Главная
Study mode:
on
1
Introduction
2
Outline
3
Two types of vulnerabilities
4
Most security mechanisms of Android
5
Recent Android vulnerabilities
6
Conclusions
7
Tower Root
8
Pimpin Root
9
Pipe Root
10
Public POC
11
Root Apps
12
Google Chrome
13
Chemi
14
Ghost Push
15
Dark Spectres
16
Why
17
Long pattern chain
18
Device fragmentation
19
Google stats
20
Chinese stats
21
Capability mismatch
22
Security vendors
23
Limitations
24
Solution
25
Version Magic
26
Module Structure Check
27
Bypass Kernel Module Authentication
28
Circle Injection
29
Memory Allocation
30
From User Memory
31
Branch
32
No explicit operation
33
Optimization
34
Limitations of current solutions
35
Famous vulnerabilities
36
Most popular devices
37
Demos
38
Next steps
39
Call out
40
Ecosystem
41
Ecosystem Alignment
42
Questions
Description:
Explore an adaptive Android kernel live patching framework in this 54-minute conference talk from Hack In The Box Security Conference. Dive into the world of Android kernel vulnerabilities and their exploitation by malware and APTs. Learn about the challenges of patching these vulnerabilities and the innovative solution presented by the speakers. Discover how this framework enables hotpatching for unpatched kernels, works directly on binaries, and automatically adjusts to different device models and kernel versions. Understand the benefits for third-party developers and the potential impact on shortening patch deployment periods. Gain insights into Android security, malware analysis, and vulnerability research from experienced security researchers Tim Xia and Yulong Zhang. Follow along as they discuss various Android vulnerabilities, root attacks, and the limitations of current solutions. Examine the technical details of the proposed framework, including version magic, module structure checks, and memory allocation techniques. Conclude with a look at famous vulnerabilities, popular devices, and the future of Android security ecosystem alignment. Read more

Adaptive Android Kernel Live Patching

Hack In The Box Security Conference
Add to list
0:00 / 0:00