Vulnerabilities in Old Third-Party Software Components- Importance of Having SBoM for IoT/OT Devices

  Рет қаралды 1,622

Black Hat

Black Hat

2 ай бұрын

Full Title: Old Code Dies Hard: Finding New Vulnerabilities in Old Third-Party Software Components and the Importance of Having SBoM for IoT/OT Devices
Device manufacturers often rely on "security by obscurity" for their own code - e.g., by encrypting firmware files - and on the "principle of many eyes" when choosing to integrate open source components - i.e., if there are no public CVEs, a component is considered safe.
This talk shows that these principles can fail the manufacturers, but serve the attackers well. Our running example is the software components of a wireless gateway device that is used to bring networking to industrial control systems, remote healthcare locations, and other environments. We discuss our journey of finding over 20 vulnerabilities within these components, both internal and open source...
By: Stanislav Dashevskyi , Francesco La Spina
Full Abstract and Presentation Materials:
www.blackhat.com/eu-23/briefi...

Пікірлер
Something Rotten in the State of Data Centers
40:27
Black Hat
Рет қаралды 8 М.
ELE QUEBROU A TAÇA DE FUTEBOL
00:45
Matheus Kriwat
Рет қаралды 27 МЛН
Super sport🤯
00:15
Lexa_Merin
Рет қаралды 20 МЛН
КАК СПРЯТАТЬ КОНФЕТЫ
00:59
123 GO! Shorts Russian
Рет қаралды 3,1 МЛН
Home Lab 14: ARP & DNS Spoofing with Bettercap
28:23
Dr. K
Рет қаралды 23 М.
Solving the secrets of gravity - with Claudia de Rham
1:01:17
The Royal Institution
Рет қаралды 22 М.
Cross-Origin Resource Sharing (CORS) | Complete Guide
52:17
Rana Khalil
Рет қаралды 63 М.
Keynote: Industrialising Cyber Defence in an Asymmetric World
41:02