Last week we gave a talk at the very first 31c0n in Auckland, New Zealand. The talk focused mainly on the methodology that we use to assess security products.
More specifically, this methodology consists of 7 steps
- Literature Research
- Jailbreak the Target
- Identify Components
- Understand the Architecture
- Map the Attack Surface
- Prioritize
- Analyze.
Details on these steps as well as general suggestions to viable alternatives for security products can be found here in the slides.
Continue reading