In this article, I want to provide a concise sum-up of the (to me) most
interesting talks of this year’s DFRWS EU
(http://www.dfrws.org/2016eu/).
Eoghan Casey, one of most famous pioneers in digital forensics, and
David-Olivier Jaquet-Chiffelle, professor in police science at University of
Lausanne, gave a keynote that emphasized the need for theoretical fundamental
basis research in the field of digital forensics, which I fully agreed on, as
this was exactly what I addressed in some of my former research.
Attila Marosi works as a Senior Threat Research at Sophos Labs in Hungary. His
talk focused on vulnerable IoT devices that are exposed to the internet. His
approach was to look for vulnerable devices with low cost tools and publicly
available data.
He started his talk with the spoiler that he is not going to reveal any new
attacks nor new techniques. But newer data are more adequate and we can see the
current state of vulnerable devices connected to the internet. This means his
approach was to test the state of IoT devices like Routers, NAS and so on with
publicly available data.
PowerView does not use the built in AD cmdlets to be independent from the Remote
Server Administration Tools (RSAT)-AD PowerShell Module which is only compatible
with PowerShell 3.0+ and by default only installed on servers that have Active
Directory services roles. PowerView, however, is compatible with PowerShell 2.0
and has no outer dependencies. Furthermore, it does not require any installation
process.
The first Keynote directly after the Opening by Enno Rey was held by Ben
Zevenbergen. At the beginning he pointed out that he is not a very technical guy
rather he specialized in Information Law and a policy advisor to the European
Parliament. Before he started to dive into his Keynote he talked about some rant
story’s which happened to him while trying to make his point clear on previous
conferences and that he came in peace to Troopers ;).
At the Troopers 16 Casey Smith has given a talk about the gap in Application
Whitelisting.
Application Whitelisting is a technique that should prevent malware and
unauthorized applications from running. Broadly speaking this is implemented by
deciding if an application is trusted or not before executing it. Casey’s talk
gave an understanding where this whitelisiting fails down.
In his introduction about the architecture he reminded us: There is no perfect
defense. It is important to understand how the defenses work and where they
fail. In the difference to exploits, which can be patched, there is no
possibility to patch architecture flaws.
In their talk
“Reverse Engineering a Digital Two Way Radio”
Travis Goodspeed and Christiane Ruetten presented the challenges they faced and
overcame while reverse engineering “Tytera MD380”, a handheld transceiver for
the Digital Mobile Radio (DMR) protocol.
“Tytera MD380” is based around two chips: STM32F405 CPU with an ARM Cortex M4F
core and Readout Device Protection and a HRC5000 baseband processor which
implements the actual digital radio. While STM32F405 is fully documented, there
is no documentation for HRC5000 publicly available but with the help of the
Chinese community they were able to obtain the Chinese documentation.
At the TROOPERS’15 Jacob l. Torrey held a track about LangSec-Aware Software
Development Lifecycle. He talked about programming conventions and what tools
can be used for enforcing the compliance. There is a lack of metrics to
understand what make software more secure or less secure. His main goals was to
show that LangSec has far-reaching impacts into software security and to give
the audience a framework to transform the theory into practice. A SLDC should
help to find bugs sooner in the development process and reduce defect rate in
production thereby. A lower defect rate in production does not only improve
security it also reduces costs.
Christopher talked already about our WiFi Network during the
IPv6 Security Summit
and mentioned our monitoring system (we like to call “netmon”). As there were
quite some people interested in the detailed setup and configuration, we would
like to share the details with you. This year we used a widely known frontend
called Grafana and as backend components InfluxDB and collectd. During Troopers
the monitoring system was public reachable over IPv6 and provided statistics
about Uplink Bandwidth, IP Protocol Distribution, Clients and Wireless Bands.
We just presented our Paper “Generic RAID Reassembly using Block-Level
Entropy” at the DFRWS EU 2016 digital forensics conference
(http://www.dfrws.org/). The article is about a new
approach that we developed for forensic RAID recovery. Our technique calculates
block-wise entropy all over the disks and uses generic heuristics on those to
detect all the relevant RAID parameters such as stripe size, stripe map, disk
order, and RAID type, that are needed to reassemble the RAID and make the data
accessible again for forensic investigations (or just for data recovery).
Kevin Fu is an Associate Professor at the University of Michigan where he
directs the Archimedes Center for Medical Device Security and cofounded Virta
Labs. At Troopers 16 he held a talk in the field of his research:
medical device security.
He started his talk with a brief introduction how he got started with medical
device security and how it has changed since he started. Round about ten years
ago he started dumpster diving for medical devices to investigate how they are
protected and maintained. In 2006 he held his first talk about medical device
security at the FDA. In 2008 he presented a wireless replay attack against a
pacemaker. In 2013 concerns about medical device security became more and more
mainstream when the television series homeland featured an episode where the
pacemaker of the American vice president was attacked resulting in his death.
Now, instead of dumpster diving for medical devices, he works together with
clinicians and has a lab for testing devices. The communication with clinicians
is very important for his work, so he visits hospitals with his student so that
they can learn how the process works on the inside.