BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//LORIA - ECPv6.17.4.1//NONSGML v1.0//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-ORIGINAL-URL:https://www.loria.fr
X-WR-CALDESC:Évènements pour LORIA
REFRESH-INTERVAL;VALUE=DURATION:PT1H
X-Robots-Tag:noindex
X-PUBLISHED-TTL:PT1H
BEGIN:VTIMEZONE
TZID:Europe/Paris
BEGIN:DAYLIGHT
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
TZNAME:CEST
DTSTART:20180325T010000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
TZNAME:CET
DTSTART:20181028T010000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
TZNAME:CEST
DTSTART:20190331T010000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
TZNAME:CET
DTSTART:20191027T010000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
TZNAME:CEST
DTSTART:20200329T010000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
TZNAME:CET
DTSTART:20201025T010000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTART;TZID=Europe/Paris:20190606T133000
DTEND;TZID=Europe/Paris:20190606T143000
DTSTAMP:20190520T092629Z
CREATED:20190520T092629Z
LAST-MODIFIED:20190520T092629Z
UID:7227-1559827800-1559831400@www.loria.fr
SUMMARY:Séminaire SSL : L. Hirschi (INRIA - LORIA) "Security and Privacy of 5G AKA vs. Formal Verification"
DESCRIPTION:Mobile communication networks connect much of the world’s population. The security of every user’s calls\, SMSs\, and mobile data\, depends on the guarantees provided by the Authenticated Key Exchange protocols used. For the next-generation network (5G)\, the 3GPP group has standardized the 5G AKA protocol for this purpose.\nWe first discuss a comprehensive formal model and security analysis of 5G AKA (CCS’18). We extract precise requirements from the 3GPP standards defining 5G and we identify missing security goals. Using the security protocol verification tool Tamarin\, we conduct a full\, systematic\, security evaluation of the model with respect to the 5G security goals. Our evaluation automatically identifies the minimal security assumptions required for each security goal and we find that some critical security goals are not met\, except under additional assumptions missing from the standard. Finally\, we make explicit recommendations with provably secure fixes for the attacks and weaknesses we found.\nWe then discuss a privacy vulnerability we manually found on 5G AKA but that also affects the 3G and 4G versions of AKA (PETS’19). Despite the practical relevance of this new attack\, no prior automated analyses were able to find it. Even a posteriori\, automatically finding the privacy attack and establishing claims about potential fixes are challenging. We discuss why is so and identify some remaining scientific and technical obstacles.
URL:https://www.loria.fr/event/seminaire-ssl-l-hirschi-inria-loria-security-and-privacy-of-5g-aka-vs-formal-verification/
CATEGORIES:Séminaire
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=Europe/Paris:20190619T100000
DTEND;TZID=Europe/Paris:20190619T230000
DTSTAMP:20190617T142434Z
CREATED:20190617T142218Z
LAST-MODIFIED:20190617T142434Z
UID:7475-1560938400-1560985200@www.loria.fr
SUMMARY:Talk Hiroaki Wagatsuma (Kyushu Institute of Technology\, RIKEN) on Brain-inspired robotics
DESCRIPTION:Hiroaki Wagatsuma (Kyushu Institute of Technology\, RIKEN) will be at Loria until June 28th. He will give a talk entitled « Brain-inspired robotics: Neural Dynamics for the Body Coordination and Interactions with the Environment » on Wednesday 19 June\, 10:00am in room C005. \nAbstract\nThe first issue that he tackled was the elucidation of the mechanism how different time scales of a behavior and synapses are associated according to the rhythm and he currently extended it to the question of how a rhythm (a specific type of the limit cycle in the system) transits to the other\, dynamically and sophisticatedly\, i.e. a structural design of the trajectory or self-organization of multiple rhythms for a complex function. For example\, a synchronous motion spontaneously appears in communication between persons faced each other and their motions differentiate as time advances because they need to express the own expressions each other. A typical example is an interactive game with motions. For judging or proceeding from a stage to the next stage\, the counterpart with a different motion have to synchronize at some moment\, which is a result to compete and determine which is winner\, or looser. A possible hypothesis is that such a quasi-equilibrium state is emerged from the coupling between the behavioral coordination and neuronal dynamics including the coordination and a conflict in the internal decision-making process. He discussed on the issue in the talk.
URL:https://www.loria.fr/event/talk-hiroaki-wagatsuma-kyushu-institute-of-technology-riken/
CATEGORIES:Séminaire
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=Europe/Paris:20190620T133000
DTEND;TZID=Europe/Paris:20190620T143000
DTSTAMP:20190520T093240Z
CREATED:20190520T093240Z
LAST-MODIFIED:20190520T093240Z
UID:7230-1561037400-1561041000@www.loria.fr
SUMMARY:Séminaire SSL : M. Korczynski (LIG - Grenoble) "Internet-wide Measurements for Cybersecurity : The Case of DNS Zone Poisoning"
DESCRIPTION:Current communication networks are increasingly becoming pervasive\, complex\, and ever-evolving due to factors like enormous growth in the number of network users\, continuous appearance of network applications\, increasing amount of data transferred\, and diversity of user behavior. Therefore\, there is a great need for comprehensive Internet-wide measurements for cybersecurity. Critical facts about the Internet security\, such as “Which domain registries are abused by the cybercriminals the most?” or « Which Internet Service Providers do not deploy source IP address filtering\, facilitating massive DDoS attacks? » remain poorly quantified. \nIn this talk\, we will discuss a number of examples of measurement studies of the domain name space. In particular\, we will explore an attack against configuration files of poorly maintained name servers allowing\, for example\, domain hijacking. We refer to this type of attack as to « zone poisoning ». The attack is as simple as sending a single RFC compliant DNS dynamic update packet to a misconfigured server. In the simplest version of an attack\, a miscreant could replace an existing A or MX DNS resource record in a zone file of a server and point the domain name to an IP address under control of an attacker. We will present the global measurement study of the vulnerability. To assess the potential impact of non-secure dynamic updates\, we scanned 290 million domains worldwide and found that among the vulnerable domains are governments\, banks and health care providers\, demonstrating that the threat impacts important services. \nWe have also issued notifications for website owners\, DNS service providers\, and network operators\, suffering from non-secure DNS dynamic updates to assess which mechanisms are more effective at remediating the vulnerability. After the introduction of the General Data Protection Regulation (GDPR) some registration information is\, however\, no longer displayed in the public WHOIS data. Therefore\, we also assessed the effectiveness of alternative communication channels and issued notifications to national CERTs. \nVia our study of the zone poisoning attack and subsequent notifications to affected parties and respective intermediaries\, we aimed to improve the security of the global DNS ecosystem and test alternative methods to contact affected parties after the introduction of the GDPR regulation.
URL:https://www.loria.fr/event/seminaire-ssl-m-korczynski-lig-grenoble-internet-wide-measurements-for-cybersecurity-the-case-of-dns-zone-poisoning/
CATEGORIES:Séminaire
END:VEVENT
END:VCALENDAR