Explore an adaptive Android kernel live patching framework in this 54-minute conference talk from Hack In The Box Security Conference. Dive into the world of Android kernel vulnerabilities and their exploitation by malware and APTs. Learn about the challenges of patching these vulnerabilities and the innovative solution presented by the speakers. Discover how this framework enables hotpatching for unpatched kernels, works directly on binaries, and automatically adjusts to different device models and kernel versions. Understand the benefits for third-party developers and the potential impact on shortening patch deployment periods. Gain insights into Android security, malware analysis, and vulnerability research from experienced security researchers Tim Xia and Yulong Zhang. Follow along as they discuss various Android vulnerabilities, root attacks, and the limitations of current solutions. Examine the technical details of the proposed framework, including version magic, module structure checks, and memory allocation techniques. Conclude with a look at famous vulnerabilities, popular devices, and the future of Android security ecosystem alignment.
Read more