首页> 外文会议>International Conference on Pervasive Computing and Communications Workshops and other Affiliated Events >Keynote: Uncovering Vulnerabilities in Bluetooth Devices with Automated Binary Analysis
【24h】

Keynote: Uncovering Vulnerabilities in Bluetooth Devices with Automated Binary Analysis

机译:主题演讲:通过自动二进制分析揭示蓝牙设备中的漏洞

获取原文

摘要

Being a near range wireless communication technology, Bluetooth, particularly its Low Energy version, is ubiquitous in the Internet-of-Things (IoT) today because of its extremely lower energy consumption. For instance, it has been widely used in many of our daily applications such as healthcare, fitness, wearables, retail, smart-home, and most recently automated digital contact tracing (when fighting for the COVID-19 pandemic). However, the security and privacy implication of these Bluetooth devices is not well understood. In this talk, Dr. Lin will present how to use binary analysis and wireless traffic inspection, to identify the security vulnerabilities in both Bluetooth protocols and implementations in real world devices. In particular, he will first talk about BLEScope, a tool developed from his research group to automatically fingerprint vulnerable Bluetooth devices from Google Play and then locate them in reality with a long range Bluetooth sniffer. Then, he will talk about FirmXRay, another tool developed from his group to automatically analyze the bare-metal firmware of Bluetooth devices to identify the linklayer vulnerabilities such as insecure pairing and unauthorized read/write. Finally, he will conclude his talk by discussing future directions in Bluetooth security.
机译:作为近距离无线通信技术,蓝牙,特别是其低能量版本,在今天的互联网上普遍存在,因为它的能耗极低。例如,它已广泛用于我们的许多日常应用,例如医疗保健,健身,可穿戴性,零售,智能家庭以及最近自动化的数字接触追踪(为Covid-19大流行时)。但是,这些蓝牙设备的安全性和隐私含义并不充分了解。在这次谈话中,Lin博士将介绍如何使用二进制分析和无线流量检查,以识别真实世界设备中蓝牙协议和实现中的安全漏洞。特别是,他将首先谈谈Blescope,该工具从他的研究组开发,以自动来自Google Play的指纹脆弱的蓝牙设备,然后使用长距离蓝牙嗅探器定位它们。然后,他将讨论FirbxRay,从他的小组开发的另一个工具自动分析蓝牙设备的裸机固件,以识别LinkLayer漏洞,例如不安全的配对和未经授权的读/写。最后,他将通过在蓝牙安全方面讨论未来的指示来结束他的谈话。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号