YoVDO

Staying Secure and Unprepared - Understanding and Mitigating the Security Risks of Apple ZeroConf

Offered By: IEEE via YouTube

Tags

Network Security Courses Cybersecurity Courses Security Analysis Courses

Course Description

Overview

Explore a comprehensive analysis of security vulnerabilities in Apple's ZeroConf systems in this IEEE conference talk. Delve into the lack of security considerations in major ZeroConf frameworks on Apple platforms, including Core Bluetooth Framework, Multipeer Connectivity, and Bonjour. Examine how popular apps and system services like Tencent QQ, Apple Handoff, printer discovery, and AirDrop are susceptible to impersonation and Man-in-the-Middle attacks. Understand the serious consequences of these vulnerabilities, such as theft of SMS messages, email notifications, and documents. Learn about the fundamental security challenges in ZeroConf techniques and discover newly developed protection methods, including conflict detection and a biometric approach using voice recognition. Gain insights from security analysis and user studies involving 60 participants, demonstrating the effectiveness and user acceptance of these new protection measures against emerging threats like speech synthesis attacks.

Syllabus

Introduction
Boundary Protocol
Traditional Network
Example
Printer
Why did it happen
Airdrop
Airdrop Example
Recap
Customization
MultiPure Connectivity
Unique IDs
Zero Configuration
Summary
Measurement Study
Defense Mini
Conclusion
Questions


Taught by

IEEE Symposium on Security and Privacy

Tags

Related Courses

Computer Security
Stanford University via Coursera
Cryptography II
Stanford University via Coursera
Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera
Building an Information Risk Management Toolkit
University of Washington via Coursera
Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network