Adrian Taylor Director, Mobile Bromium vSentry Adrian Taylor Director, Mobile 1
Paid 3644-2276-1234-5678
Zero-day price list Zero-day Adobe Reader $5,000-$30,000 Flash, Java $40,000-$100,000 Word $50,000-$100,000 Internet Explorer $80,000-$200,000 iOS $100,000-$250,000 Source: http://www.forbes.com/sites/andygreenberg/2012/03/23/shopping-for-zero-days-an-price-list-for-hackers-secret-software-exploits/
Demo
Micro-virtualization: Hardware-isolation for untrusted tasks Hardware-isolates each untrusted Windows task Lightweight, fast, hidden, with an unchanged native UX Microvisor Based on Xen with a tiny, secure code base Fully integrated into the desktop user experience Uses I/O Virtualization VT-d, TXT & TPM if available Hardware Virtualization (VT-x)
Demo
Hardware Kernel OS Libs / Utils Applications
Mutually isolates untrustworthy tasks from the Desktop, & each other CPU Untrusted Tasks
http://www.facebook.com
Micro-VMs have “need to know” access to files, networks, and the user’s desktop
Micro-VMs execute “Copy on Write”
Malware is automatically discarded
Live attack visualization and analysis : LAVA
APIs for Live Attack Analysis 2. One task per micro-VM 3. Full attack execution 1. Micro-VM Introspection
DEMO
Desktop, Laptop, Tablet and Smartphone 2012 2013 Future
Thank you