DEF CON 32 - Breaking Secure Web Gateways  for Fun and Profit -Vivek Ramachandran, Jeswin Mathai

DEF CON 32 - Breaking Secure Web Gateways for Fun and Profit -Vivek Ramachandran, Jeswin Mathai

Source: YouTube · DEFCONConference · published Nov 17, 2024 · 47:11

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Secure Web Gateways (SWGs) have fundamental architectural vulnerabilities that allow attackers to bypass malware detection 3:40. These vulnerabilities break vendor SLAs that guarantee 100% malware prevention through their systems 4:55.

Key Takeaways:
• SWGs operate at the network level without browser context, making them blind to client-side attacks 10:00
• Unmonitored channels like WebRTC, WebSockets, and gRPC completely bypass SWG detection 16:55
• "Last Mile reassembly attacks" break files into chunks that are reassembled by the browser, invisible to SWGs 27:34
• All major SWG vendors are vulnerable to these architectural flaws affecting the $80B SASE market 3:40

These bypass techniques demonstrate that effective web security requires browser-level context rather than just network analysis 44:04.

Sources:

  • 2:01 Browser as primary enterprise computer
  • 4:55 Vendor SLAs promising 100% malware prevention
  • 10:00 Browser complexity vs operating systems
  • 16:55 Unmonitored channels bypassing detection
  • 27:34 Last Mile reassembly attack explanation
  • 44:04 Root cause of architectural issues

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

hello everyone good evening uh this is a late evening talk so really appreciate everybody showing up I I'm guessing some of the parties have already started so hopefully this one will be worth it so I'm VI ramachandran and I'll be talking about breaking secure web gateways for Fun and Profit quick introduction uh did my very first Defcon talk way back in 2007 17 years back uh been working in cyber security for the last 20 25 years found multiple attacks uh I was uh the creator of the cafe latte attack and and a couple of others then founded pentester Academy and now I run a browser security company called squarex now this has been a very big team effort some of the great folks are here I'll just allow them to uh introduce themselves hello everyone uh I'm sh happy to be here I work as the p…