Firewall News

Top Menu

  • Home
  • Our Blog
  • Contact Us

Main Menu

  • Software Updates
  • Alerts & Bugs
  • Out of the Box
  • Home
  • Our Blog
  • Contact Us

Firewall News

Firewall News

  • Software Updates
    • WatchGuard logo

      TDR 6.0.0 is now integrated into WatchGuard Cloud

      04/01/2021
      0
    • Sophos Logo

      XG Firewall 17.5 MR14 Released

      30/07/2020
      0
    • Sophos Logo

      Sophos Firewall Manager SFM 17.1 MR4 Released

      27/07/2020
      0
    • Sophos Logo

      Sophos Enterprise console - Endpoint Security and Control v10.8.9 for Windows has ...

      16/07/2020
      0
    • Sophos Logo

      Sophos iView v3 MR-2 Released

      07/07/2020
      0
    • Sophos Logo

      SD-RED Firmware 3.0.002 Pattern Update

      06/07/2020
      0
    • Sophos Logo

      XG Firewall 17.5 MR13 Released

      06/07/2020
      0
    • Sophos Logo

      End-of-Life (EoL) announcement for old firmware v17 and v17.1 for XG Firewall

      03/07/2020
      0
    • WatchGuard logo

      Fireware 12.5.4 Now Available

      01/07/2020
      0
  • Alerts & Bugs
    • Sophos Logo

      Advisory: Sophos Central Maintenance scheduled for Saturday, April 2nd, 2022

      29/03/2022
      0
    • Sophos Logo

      Sophos: Important Product Lifecycle Updates

      03/03/2022
      0
    • WatchGuard logo

      WatchGuard Support Alert

      23/02/2022
      0
    • Sophos Logo

      Sophos: Important Product Lifecycle Reminder

      03/02/2022
      0
    • Sophos Logo

      Sophos: Product Lifecycle Information: Extended Support for Windows 7 and Windows Server ...

      31/01/2022
      0
    • Sophos Logo

      End-of-Life (EoL) announcement for Sophos SSL VPN Client

      29/11/2021
      0
    • WatchGuard logo

      WatchGuard: macOS Monterey 12.0.1 Does Not Support the AuthPoint Logon App

      09/11/2021
      0
    • Sophos Logo

      Sophos UTM Manager (SUM) End of Distribution

      04/11/2021
      0
    • WatchGuard logo

      WatchGuard: End of Sale Notice: AP420

      01/11/2021
      0
  • Out of the Box
    • WatchGuard’s Firebox T80 Earns 5-Star Rating in SC Labs Review

      17/11/2020
      0
    • WatchGuard Wins Big in CRN 2020 Tech Innovator Awards

      16/11/2020
      0
    • Coronavirus scams: what to look for and how to stop them

      02/04/2020
      0
    • Dell SonicWALL TZ 300

      Out the Box - Dell SonicWALL TZ 300

      05/07/2016
      0
    • Dell SonicWALL TZ SOHO

      Out the Box - Dell SonicWALL TZ SOHO

      05/07/2016
      0
    • WatchGuard Firebox T50

      WatchGuard Firebox T50

      31/03/2016
      0
    • WatchGuard Firebox M200

      WatchGuard Firebox M200

      31/03/2016
      0
NewsUncategorized
Home›News›A wrap up of HITCON 2017

A wrap up of HITCON 2017

By admin
05/09/2017
3074
0
Share:
Fortinet HITCON 2017

The 13th annual Hacks In Taiwan Conference (HITCON) took place August 25th and 26th at Academia Sinica, Taiwan’s national academy located in Taipei. Elite cyber security researchers from across the world gather at this annual conference to share their research and exchange ideas about the global threat landscape. Approximately 1000 people registered for the conference and, according to one of the HITCON crewmembers we met, one third of the attendees were undergraduates and fresh graduates. This is a good sign, given the current cyberskills gap, and indicates the enthusiasm that Taiwanese college students have to participate in the cyber security industry.

We were honored to present our research, The Dawn of AV Self-Protection, at HITCON. Our talk consisted of 2 parts; we first talked about how malware managed to bypass AV in the past, and then we shared our findings on the attack vectors of new AV self-protection features that could be leveraged by malware in order to disable the protections provided by many legacy security products. It was the emergence of the Dridex malware that drove us to this topic, which was first mentioned in a blog post published last year.

In this blog post, we will review some of the HITCON 2017 briefings that we enjoyed the most.

As security engineers who have been performing deep malware analysis for a decade, we are most interested in the latest anti-virus technology. One of our favorite talks was NeuralBlacklisting presented by Sean Park, a senior malware scientist from Trend Micro. He presented his solutions, which are based on deep learning, to counteract the polymorphic URLs generated by notorious ransomware that aim to evade detection. In his presentation, he first explained the principle of polymorphic URL patterns that makes the automatic detection job extremely challenging, and the traditional way to match these URL patterns, such as regular expression and handcrafted algorithms. He then elaborated on how and why the state of the art use of Attention in Long Short-Term Memory (LSTM) in recurrent neural networks can separate different classes of URLs with high accuracy. He then provided a demo to show how he is able to manipulate his neural network in order to detect variable length patterns of malicious URLs. His talk demonstrated that deep learning not only works well in recognizing non-linear patterns, which can closely resemble the human brain’s neural network, but also works great at solving highly sophisticated engineering tasks.

There were also multiple talks regarding Internet of Things (IoT), which was not surprising to us given the rise in IoT-based attacks. One of our favorite IoT talks was Breaking Tizen by Amihai Neiderman from Azimuth Security. It’s worth mentioning that this was one of the three topics related to software “breaking” in addition to our own. The topic itself is not really technical, as Amihai was trying to emphasize his unpleasant experience with dealing with a vendor with affected IoT devices regarding the vulnerability reports he submitted to them. One of the highlights from Amihai is that he has been able to pinpoint over 40 trivial security issues found on multiple Tizen applications simply by performing a manual code audit. Uncovered security issues can be as trivial as classic buffer-overflow due to improper usage of the C function, like strcpy and memcpy, without proper user input sanitization. Finally, Amihai concluded that there could be other potential security issues that exist in Tizen that he simply hasn’t discovered yet.

Day Two of the conference started with the keynote by Orange Tsai. He talked about his exploitation technique used to turn Server Side Request Forgery (SSRF) to remote code execution (RCE), A New Era of SSRF – Exploiting URL Parser in Trending Programming Languages! He first showed an exploit chain that could lead to RCE by chaining four vulnerabilities on the GitHub Enterprise. He then elaborated on some new powerful approaches on exploiting SSRF, with a really impressive demonstration.

The keynote was followed by Nicolas Joly’s Mitigating the unknown, when your SMB exploit fails. As a quick background, the SMB exploit that Nicolas mentioned was first leaked by ShadowBroker and then leveraged by the infamous WannaCry ransomware that caused havoc for companies and individuals around the world. Nicolas started by explaining the exploitation techniques used by the leaked exploits and the root cause of the vulnerabilities. Before we attended his talk, we were expecting him to explain the techniques he used to discover other SMB vulnerabilities, which are part of his efforts as a security engineer from Microsoft Security Response Center (MSRC) to harden the SMB protocol after the WannaCry outbreak. Nicolas didn’t disappoint us, as he spent the last 10 minutes elaborating on the root cause of the SMB vulnerabilities that he reported internally.

In all, it was a great experience for us to be able to join this renowned cyber security conference, give our presentation, and meet with other security experts in the field. If you are interested to other topics that we were not able to cover in this blog post, you can check out HITCON’s official page for the full list of briefings with corresponding presentation slides.

Previous Article

SonicWall CEO Bill Conner Wins Inaugural SC ...

Next Article

The Value of Fortinet Products in Education: ...

0
Shares
  • 0
  • +
  • 0
  • 0
  • 0
  • 0

Related articles More from author

  • NewsSonicWALL

    SonicWall Reinvents Branch Connectivity with Secure SD-Branch and Switches

    11/06/2020
    By admin
  • NewsSophos

    Sophos Mobile 9.5 and Intercept X for Mobile have launched!

    14/01/2020
    By admin
  • BarracudaNews

    Barracuda Acquires Fyde, a Zero Trust Network Access (ZTNA) Innovator

    11/11/2020
    By admin
  • FortinetNews

    New Customers Choose Fortinet’s Cloud Security for Protection of Hybrid Cloud and On-Prem Networks

    11/09/2019
    By admin
  • WatchGuard logo
    NewsWatchGuard

    WatchGuard’s New Firewalls Deliver the Power and Protection Organizations Need Today with the Agility to Evolve Tomorrow

    15/12/2020
    By admin
  • NewsTrendMicro

    Trend Micro’s Zero Day Initiative Leads Vulnerability Disclosure Landscape in Independent Research

    03/12/2019
    By admin

  • Fortinet NSS Labs
    News

    FortiGate NGFW Consistently Delivers in NSS Lab’s 2018 DCSG Group Tests

  • Alerts & BugsSonicWALL

    SonicWALL – MADMAX DGA TARGETED TROJAN VARIANT

  • Fortinet
    FortinetNews

    Tata Communications Transformation Services Limited (TCTS) and Fortinet set to enable service providers to accelerate revenue with the launch of Secure SD-WAN managed services for Microsoft Azure Virtual WAN

Timeline

  • 29/03/2022

    Advisory: Sophos Central Maintenance scheduled for Saturday, April 2nd, 2022

  • 03/03/2022

    Sophos: Important Product Lifecycle Updates

  • 01/03/2022

    Shoring up your cybersecurity posture in light of ongoing crisis

  • 23/02/2022

    WatchGuard Support Alert

  • 03/02/2022

    Sophos: Important Product Lifecycle Reminder

Sponsored Links

Latest Comments

  • Paul Sillars
    on
    21/06/2016
    I received this in an email this morning, it was the first I heard about it ...

    Dell Software Group sold to help fund looming EMC deal

  • Paul Sillars
    on
    20/06/2016
    This is going to be an interesting one to watch. Especially after today's announcement that ...

    Ingram Micro gets distribution access to Dell’s security range in Australia

Find us on Facebook

Firewall.News Logo

This site serves more as a reference point for some of the major security vendor's updates and product/press releases

It will never be a definitive list, but it helps our customers keep up to date and also allows us to express our comment and observations as well.

About us

  • PO Box 451, North Lakes, Queensland, 4509, Australia
  • [email protected]
  • Recent

  • Popular

  • Comments

  • Sophos Logo

    Advisory: Sophos Central Maintenance scheduled for Saturday, April 2nd, 2022

    By admin
    29/03/2022
  • Sophos Logo

    Sophos: Important Product Lifecycle Updates

    By admin
    03/03/2022
  • Shoring up your cybersecurity posture in light of ongoing crisis

    By admin
    01/03/2022
  • WatchGuard logo

    WatchGuard Support Alert

    By admin
    23/02/2022
  • Dell SonicWALL Supermassive

    Ingram Micro gets distribution access to Dell’s security range in Australia

    By admin
    14/06/2016
  • Francisco Partners and Elliott Management to Acquire the Dell Software Group

    Dell Software Group sold to help fund looming EMC deal

    By admin
    21/06/2016
  • WatchGuard Firebox M500 – The Cure for HTTPS Performance Headaches

    By admin
    05/03/2015
  • Sophos Logo

    Advisory: Sophos Central Maintenance scheduled for Saturday, April 2nd, 2022

    By admin
    29/03/2022
  • Paul Sillars
    on
    21/06/2016

    Dell Software Group sold to help fund looming EMC deal

    I received this in ...
  • Paul Sillars
    on
    20/06/2016

    Ingram Micro gets distribution access to Dell’s security range in Australia

    This is going to ...

Follow Me

  • Contact
  • About Us
  • Home