Главная
Study mode:
on
1
Introduction
2
Outline
3
Android Components
4
Previous Research
5
Analysis
6
Services
7
Intent Message
8
Attack Model
9
UI Target
10
Databases
11
Remote Target Attacks
12
Formal Analysis
13
Static Analysis
14
Validation
15
Results
16
Application Analysis
Description:
Explore a comprehensive analysis of Intent Message vulnerabilities in Android applications in this 17-minute Black Hat conference talk. Delve into the identification of common programming malpractices that introduce security flaws, and learn about the development of an effective static analyzer for automatic vulnerability detection. Discover how the research team demonstrates the real-world exploitability of these vulnerabilities through automatic payload generation. Gain insights into the formal approach used to reproduce dangerous behaviors in vulnerable apps, and understand the implications of insufficient sanity checks when receiving messages from unknown sources. Cover topics including Android components, attack models, UI targets, databases, remote target attacks, formal analysis, static analysis, and validation results.

Static Detection and Automatic Exploitation of Intent Message Vulnerabilities in Android

Black Hat
Add to list
0:00 / 0:00