[VB 2016] Mobile Applications: a Backdoor into Internet of Things?

Abstract

Smart watches, wearable cameras, fitness wristbands, skin exposure detectors, connected...

[Hack.Lu 2016] Android Reverse Engineering Workshop

Abstract

REQUIREMENTS:

  • 64 bit laptop
  • Internet connection
  • <...

[DefCamp 2016] Infecting Internet of Things

Abstract

Every (security) researcher knows Internet of Things...

FortiGuard Labs: Hot Bulletin

Papers and Presentations

Papers and presentations and other original research from the FortiGuard Research Center.

Click here to see all Papers and Presentations
White papers and presentation from the labs are a direct result of FortiGuard Labs' research. This material originates from analysis of emerging threats. These threats include malware, botnets and communication protocols, evasion techniques as well as vulnerability and exploitation code. Moreover, through pure security research some material is created on previously unknown attack or evasion techniques. The goal of this research is to provide advanced material to customers and the security industry before the threats are discovered and leveraged by attackers. Quite often this research material will be presented by FortiGuard Labs' researchers at security conferences around the world. These conferences include BlackHat, EICAR, AVAR, VB100, Insomni'hack, and Hashdays. Research material is also published, for example VB100 Magazine.

FortiGuard Labs

FortiGuard Labs consist of over 175 researchers and analysts world wide. Fortinet needs to cover the entire threat spectrum through UTM, thus the FortiGuard Labs team has dedicated experts in each applicable area. The researchers work with world class, in-house developed tools and technology to study, discover and protect against breaking threats.

Malware Research

Malware researchers are trying to find the latest malware kits and breaking code that exist on the internet. By reverse engineering, secrets of malware can be discovered. What is the malware trying to do? What targets does it have? Have we seen this type of creation before?

Botnet Research

Botnet research is unique to tracking movements in Botnets. A Botnet is a collection of infected computers that is controlled through an attacker (command and control). FortiGuard Labs' tracks botnets. How are they communicating? What commands are the botnets receiving, and when? What IPs are they communicating to? What information are they trying to steal? These are all questions the Botnet Research team address.

Mobile Research

Mobile malware continues to develop at record pace. Mobile malware differs from traditional PC based malware: it is written and compiled specifically for a handset and/or operating system. Thus, researchers need to be well-versed to discover and analyze instruction sets such as ARM, etc. The mobile research team will use custom mobile environments to reproduce and study mobile threats. Ultimately, this research will be used to create protection through signatures (Service Analyst team).

Zero-Day Vulnerability Research

FortiGuard Labs has a very unique security research team that focuses purely on discovering new hacking techniques. Responsible Disclosure is followed, meaning that once a new hacking technique (read: vulnerability exploitation) is discovered - it is reported confidentially through channels with PSIRT (Product Security and Incident Response) teams. The goal is to get the affected vendor's product fixed before the bad guys actually discover the same zero-day vulnerability. Since this is discovered internally and kept private between FortiGuard Labs and the affected vendor, the team will also create IPS signatures to protect customers in advance in case an attack takes place before the issue is patched / fixed by the vendor. The team has been very successful, discovering over 150 vulnerabilities to date - making the world a safer place, one step at a time.

Service Analysts

The Analyst team studies breaking code and develops mitigation signatures. A team exists for each FortiGuard service that is offered. Signature development includes antivirus, intrusion prevention, website categorization (malicious, phishing, etc), antispam, botnet, and so forth.

Technology Developers

Research is streamlined to an in-house FortiGuard development group that creates tools and technology roadmap for Fortinet products. This is crucial in the fight against cyber attack, since new offensive techniques are developed on a regular basis. Two notable groups are the AntiVirus Engine and IPS Engine development teams. New engines will be developed and released through Fortinet's update network, without requiring a firmware update.