario — an attack model where attackers are very powerful since they basically are on your computer: read/write code, execute it step-by-step, patch on the fly. Current state of known attacks and defenses; overview of this research area.

Materials :: Slides

Semantic attacks (program analysis) (2021-02-02)

TBA.

Fuzzing (2021-02-09)

Overview of the current state of software fuzzing. Fuzzers have gained tremendous traction recently as automatic tools to find bugs. We will present the basics, an overview of recent results, and devote a good amount of time to hands-on experiments with the AFL fuzzer.

Materials :: Slides · Exercises · Tarball

References

Exam (2021-02-16)

The final exam will contain 2 parts:

  • The presentation of a research article (groups of 2, 20 minutes + questions) — rank the articles from the list in decreasing order and send a message ranking them to the professors.
  • A mini CTF problem (find the secret key!) and its written solution report (10 p. max).

CTFs available at https://github.com/rbonichon/asi36-ctf/tree/ctf-2020-2021

Deadline for CTF reports: April 2, 2021.

References

Student talks

Time Paper Students
9:00 Weird Machines in ELF Loïc, Jean-Baptiste
9:30 Transparent ROP Exploit Mitigation using Indirect Branch Tracing Alizée, Sabry
10:00 ContractFuzzer: Fuzzing Smart Contracts for Vulnerability Detection Tom
10:30 Grey-box Concolic Testing on Binary Code Laetitia, Laetitia
11:00 Function Boundary Detection in Stripped Binaries Quentin, Pierre-Élisée
11:30 Towards Paving the Way for Large-Scale Windows Malware Analysis (Generic Binary Unpacking) Charbel, Mahmoud