- Webinar |
- Netherlands 2024 |
- USA 2024 |
- Netherlands 2023 |
- USA 2023 |
- Netherlands 2022 |
- USA 2022 |
- Netherlands 2021 |
- USA 2021 |
- Germany 2021 |
- Berlin 2021 |
- Netherlands 2020 |
- Virtual Con 2020 |
- Berlin 2020 |
- Netherlands 2019 |
- USA 2019 |
- Berlin 2019 |
- Netherlands 2018 |
- Berlin 2018 |
- Netherlands 2017 |
- Netherlands 2016 |
- Netherlands 2015
Johannes vom Dorp
Designation
Security Researcher at Fraunhofer FKIE
Workshop Title
Automated Unpacking, Analysis and Comparision of Arbitrary Firmware
Images: The Firmware Analysis and Compare Tool (FACT)
Workshop Abstract
We introduce "The Firmware Analysis and Compare Tool" (FACT) a plug-in-based open source solution for automated unpacking, analysis and comparison of arbitrary firmware samples. In contrast to other solutions, FACT is not limited to Linux based firmware or embedded device firmware, but supports UEFI as well as HDD firmware. To be more precise, FACT can handle arbitrary firmware as long as an appropriate unpacking plug-in is available. Thereby, unpacker, analysis capabilities and comparison features can be added with low effort, because of FACT's plug-in concept. Furthermore, it is easy to use, due to its Web-GUI and can be integrated easily by providing a REST-API. Our workshop will focus on the typical problems associated with firmware analysis and how FACT can be used to mitigate some of them.
Topics include analysis of firmware container formats and some advances in automated analysis techniques. A series of analysis results and live analysis will be shown to demonstrate the capabilities of FACT. To support the notion of easy extensibility, some code snippets will be shown to give an idea how a simple unpack plug-in can be integrated into FACT.
Bio
Johannes vom Dorp is a computer security researcher in the area of firmware security at Fraunhofer FKIE. He graduated in Computer Science at the University of Bonn in 2016. After already working there as a student he joined Fraunhofer FKIE as a research assistant after the completion of his master thesis.