a day in the life of a vulnerability researcher · a day in the life of a vulnerability researcher...

45
A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher

Upload: others

Post on 20-Mar-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

A Day in the Life of a Vulnerability Researcher

Vincent LeeVulnerability Researcher

Page 2: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

2 Copyright 2017 Trend Micro Inc.2

Who am I?

•Vulnerability Researcher @ ZDI

•BASc Computer Engineering

•Twitter: @trendytofu

Page 3: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

What is ZDI?and what do we do?

Page 4: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

4 Copyright 2017 Trend Micro Inc.4

World’s largest vendor agnostic bug bounty program

ZERO DAY INITIATIVE

Page 5: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

5 Copyright 2017 Trend Micro Inc.

How it works

Trend Micro Customers Protected Ahead of Patch

Other Network Security Vendor’s Customers at Risk

Vulnerability submitted to the

ZDI program

Vendor Notified

Digital Vaccine®

Filter Created

Vendor Response Window

Vulnerability is Patched or Remains

Unfixed

Public Disclosure

Page 6: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

Copyright 2018 Trend Micro Inc.6

Law EnforcementIndustry

Coordinated disclosure

Consumers Business Government

Public/Private Partnerships

Alerts, blogs, news, reports, guidance

Free tools

Insights to improve Trend Micro’s core technology and products

Trend Micro Research

24X7 response, security updates, IPS rules…

Threats Vulnerabilities & Exploits

Cybercriminal Undergrounds

IoT OT / IIoTAI &Machine Learning

Future Threat Landscape

Targeted Attacks

Healthcare

Page 7: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

Copyright 2017 Trend Micro Inc.

Targeted Incentive Program

Page 8: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

Copyright 2017 Trend Micro Inc.

Pwn2Own Organizer

Page 9: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

TheExploitEconomy

Page 10: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

10 Copyright 2017 Trend Micro Inc.

Evolving Marketplace

SECURITY RESEARCHERS and HACKERS have a multitude of options available to sell their BUGS

White Market Grey Market Black Market

Page 11: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

11 Copyright 2017 Trend Micro Inc.

Marketplace

White Market

Security Vendors

Bug Bounty Programs

Gray Market

Exploit Brokers

Exploit Shops

Exploit Intelligence Marketplace

Page 12: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

12 Copyright 2017 Trend Micro Inc.

Economy in Action

ResearchersFinds Bugs

Bug BountyProgram

Report to Vendor

Sell Report$1K - $25K

Signatures

Exploit Writer

$10K - $100K

Vuln Broker

Government

$10K - $1000K

$10K - $1000K

UsedAgainst??

Bot HerderBotnet Creator Compromises PCs

Sells Exploit Rents Botnet

Spammer DDoS Extortion Credential Harvesting

Smart Criminal Make One Big Purchase

Sells Stolen Creds

Dumb Criminal Buys Beer & Chips

Re-Sells Stolen Creds

Page 13: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

13 Copyright 2017 Trend Micro Inc.

Economy in Action

ResearchersFinds Bugs

Bug BountyProgram

Report to Vendor

Sell Report$1K - $25K

Signatures

Completely Legal*

Page 14: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

14 Copyright 2017 Trend Micro Inc.

Economy in Action

ResearchersFinds Bugs

Vuln Broker

Government

$10K - $1000K

$10K - $1000K

UsedAgainst??

Mostly Legal*

Page 15: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

15 Copyright 2017 Trend Micro Inc.

Economy in Action

ResearchersFinds Bugs

Exploit Writer

$10K - $100K

Bot HerderBotnet Creator Compromises PCs

Sells Exploit Rents Botnet

Spammer DDoS Extortion Credential Harvesting

Smart Criminal Make One Big Purchase

Sells Stolen Creds

Dumb Criminal Buys Beer & Chips

Re-Sells Stolen Creds

Definitely Not Legal*

Page 16: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

16 Copyright 2017 Trend Micro Inc. 16

Responsibilities

Page 17: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

17 Copyright 2017 Trend Micro Inc.

•Review report•Acquire/install/configure product•Run PoC and debug•Reverse engineering to find out root cause, and determine exploitability •Offer•Detection guidance

Triage process in a nutshell

Page 18: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

ZDI-19-508CVE-2019-7824

Page 19: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

19 Copyright 2017 Trend Micro Inc.

ZDI-19-508

Page 20: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

20 Copyright 2017 Trend Micro Inc.

ZDI-19-508

Page 21: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

21 Copyright 2017 Trend Micro Inc.

ZDI-19-508

Page 22: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

22 Copyright 2017 Trend Micro Inc.

ZDI-19-508

Page 23: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

23 Copyright 2017 Trend Micro Inc.

ZDI-19-508

Page 24: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

24 Copyright 2017 Trend Micro Inc.

ZDI-19-508

Page 25: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

25 Copyright 2017 Trend Micro Inc.

ZDI-19-508

Page 26: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

26 Copyright 2017 Trend Micro Inc.

ZDI-19-508

Page 27: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

27 Copyright 2017 Trend Micro Inc.

ZDI-19-508

Page 28: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

28 Copyright 2017 Trend Micro Inc.

ZDI-19-508

Page 29: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

29 Copyright 2017 Trend Micro Inc.

ZDI-19-508

Page 30: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

30 Copyright 2017 Trend Micro Inc.

ZDI-19-508

Page 31: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

31 Copyright 2017 Trend Micro Inc.

ZDI-19-508

Page 32: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

Pwn2Own

Page 33: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

33 Copyright 2017 Trend Micro Inc.

Pwn2Own

Page 34: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

34 Copyright 2017 Trend Micro Inc.

Pwn2Own

•CanSecWest - Vancouver(March)

•PacSec – Tokyo (November)

Page 35: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

35 Copyright 2017 Trend Micro Inc.

Pwn2Own

Page 36: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

36 Copyright 2017 Trend Micro Inc.

Pwn2Own

Page 37: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

37 Copyright 2017 Trend Micro Inc.

Pwn2Own

Page 38: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

38 Copyright 2017 Trend Micro Inc.

Pwn2Own

Page 39: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

39 Copyright 2017 Trend Micro Inc.

Pwn2Own

Page 40: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

40 Copyright 2017 Trend Micro Inc.

Pwn2Own

Page 41: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

41 Copyright 2017 Trend Micro Inc. 41

Research

Page 42: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

42 Copyright 2017 Trend Micro Inc. 42

Research

https://www.zerodayinitiative.com/blog/

Page 43: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

43 Copyright 2017 Trend Micro Inc. 43

Find us at these conferences

Page 44: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

44 Copyright 2017 Trend Micro Inc.

Plugging In

https://www.zerodayinitiative.com

@thezdi

PGP https://www.zerodayinitiative.com/documents/zdi-pgp-key.ascFingerprint: 743F 60DB 46EA C4A0 1F7D B545 8088 FEDF 9A5F D228

Page 45: A Day in the Life of a Vulnerability Researcher · A Day in the Life of a Vulnerability Researcher Vincent Lee Vulnerability Researcher. 22 Copyright 2017 Trend Micro Inc. Who am

QuestionsThank you for your time and attention