報告簡介:
The cloud-centered IoT infrastructure has emerged to help IoT manufacturers connect their devices to their users. In the infrastructure, IoT protocols determine how IoT devices communicate with users and how they are access-controlled. However, IoT protocols come with fundamental security challenges, and can hardly guide the implementation of trusted IoT systems. In this talk, I will introduce the latest security analysis on IoT protocols in the context of real-world systems, and new insights and techniques to safeguard IoT systems.
報告人簡介:
邢璐祎,印第安納大學布盧明頓分校助理教授,博士生導師。曾在安全四大會議和Black Hat上發表論文20篇,并擔任安全頂級會議ACM CCS和NDSS程序委員會(Program Committee)成員。目前的研究興趣包括對IoT、移動系統(iOS和Android),雲平台和服務的安全分析和隐私保護,研究廣泛涉及協議設計和分析,程序分析,形式化驗證,機器學習/ 自然語言處理等,是iOS和Apple系統安全科研的最早的先驅之一。他的課題組揭示了衆多實際系統中根本上的設計缺陷和漏洞,區别于因程序員疏忽而導緻的編程實現失誤/錯誤。基于對系統和設計缺陷的深入理解和分析,他的課題組也開發了衆多安全防護方案來保護實際系統和廠商,包括Apple,Google,Amazon / AWS,Microsoft,Samsung,IBM,Alibaba,PayPal, Firefox,騰訊等。