ASI36 — Analyse de vulnérabilité (2021)
Software attacks are a common part of today's headlines. This course aims at demystifying them by giving the fundamentals to understand these attacks, what they consist in and how to mitigate them. We will mostly focus on software vulnerabilities.
We will cover the following topics:
- semantics and modelization of low-level languages
- classical attack and exploitation
- control-flow integrity techniques
- MATE attacks and reverse engineering
- code obfuscation
Note: These lectures will require a fair amount of hands-on experiments on the computer to make the concepts more practical. They also involve supplementary reading material as part of the contents.
Lectures
| # | Date | Title |
|---|---|---|
| 1 | 2021-01-05 | Introduction |
| 2 | 2021-01-12 | Basic attacks & exploitation |
| 3 | 2021-01-19 | MATE, attack & defense |
| 4 | 2021-01-26 | Control-flow integrity |
| 5 | 2021-02-02 | Semantic attacks (program analysis) |
| 6 | 2021-02-09 | Fuzzing |
| 7 | 2021-02-16 | Exam |
Introduction (2021-01-05)
Basic attacks & exploitation (2021-01-12)
Basic low-level attack techniques: buffer overflows, heap overflows, format string exploitation. Most of the session is allotted to hands-on experimentation.
Materials :: Slides · Exercises · Tarball
References
- How to write Buffer Overflows
- Smashing The Stack For Fun And Profit
- Microcorruption
- 80x86 CodeTable
- X86 opcode/instruction reference
- Intel full ISA reference
- w00w00 on Heap Overflows
- Hacking: The Art of Exploitation (Jon Erickson) — Ch. 0x200 & 0x300
- Low-level Software Security by Example
- Reverse Engineering for Beginners
- Reverse Engineering Course (in progress)
MATE, attack & defense (2021-01-19)
Discussion of the Man-At-The-End (MATE) scenario — an attack model where attackers are very powerful since they basically are on your computer: read/write code, execute it step-by-step, patch on the fly. Current state of known attacks and defenses; overview of this research area.
Materials :: Slides
Control-flow integrity (2021-01-26)
Three main basic binary exploitation mitigation techniques:
- stack canaries
- data execution prevention
- ASLR
We will also discuss their limitations and briefly present more advanced control-flow integrity measures currently available. Hands-on experiments included.
Materials :: Slides · Exercises · Tarball
References
- Exploiting OpenBSD
- Stack Smashing as of Today
- Bypassing PaX ASLR Protection
- The Frame Pointer Overwrite
- Bypassing StackGuard and StackShield
- Practical Control-Flow Integrity & Randomization for Binary Executables
- Enforcing Forward-Edge Control-Flow Integrity in GCC & LLVM
- The Geometry of Innocent Flesh on the Bone
- Framing Signals — A Return to Portable Shellcode
- ASLR Smack & Laugh Reference
- Bad Binder: Android In-The-Wild Exploit
- Preventing zero-day exploits of memory vulnerabilities with guard lines
- Smashing the Stack in 2011
Semantic attacks (program analysis) (2021-02-02)
TBA.
Fuzzing (2021-02-09)
Overview of the current state of software fuzzing. Fuzzers have gained tremendous traction recently as automatic tools to find bugs. We will present the basics, an overview of recent results, and devote a good amount of time to hands-on experiments with the AFL fuzzer.
Materials :: Slides · Exercises · Tarball
References
- Driller: Augmenting Fuzzing Through Selective Symbolic Execution
- Angora: Efficient Fuzzing by Principled Search
- VUzzer: Application-aware Evolutionary Fuzzing
- AFL homepage
- Directed Greybox Fuzzing
- FairFuzz: A Targeted Mutation Strategy for Increasing Greybox Fuzz Testing Coverage
- A list of recent results on fuzzing
- The Fuzzing Book
Exam (2021-02-16)
The final exam will contain 2 parts:
- The presentation of a research article (groups of 2, 20 minutes + questions) — rank the articles from the list in decreasing order and send a message ranking them to the professors.
- A mini CTF problem (find the secret key!) and its written solution report (10 p. max).
CTFs available at https://github.com/rbonichon/asi36-ctf/tree/ctf-2020-2021
Deadline for CTF reports: April 2, 2021.
References
- Not All Coverage Measurements Are Equal: Fuzzing by Coverage Accounting for Input
- Transparent ROP Exploit Mitigation using Indirect Branch Tracing
- Weird Machines in ELF
- Q: Exploit Hardening Made Easy
- Towards Paving the Way for Large-Scale Windows Malware Analysis: Generic Binary Unpacking
- Function Boundary Detection in Stripped Binaries
- Grey-box Concolic Testing on Binary Code
- Symbolic execution with SymCC: Don't interpret, compile!
- ContractFuzzer: Fuzzing Smart Contracts for Vulnerability Detection
Student talks
| Time | Paper | Students |
|---|---|---|
| 9:00 | Weird Machines in ELF | Loïc, Jean-Baptiste |
| 9:30 | Transparent ROP Exploit Mitigation using Indirect Branch Tracing | Alizée, Sabry |
| 10:00 | ContractFuzzer: Fuzzing Smart Contracts for Vulnerability Detection | Tom |
| 10:30 | Grey-box Concolic Testing on Binary Code | Laetitia, Laetitia |
| 11:00 | Function Boundary Detection in Stripped Binaries | Quentin, Pierre-Élisée |
| 11:30 | Towards Paving the Way for Large-Scale Windows Malware Analysis (Generic Binary Unpacking) | Charbel, Mahmoud |