My attendance throughout the entire ACM CCS 2016 week and my presentation at
TrustED was possible thanks to generous support from Enno Rey and ERNW, and I
thank them again for this opportunity!
TROOPERS16 was packed with epic talks
from around the world, an unknown evil twin brother appearing, hands-on
trainings, and a legendary year for our TROOPERS Charity efforts! If you were
there you might be wondering to yourself how could they possibly top it? Well, I
am going to let you in on a little secret: Next year is the 10th edition of
TROOPERS. One DECADE of TROOPERS, and we
are pulling out all the stops! Starting with the announcement of the first 5
talks!
The newest addition to ERNW, ERNW Insight which now hosts
TROOPERS, is launching a new concept this
year. Based on the successful TROOPERS Roundtable sessions, ERNW Insight will
host a series events every year covering current and relevant topics in the
field of IT Security. While the style of the events may vary the in-depth
knowledge sharing that you have come to know from TROOPERS will not!
The inaugural event will be
our IoT Insight Summit,
taking place on November 15, 2016 at the
Crowne Plaza Heidelberg.
This 1-day event will begin with a keynote and case study from industry
experts. Afterwards, all participants will be divided into five groups of 10
persons each to participate in our “Break Out Sessions”. Every participant will
get the opportunity to attend all 5 Break Out Sessions, where our IT Security
moderators will lead discussions on typical problems and solutions in IoT.
TROOPERS16 offered many different
speakers from around the globe. Below are three different talks from the
afternoon of Day 2’s Defense and Management Track.
===
The TROOPERS16 talk
“Attacking & Protecting Big Data Environments”
presented the research of Birk Kauer and Matthias Luft, (ERNW)
in which they showed how enterprise-grade “big data” environments, based on e.g.
HortonWorks or Cloudera, comprising of components such as HDFS, Yarn, Hue,
Flume, Hive, Spark, Sentry/Ranger could be attacked. These environments
typically process huge amounts of data. The data is either stored in a cluster
file system or streamed into clusters. The processing of these datasets are done
by jobs, and these jobs can be arbitrary code execution.
Christopher Werny leads the network security team for ERNW and since 2005 he is
involved in numerous IPv6 projects where he is responsible for planning,
implementation and troubleshooting existing projects.
The first topic he approached was “How to build a conference WLAN Network in
General”. The very first suggestion was to put it to the 5GHz channel because
there could be a lot of interferences in the 2.4 GHz channel. The basic idea
here is to disable 802.11b completely if it´s possible in your environment and
no-one is using it anyway. Further you should also consider nearby Wi-Fi signals
and on which channels they reside. His next recommendation was about setting the
inactivity timer to short intervals, this will avoid unnecessary resource
spending from the APs when they try to track down moved or shut down devices.
His last general recommendation from him was regarding a central DHCP Server.
This will enable the roaming from mobile devices without getting a new
IP-Address when bridged mode is enabled for the APs.
Ange Albertini is a reverse engineer and author of Corkami.
First and foremost he explained what a polyglot file is. A polyglot is a special
file that has more than one type in the same file. For example, Ange Albertini
demonstrated a polyglot which is a pdf, a pdf reader, a java executable and an
html file inside of one file. The second polyglot he demonstrated was a file
which had the characteristics that when you encrypted it with AES you get a PNG
image and if it´s encrypted with another key you will get a flash video and when
you encrypted it with DES you get a PDF document. He pointed out that a file
format is not just a sequence of byte it´s rather a computer dialect to
communicate between communities. He also highlighted that people don’t really
care about what is behind the file format they only what to use it and
communicate with other people.
At TROOPERS16, Dr. Cédric LÉVY-BENCHETON an expert in cyber security at ENISA,
the European Union Agency for Network and Information Security. Dr. Cédric
LÉVY-BENCHETON holds a presentation about cyber security of IoT (Internet of
Things) and smart cars he presents the current threats in IoT and Smart cars.
ENISA is an agency of the European Union. ENISA assists the Commission, the
Member States and, the business community in meeting the requirements of network
and information security.
Attila Marosi works as a Senior Threat Research at Sophos Labs in Hungary. His
talk focused on vulnerable IoT devices that are exposed to the internet. His
approach was to look for vulnerable devices with low cost tools and publicly
available data.
He started his talk with the spoiler that he is not going to reveal any new
attacks nor new techniques. But newer data are more adequate and we can see the
current state of vulnerable devices connected to the internet. This means his
approach was to test the state of IoT devices like Routers, NAS and so on with
publicly available data.
Kevin Fu is an Associate Professor at the University of Michigan where he
directs the Archimedes Center for Medical Device Security and cofounded Virta
Labs. At Troopers 16 he held a talk in the field of his research:
medical device security.
He started his talk with a brief introduction how he got started with medical
device security and how it has changed since he started. Round about ten years
ago he started dumpster diving for medical devices to investigate how they are
protected and maintained. In 2006 he held his first talk about medical device
security at the FDA. In 2008 he presented a wireless replay attack against a
pacemaker. In 2013 concerns about medical device security became more and more
mainstream when the television series homeland featured an episode where the
pacemaker of the American vice president was attacked resulting in his death.
Now, instead of dumpster diving for medical devices, he works together with
clinicians and has a lab for testing devices. The communication with clinicians
is very important for his work, so he visits hospitals with his student so that
they can learn how the process works on the inside.
The Troopers experience will never be the same without the
“IPv6 summit”. It is one of
kind of two-day special event where different security experts gather to discuss
IPv6 current challenges. It addresses different topics ranging from a broad
introduction of the IPv6 to how secure the protocol is and what the latest
standards are.
The summit is divided into 2 different tracks that run simultaneously. For the
first day on the second track, Christopher Werny and Rafael Schaefer have
carried out the first three sessions.