Skip to main content

Fuzzing and Attacking Deeply Embedded Systems

February 1st, 2nd & 3rd
Intermediate

Fuzzing and Attacking Deeply Embedded Systems

Description

Deeply embedded systems play a crucial role in the ever-growing Internet of Things and typically offer a lucrative attack surface with over-the-air interfaces, hardcoded secrets, and missing security protections. During the training, we will understand the inner workings of a typical embedded system, and re-discover memory corruption vulnerabilities in a real-world, non-linux embedded operating system by combining reverse engineering, emulation and fuzzing. We will then develop proof-of-concept exploits using the discovered vulnerabilities to demonstrate how an attacker could compromise the target system. The full training is accompanied with various practical hands-on exercises and tinkering with a physical embedded training platform created for this training. After the training, we expect participants to feel comfortable to independently analyze deeply embedded systems of their choice.

Course Level

Intermediate

Course Requirements

Students should bring their own laptop with: - At least 8GB of RAM - At least 50 GB of available disk space - Access to the internet (including github) - One free and usable USB port - NATIVE Linux OS (Ubuntu 24.04 or above)

Key takeaways

- The inner workings of deeply embedded firmware - Fundamentals of firmware reverse engineering - Harnessing parsers for fuzzing - Overcoming typical fuzzing roadblocks - Triaging found crashes - Exploitation strategies for Arm Cortex-M systems

Speaker

Suggested sessions