Dear all,
This year the
TelcoSecDay
will take place on March 15th. For those of you who does not know about: the
TelcoSecDay it is a sub-event of Troopers bringing
together researchers, vendors and practitioners from the telecommunication /
mobile security field.
The event is celebrating its 5th anniversary now, that’s why I’d like to say
“thank you” to everybody taking part at this very great discussion round in the
last few years. We always had a lot of very good feedback and interesting
discussions and the increasing participation list of operators from year to year
says (almost) everything!
Admitted, we’re a bit late this time, but here we go with the agenda of this
year’s TelcoSecDay.
Given the high number of quality contributions overall there’s more talks than
in the previous years and we’ll hence start more early (and finish later 🙂 ),
so please plan accordingly.
This is the agenda, details for the invididual talks can be found in the
respective links:
We have pretty much finalized the agenda for the
Troopers TelcoSecDay and here’s another
cool talk (the others can be found
here,
here and
here):
Rob Kuiters: On her majesty’s secret service – GRX and a Spy Agency
Synopsis: In 2013 the GPRS Roaming eXchange (GRX) was in mainstream media as
part of the high profile Edward Snowden revelations. The leaked documents
indicated that the UK government’s intelligence organisation, Government
Communications Headquarters’ (GCHQ) hacked the Belgian GRX provider, Belgacom
International Carrier Services (BICS). They did this by targeting the GRX
provider’s employees with the ultimate aim of gaining access to Belgacom’s Core
GRX routers. Allegedly, GCHQ hacked the GRX routers in order to carry out
man-in-the middle “traffic sniffing” attacks against mobile users who are
roaming with smartphones or other devices capable of handling data.
in addition to those
recently announced and
these,
we’ve identified three more suitable talks for the TelcoSecDay
.
These are:
Hendrik Schmidt: Security Aspects of VoLTE
Synopsis: VoLTE is on its rise in mobile telecommunications. The service is
provided by the IP Multimedia Subsystem (IMS) which consists of a couple of
components. All those components offer new and, from an attacker’s perspective,
interesting interfaces. This talk evaluates the most interesting interfaces and
demonstrates attack vectors an attacker could abuse. This covers attacks from
customer access, Internet VoIP services and roaming exchange.
in addition to those
recently announced
we’ve identified two more suitable talks for the TelcoSecDay 😉
These are
Ravishankar Borgaonkar – TelcoSecurity Mirage: 1G to 5G
Synopsis: The evolution of the mobile networking technology from 1G to 5G is
driving the needs of our modern Digital Society. In this talk, we visit the
security pillars of these technologies and discuss if 5G can strengthen them or
not from an end-users perspective. In particular, we try to fill up security
requirements for 5G networks based on the ongoing design direction.
At Troopers15 there will be another
TelcoSecDay, like in the years before
(2014,
2013,
2012). Here’s the
first three talks (of overall 5-6):
Luca Bruno: Through the Looking-Glass, and What Eve Found There
Synopsis: Traditionally, network operators have provided some kind of public
read-only access to their current view of the BGP routing table, by the means of
a “looking glass”.
In this talk we inspect looking glass instances from a security point of view,
showing many shortcomings and flaws which could let a malicious entity take
control of critical devices connected to them. In particular, we will highlight
how easy it is for a low-skilled attacker to gain access to core routers within
multiple ISP infrastructures.
Given we’ve received a number of inquiries as for the agenda of this year’s
TelcoSecDay here’s a first preliminary agenda. To get an idea of the event’s
character you might have a look at the agenda of the
2012 edition
or the
2013 edition.
Pls note that there might be changes/additions to the following outline as we’re
currently discussing potential contributions with two European operators. Here
we go, for today:
9:00: Opening Remarks & Introduction
9:15: Ravi Borgaonkor – Evolution of SIM Card Security
10:15: Break
10:45: Adrian Dabrowski
11:45: Collin Mulliner – PatchDroid – Third Party Security Patches for Android
12:30: Lunch
13:45: Philippe Langlois
14:45: Break
15:15: Haya Shulman – The Illusion of Challenge-Response Authentication
16:00: Christian Sielaff & Daniel Hauenstein – Breaking Network Monitoring Tools
Used in Telco Space
16:30: Closing Remarks
19:00: Joint dinner (hosted by ERNW) in Heidelberg Altstadt for those interested
and/or staying for the main conference
just to let you know that all presentations from this year’s
TelcoSecDay
are published in the interim. (Harald [Welte] couldn’t participate as in the
morning of that day FRA airport was closed on short notice).
Here’s a number of updates as for upcoming
TROOPERS13.
The preliminary agenda for this year’s TelcoSecDay can be found
here.
Here‘s
the (again: preliminary) agenda of the IPv6 Security Summit.
Last, but not least we’ve included another four talks in the main conference:
======
Sergey Bratus & Travis Goodspeed: You wouldn’t share a syringe. Would you share
a USB port?
Synopsis: Previous work has shown that a USB port left unattended may be subject
to pwnage via insertion of a device that types into your command shell (e.g.
here).
Impressive attack payloads have been delivered over USB to
jailbreak PS3
and a
“smart TV“.
Not surprisingly, USB stacks started incorporating defenses such as device
registration, USB firewalls, and other protective kits. But do these protective
measures go far enough to let you safely plug in a strange thumb drive into your
laptop’s USB port?
As I mentioned the Telco Sec Day in the last post… for those who missed Flo’s
announcement: in the interim all slides of the Telco Sec Day are available
online here.
Obviously, given I initiated the event, I’m biased 😉 but to me it provided
great insight from both the talks and the networking with other guys from the
telco security field, and it did actually what it was meant for: fostering the
exchange between different players in that space, for the sake of sustainably
improving its’ overall security posture.