BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Watchers being watched: Exploiting the Surveillance 
 System and\n   its supply chain\n   When: Saturday\, Aug 10\, 16:30 - 17:1
 5 PDT\n   Where: LVCC West/Floor 1/Hall 1/Track 1 - [1]Map\n\n   Descripti
 on:\n\n   With the development of artificial intelligence and image proces
 sing\n   technology\, the video industry such as CCTV is developing greatl
 y.\n   However\, CCTV video may infringe on an individual's privacy\, and\
 n   personal information may be leaked due to hacking or illegal video\n  
  collection. As such\, Surveillance System's Security issues are also\n   
 increasing\, the importance of the video surveillance industry is\n   beco
 ming more prominent.\n\n   In order to prevent hacking or illegal video co
 llection\, research on\n   camera security is being conducted. However\, t
 here is a lack of\n   awareness of NVR (Network Video Recorder)\, a device
  that actually\n   watches videos recorded by cameras\, and research on th
 is is also\n   insufficient.\n\n   We selected Hikvision and Dahua\, which
  have a high NVR market share\,\n   as target vendors\, and also selected 
 Synology's NVR-related package\,\n   Surveillance Station\, as targets. Be
 fore proceeding with vulnerability\n   analysis\, several problems occurre
 d during the file system extraction\n   process\, but U-Boot mitigation wa
 s successfully bypassed through\n   various methods. Afterwards\, various 
 types of vulnerabilities were\n   discovered through analysis\, and OEM ve
 rification was also conducted\n   to increase impact. We present exploit s
 cenarios for surveillance\n   devices through vulnerability linkage and pr
 esent supply chain\n   security issues in the Surveillance System.\n\n    
  1. [2]link\n\n     2. [3]link\n\n     3. [4]link\n\n     4. [5]link\n\n  
    5. [6]link\n\n     6. [7]link\n\n     7. [8]link\n\n     8. [9]link\n\n
      9. [10]link\n\n     10. [11]link\n\n     11. [12]link\n\n     12. [13
 ]link\n\n     13. [14]link\n\n     14. [15]link\n\n     15. [16]link\n\n  
    16. [17]link\n\n   Speakers:Chanin Kim\,Myeonghun Pak\,Myeongjin Shin\n
 \n   SpeakerBio:  Chanin Kim\, Offensive Researcher at S2W Inc\n\n   Chani
 n Kim has previously conducted offensive research and has\n   experience d
 iscovering vulnerabilities in various places\, including\n   Windows\, Rus
 t\, and OpenVPN. Chan In-Kim is also currently working as\n   an Offensive
  Researcher at S2W Inc in Korea and is conducting various\n   offensive re
 search.\n\n   SpeakerBio:  Myeonghun Pak\, Researcher at KITRI\n\n   Myeon
 ghun Pak is currently a university student and is working on\n   offensive
  research. He enjoys analyzing embedded vulnerabilities.\n\n   SpeakerBio:
   Myeongjin Shin\, Student at Chonnam National University\n\n   Myeongjin 
 Shin is currently a student at Chonnam National University\n   and belong 
 to SRC lab. He is interested in vulnerability analysis and\n   research.\n
 \n   '\n\n   1. #LVCCW_Level1_Hall1\n   2. https://media.defcon.org/DEF%20
 CON%2024/DEF%20CON%2024%20presentations/DEF%20CON%2024%20-%20Brad-Dixon-Pi
 n2Pwn-How-to-Root-An-Embedded-Linux-Box-With-A-Sewing-Needle-UPDATED.pdf\n
    3. https://www.mdpi.com/1424-8220/20/17/4806\n   4. https://www.science
 direct.com/science/article/pii/B978032390054600009X\n   5. https://arxiv.o
 rg/pdf/2202.06597\n   6. https://arxiv.org/abs/1904.08653\n   7. https://a
 rxiv.org/pdf/1812.02361\n   8. https://www.researchgate.net/publication/31
 7714199_Security_Requirements_Analysis_on_IP_Camera_via_Threat_Modeling_an
 d_Common_Criteria\n   9. https://www.researchgate.net/profile/Kyounggon-Ki
 m/publication/346494741_Derivation_of_Security_Requirements_of_Smart_TV_Ba
 sed_on_STRIDE_Threat_Modeling/links/5fc50fc24585152e9be40802/Derivation-of
 -Security-Requirements-of-Smart-TV-Based-on-STRIDE-Threat-Modeling.pdf\n  
  10. https://scholarworks.bwise.kr/cau/handle/2019.sw.cau/25949\n   11. ht
 tps://dl.acm.org/doi/10.1145/2995289.2995290\n   12. https://www.mdpi.com/
 2076-3417/11/12/5571\n   13. https://arxiv.org/abs/2302.04900\n   14. http
 s://kth.diva-portal.org/smash/get/diva2:1697718/FULLTEXT01.pdf\n   15. htt
 ps://dl.acm.org/doi/10.1145/3232829.3232832\n   16. https://www.sciencedir
 ect.com/science/article/pii/S0045790622004529\n   17. https://www.research
 gate.net/publication/334396073_Vulnerability_Analysis_of_IP_Cameras_Using_
 ARP_Poisoning\n\n\n
DTEND:20240811T001500Z
DTSTART:20240810T233000Z
LOCATION:DC - LVCC West/Floor 1/Hall 1/Track 1
SUMMARY:Watchers being watched: Exploiting the Surveillance System and its 
 supply chain
END:VEVENT
END:VCALENDAR
