本期的國(guó)外計(jì)算機(jī)系介紹的是The University of Wisconsin at Madison
Research Areas & Projects 
其中和程序分析相關(guān)的
從下面兩個(gè)頁(yè)面能夠獲得豐富的內(nèi)容
此外可以看看這個(gè)會(huì)議
2011 International Symposium on Software Testing and Analysis
其中的session:Analysis of Systems and Binary Code
全是The University of Wisconsin at Madison
可見(jiàn)其研究還是有一定影響的
================= ================= ================= =================
一個(gè)專(zhuān)門(mén)提供征稿信息的網(wǎng)站wikicfp
安全和密碼學(xué)方面的內(nèi)容
================= ================= ================= =================
Linux Kernel 3.0正式版發(fā)布

不解釋
================= ================= ================= =================
調(diào)查稱(chēng)逾8% Android應(yīng)用泄露用戶個(gè)人資料

據(jù)國(guó)外媒體報(bào)道,安全廠商Dasient對(duì)1萬(wàn)款A(yù)ndroid應(yīng)用進(jìn)行了研究,發(fā)現(xiàn)逾8%的應(yīng)用向沒(méi)有獲得授權(quán)的計(jì)算機(jī)傳輸用戶的個(gè)人資料。類(lèi)惡意件旨在控制用戶的智能手機(jī)。例如,11款應(yīng)用會(huì)自動(dòng)向用戶通信錄中的聯(lián)系人發(fā)送短信。如果用戶需要為短信付費(fèi),用戶在不知情的情況下就可能需要支付巨額賬單。

Dasient首席技術(shù)官尼爾·達(dá)斯萬(wàn)尼(Neil Daswani)表示,在過(guò)去2年內(nèi),惡意的Android應(yīng)用增長(zhǎng)了1倍。用戶可能在訪問(wèn)網(wǎng)站時(shí)不知不覺(jué)地被安裝了惡意件。

Android Market不對(duì)提交的應(yīng)用進(jìn)行審查是惡意Android應(yīng)用泛濫的一大原因。

盡管開(kāi)發(fā)者無(wú)需等待應(yīng)用通過(guò)審批,但這樣做的代價(jià)卻要有用戶來(lái)承擔(dān)。由于沒(méi)有采取最基本的措施確保應(yīng)用不是惡意件,如果當(dāng)前的趨勢(shì)不發(fā)生改變,未來(lái)兩年內(nèi)Android Market中將充斥著大量惡意件。

除用戶的個(gè)人資料外,惡意件還經(jīng)常泄露手機(jī)的IMEI碼(國(guó)際移動(dòng)電話設(shè)備識(shí)別碼)和IMSI碼(國(guó)際移動(dòng)用戶識(shí)別碼)。這些信息被泄露后,犯罪分子可以方便地復(fù)制用戶的SIM卡,或?qū)⑿畔⑴砍鍪劢o非法組織。

================= ================= ================= =================

學(xué)術(shù)會(huì)議推薦

http://www.light-sec.org

一個(gè)研究輕量級(jí)密碼學(xué)與安全的workshop,The main goal of this workshop is to promote and initiate novel research on the security & privacy issues for applications that can be termed as lightweight security

此外,根據(jù)一個(gè)計(jì)算機(jī)學(xué)術(shù)會(huì)議排名網(wǎng)站cs.conference-ranking.net給出一些參考的好會(huì)議,其中和LoCCS緊密相關(guān)的有(為什么里面有Asiacrypt沒(méi)有Eurocrypt我不知道……)

ASIACRYPT: International Conference on the Theory and Application of Cryptology and Information Security

CCS: Conference on Computer and Communications Security

CRYPTO: International Crytology Conference

CSFW: IEEE Computer Security Foundations Workshop

ISSP: IEEE Symposium on Security and Privacy

ISSTA: International Symposium on Software Testing and Analysis

PLDI: SIGPLAN Conference on Programming Language Design and Implementation

有一些關(guān)系的

ASPLOS: International Conference on Architectural Support for Programming Languages and Operating Systems

CAV: Computer Aided Verification

ICALP: International Colloquium on Automata, Languages and Programming

ICCS: IAENG International Conference on Computer Science

ICCSE: International Conference of Computer Science and Engineering

ICFP: International Conference on Function Programming

ICNP: International Conference on Network Protocols

ICLP: International Conference on Logic Programming

ICSE: IAENG International Conference on Software Engineering

MOBICOM: ACM/IEEE International Conference on Mobile Computing and Networking

OSDI: Operating Systems Design and Implementation

PADS: Workshop on Parallel and Distributed Simulation

PODC: ACM SIGACT-SIGOPS Symposium on Principles of Distributed Computing

SIGCOMM: ACM SIGCOMM Conference

USITS: USENIX Symposium on Internet Technologies and Systems

WWW: World-Wide Web Conference

幾乎沒(méi)啥關(guān)系

AAAI: National Conference on Artificial Intelligence

ACL: Association for Computational Linguistics

ACM-EC: ACM Conference on Electronic Commerce

ATAL: Agent Theories, Architectures, and Languages

CHI: Computer Human Interaction

CPM: Combinatorial Pattern Matching

ECOOP: European Conference on Object-Oriented Programming

EDBT: International Conference on Extending Database Technology

FPGA: Symposium on Field Programmable Gate Arrays

ICCAD: International Conference on Computer Aided Design

ICCV: IEEE International Conference on Computer Vision

ICDE: International Conference on Data Engineering

ICMCS: International Conference on Multimedia Computing and Systems

ICML: International Conference on Machine Learning

KDD: Knowledge Discovery and Data Mining

SIGGRAPH: Annual Conference on Computer Graphics

SIGKDD: ACM Knowledge Discovery and Data Mining

SIGMOD: ACM SIGMOD Conference on Management of Data

VLDB: Very Large Data Bases

================= ================= ================= =================

 

據(jù)最新消息透露,著名越獄開(kāi)發(fā)者Comex已經(jīng)在他的GitHub頁(yè)面上公布了JailbreakMe 3.0的源代碼。
專(zhuān)門(mén)進(jìn)行越獄分析的Sogeti網(wǎng)站隨后在博客上發(fā)表了相關(guān)消息

“我們知道,本次代號(hào)為“Saffron”的越獄能夠通過(guò)利用PDF漏洞來(lái)安裝一個(gè)自定義的載荷系統(tǒng)。具體的說(shuō)法是,這個(gè)漏洞能夠讓iOS用戶通過(guò)在 Safari瀏覽器中打開(kāi)PDF文件對(duì)設(shè)備進(jìn)行越獄,其中最初的代碼執(zhí)行可以在Freetype Type 1字體分析器的一個(gè)漏洞當(dāng)中獲得,并通過(guò)內(nèi)核 漏洞的后續(xù)開(kāi)發(fā)來(lái)禁止代碼簽名,隨后獲得root權(quán)限從而實(shí)現(xiàn)越獄的安裝。另外,設(shè)備重新啟動(dòng)后能夠利用相同的內(nèi)核漏洞來(lái)進(jìn)行完美越獄,使用 Incomplete Codesign技術(shù)來(lái)引導(dǎo)內(nèi)核利用。”
PS:和之前的公布一樣,JailbreakMe 3.0的源代碼只是為越獄開(kāi)發(fā)者提供,對(duì)于非開(kāi)發(fā)者并無(wú)實(shí)際意義。如果有朋友想要進(jìn)一步了解這些代碼,請(qǐng)登錄http://esec-lab.sogeti.com/post/Analysis-of-the-jailbreakme-v3-font-exploit。 

 

================= ================= ================= =================
推薦一篇程序分析的文章
Detecting Algorithms using Dynamic Analysis
by Kenneth Oksanen
Helsinki Institute for Information Technology HIIT
看起來(lái)算法的自動(dòng)化分析慢慢要提上研究者的議事日程了!
================= ================= ================= =================
最后是一個(gè)Security events的list(這里所說(shuō)的Security events大部分都是比較practical的,不是我們常常提到的CCS、NDSS那種)