TL;DR: Marie Moe talked about security issues of medical devices, especially
implantable devices like pacemakers, but not in overwhelming technological
depth. She wanted to point out the necessity of intensified security research in
the field of medical devices as vendors and medical personnel seem to be lacking
necessary awareness of security of devices, interfaces, services, and even data
privacy.”Get involved, join the cavalry” was
her core message.
Lub-Dub-Lub-Dub-Lub-Dub
Marie started her talk with the sound of a repeating heartbeat. First she
introduced how she came up with the topic of her talk: Marie relies on a
pacemaker herself andsince she got it implanted she was curious how secure this
little device might be. A minimum education of the auditorium followed including
an explanation how a human heart works and what a pacemaker does.
A
talk
about DirectAccess (an IPv6-only VPN solution) was given by our colleague Ali
Hardudi during IPv6 summit. Ali has recently finished his master thesis on this
topic.
The DirectAccess VPN technology was introduced by Microsoft starting from
Windows server 2008. It allows users remotely, seamlessly and securely connect
to their internal network resources without a need to provide user credentials,
which is done using different technologies such as Windows domain group
policies.
Jasper Bongertz is a Senior Technical Consultant at Airbus Defence and Space
CyberSecurity. He is focusing on IT security, Incident Response and Network
Forensics.
During the IPv6 summit on Troopers16 he had given a
talk
on anonymization IPv6 in PCAPs and presented his new tool.
Sometimes you need to share your packet capture files (PCAPs), but distributing
them involves a risk of exposing the confidential information. To avoid this,
you must sanitize your PCAPs. The goal of sanitization is to remove the critical
details but keep enough information for the PCAP to still be useful. The
original-to-sanitized ratio is based on your goals.
The first talk after the keynote on day 2 of TROOPERS was from Christopher
Truncer about passive intelligence gathering and the analytics of that.
Christopher Truncer (@ChrisTruncer) is a red teamer with Mandiant. He is a
co-founder and current developer of the Veil-Framework, a project aimed to
bridge the gap between advanced red team and penetration testing toolsets.
His talk is mainly about defending a network from different threats by
collecting and analyzing metadata from different sources.
At the second day of the TROOPERS16 conference an interesting talk about
Advanced Persistent Threats took place from Marion Marschalek and Raphaël Vinot.
Marion Marschalek is a Security Researcher, focusing on the analysis of emerging
threats and exploring novel methods of threat detection. Marion started her
career within the anti-virus industry and also worked on advanced threat
protection systems where she built a thorough understanding of how threats and
protection systems work and how both occasionally fail.
Right now, I’m in Buenos Aires for IETF95 where, amongst others, an
Internet-Draft authored by
Eric Vyncke,
Antonios Atlasis and myself will be presented
(and hopefully discussed) in two working groups. In the following I want to
quickly lay out why we think this is an important contribution.
As some of you may remember about two years ago we started an internal research
project on the IPv6 “helper procotol” Multicast Listener Discovery (MLD) and
its security properties. One outcome of this research project was
Jayson Salazar‘s excellent thesis on the topic
(the full document
can be found here),
another outcome were the related talks we gave at DeepSec 2014 and at
Troopers15.
Fernando Gont, who is specializing in the field of communications protocols
security, gave a
talk
during this year’s Troopers IPv6 summit. He spoke about network reconnaissance
techniques in IPv6 area and presented a brand new set of tools for this purpose.
Comparing with methods for IPv4, reconnaissance techniques for IPv6 should be
different. It offers much larger address space, so such attacks as brute force
address scanning are not feasible anymore, because it would take too much time
to send one packet to each and every possible address. Fernando has also noted
that in general network reconnaissance support in security tools has
traditionally been poor. Together these facts prompt that it’s time for
something new, and recently a new
IETF RFC 7707 was published.
Right after the Opening Keynote of TROOPERS16, an informative and interesting
talk took place at the SAP Security track. This talk was given by three
speakers; Damian Poddebniak who is currently a master student at the University
of Applied Sciences of Münster, Sebastian Schinzel who works as an IT security
Professor at the University of Applied Sciences of Münster and he is also the
founder of CycleSEC GmbH and finally the sixth-time speaker at Troopers “Andreas
Wiegenstein” who is the CTO of Virtual Forge GmbH and a professional SAP
security consultant since 2003.
Yet another interesting 180-minute workshop in IPv6 Security Summit of
TROOPERS16, which aimed to introduce the IPv6 troubleshooting and monitoring
tools, which are essentially needed by users in order to know how to deal with
IPv6 in any IPv6-enabled network.
Before we dive into this post, let me introduce you in few words “Gabriel
Müller” the speaker and the instructor of this workshop. Gabriel works as a
senior consultant at AWK Group by mainly assisting clients in the public and
private sectors as a project manager and an expert in the network area.
Christopher Werny leads the network security team for ERNW and since 2005 he is
involved in numerous IPv6 projects where he is responsible for planning,
implementation and troubleshooting existing projects.
The first topic he approached was “How to build a conference WLAN Network in
General”. The very first suggestion was to put it to the 5GHz channel because
there could be a lot of interferences in the 2.4 GHz channel. The basic idea
here is to disable 802.11b completely if it´s possible in your environment and
no-one is using it anyway. Further you should also consider nearby Wi-Fi signals
and on which channels they reside. His next recommendation was about setting the
inactivity timer to short intervals, this will avoid unnecessary resource
spending from the APs when they try to track down moved or shut down devices.
His last general recommendation from him was regarding a central DHCP Server.
This will enable the roaming from mobile devices without getting a new
IP-Address when bridged mode is enabled for the APs.