KasperskySecurityAnalyst summitBali, Indonesia
22-25 October2024

SAS24

-1
days
-23
hours
-43
minutes
-32
seconds
-1
days
-23
hours
-43
minutes
-32
seconds
-1
days
-23
hours
-43
minutes
-32
seconds
-1
days
-23
hours
-43
minutes
-32
seconds
-1
days
-23
hours
-43
minutes
-32
seconds
-1
days
-23
hours
-43
minutes
-32
seconds
-1
days
-23
hours
-43
minutes
-32
seconds
-1
days
-23
hours
-43
minutes
-32
seconds
-1
days
-23
hours
-43
minutes
-32
seconds
-1
days
-23
hours
-43
minutes
-32
seconds
-1
days
-23
hours
-43
minutes
-32
seconds
-1
days
-23
hours
-43
minutes
-32
seconds
-1
days
-23
hours
-43
minutes
-32
seconds
-1
days
-23
hours
-43
minutes
-32
seconds

Our sponsors

av comparititves.png
security vision.png
av comparititves.png
security vision.png
av comparititves.png
security vision.png
av comparititves.png
security vision.png

Security Analyst Summit 2024

Now in its 16th iteration, Kaspersky’s renowned Security Analyst Summit (SAS) continues to attract high-caliber cybersecurity researchers, global law enforcement, CERTs and senior executives from financial services, technology, healthcare, academia and government agency backgrounds to shed light on trends and opportunities critical to the development of the cybersecurity industry.

The conference provides an exclusive atmosphere that encourages debate, information sharing and displays of cutting-edge research and new technologies, as participants explore ways to improve collaboration in the fight against cybercrime.

Let’s have some fun together!

Bali, Indonesia

Bali, Indonesia

22-25 October, 2024

#TheSAS2024 will happen on Bali, Indonesia. Join us at the Sofitel Bali Nusa Dua Beach Resort

Event

SAS CTF 2024

In addition to its conference agenda, SAS 2024 will feature the finals of the international Capture The Flag (CTF) competition for cybersecurity experts.

With a prize of $18,000, the qualification round held earlier in May 2024 attracted 846 teams from over 80 countries, and the top 8 finalists will come to Bali for the finals.

+------------------------------------------------------+
|                                                      |
|   root@sasctf:~$ cat flag.txt                        |
|   SAS{w3lc0m3_t0_S4S_2024}                           |
|                                                      |
|                   ++++++++++++++++                   |
|               +++++++++++++     ++++++               |
|             +++++++++++  ++   +++   ++++             |
|           +++++++++++++++++++++++     ++++           |
|         ++++     ++++++++++    ++++     ++++         |
|        +++     ++++ +++  ++  ++++++++     +++        |
|       +++     ++ +++  ++++++++      ++     +++       |
|       ++     +++++++++   ++++++++    +++    ++       |
|      ++     ++   ++++  ++++++++ ++  + +++    ++      |
|      ++    ++    +++++ ++++++++++ + +++++++++++      |
|      ++    ++   +   ++++    +++++  +   ++++++++      |
|      +++++++++++++++  ++++++ ++++++++++++++++++      |
|      ++    ++   +     ++    +++ ++ +   +++  +++      |
|      ++    ++    +      ++++      ++++++++  +++      |
|      ++    +++    +             +++++++++++ +++      |
|       ++    +++    ++    ++    +++++++++++++++       |
|       +++     ++     +++++++++++++++++++++++++       |
|        +++     +++       ++++++++++++++++++++        |
|         ++++     ++++    +++++++++++++++++++         |
|           ++++       +++++++++++++++++++++           |
|             ++++         ++ ++++++++++++             |
|               ++++++     ++ +++ ++++++               |
|                   ++++++++++++++++                   |
|                                                      |
+------------------------------------------------------+
    

Program committee

Gabriel Bergel
Cybersecurity Foundation 8.8
Flip for more
Gabriel Bergel
Gabriel has 22 years of experience in different Cybersecurity roles. He is the President of Cybersecurity Foundation 8.8, CEO and Co-Founder of 8.8 Computer Security Conference, Coordinator of the Industrial Cybersecurity Center (CCI), Co-Chairperson at the Latin American Advisory Council (LAAC) at (ISC)2, Director of Public Policy at Whilolab and Director at Fundación Nativos Digitales. He presented at PHDays7, Campus Party, Roadsec, Defcon26 Biohacking Villa and the (ISC)² Secure Summit LATAM.


Follow @gbergel
Flip for less
Ekaterina Burdova
Kaspersky
Flip for more
Ekaterina Burdova
Kate is working as a Deputy Global PR Director at Kaspersky. She joined the company in 2017 and was working with communications of threat research. Before Kaspersky, she implemented and managed international comms projects in state and non-governmental organisations, including on topics of international relations, climate change issues and sustainable development. Kate is a graduate of the Lomonosov Moscow State University. She is also an alumnus of the Global Shapers Community (WEF initiative).


Follow @kateodna
Flip for less
Andreas Clementi
AV-Comparatives
Flip for more
Andreas Clementi
Andreas is the founder and CEO of AV-Comparatives. He has pioneered rigorous evaluation methods for security products, making AV-Comparatives a globally trusted authority. His expertise includes developing test protocols to assess the effectiveness, performance and user impact of antivirus and IT security solutions. Andreas frequently reviews academic and technical papers for various conferences and universities and has received multiple awards for his contributions to cybersecurity.


Flip for less
Florian Roth
Nextron Systems GmbH
Flip for more
Florian Roth
Florian is an accomplished professional in the information security industry since 2003, currently serving as the Head of Research at Nextron Systems GmbH. With a strong focus on YARA, Florian has made significant contributions by creating various tools, educational materials, and publishing numerous YARA rules. He has also co-founded the widely recognized Sigma project, setting the standard for SIEM queries. Florian's expertise and dedication have made him a respected figure in the industry.


Follow @cyb3rops
Flip for less
Boris Larin
Kaspersky
Flip for more
Boris Larin
Boris is a renowned expert in the fields of threat hunting and software reverse engineering. He works as a Principal Security Researcher in GReAT at Kaspersky. He has discovered and investigated a number of high-profile APT attacks and reported two dozen zero-day exploits. While working at Kaspersky, Boris has presented his work at a large number of conferences: CanSecWest, SAS, BlueHat, TyphoonCon, CodeBlue, Chaos Communication Congress, OffensiveCon, and many others.


Follow @oct0xor
Flip for less

Speakers

Sergey Anufrienko
Research Group Manager, Kaspersky ICS CERT
Talk: 

Unisoc are DooM'ed: how to remotely hack a modern SoC                         


Flip for more
Sergey Anufrienko

Technology enthusiast with over two decades of experience in software development, hardware, and reverse engineering.     

In his talk he will examine a modern modem from Unisoc and demonstrate how the entire SoC can be compromised via just a single 0-day vulnerability in the modem.



Flip for less
Fabio Assolini
Head of Research Center, Latin America, Kaspersky GReAT
Talk: Grandoreiro: a global trojan with grandiose goals
Flip for more
Fabio Assolini
Fabio Assolini is a director of Kaspersky’s Global Research and Analysis Team in Latin America. Fabio joined Kaspersky’s Global Research & Analysis Team (GReAT), which boasts the industry’s top analysts, in July 2009 to primarily focus on one of the most dynamic countries in Latin America: Brazil. Fabio’s responsibilities include the analysis of viruses, cyberattacks, banking trojans and other types of malware that originate from Brazil and the rest of the region. He particularly focuses on the research and the detection of banking trojans. In November 2012, he was promoted to senior security researcher. Fabio has more 10 years of experience as a malware analyst and possesses a BSc in Computer Science.


Follow @assolini
Flip for less
Yuki Chen
Independent Security Researcher
Talk: Hunting Pre-auth RCE Bugs in Windows Components
Flip for more
Yuki Chen
Yuki Chen is an independent security researcher. His current research areas include vulnerability hunting/exploiting/detecting.

He has more than 15 years of experience in both offensive and defensive security and published much research in industry. Yuki have found hundreds of bugs in the past years and have made 5 yearly Top1 on the MSRC most valuable security researcher list in year 2019/2021/2022/2023/2024.

He is also the winner in multiple targets in pwn2own 2015/2016/2017 and Tianfu Cup 2018/2019. He has been rewarded 2 pwnie awards: best remote code execution and epic achievement.


Follow @guhe120
Flip for less
Leroy Chiao, Ph.D,
Former NASA astronaut and International Space Station commander
Talk: 

Security Beyond Earth: Addressing Cyber Risks in Space Exploration

Flip for more
Leroy Chiao, Ph.D,
Leroy Chiao is a former NASA astronaut and International Space Station commander. He works in business, consulting, and space education. He is a a professional international speaker, and a co-founder and the CEO of OneOrbit, a training & education company. Chiao also holds academic appointments at Rice University and the Baylor College of Medicine. He has worked in both government and commercial space programs, and has held leadership positions in commercial ventures and NASA. He was the first LSU Raborn Distinguished Chair Professor and was also on the faculty at Rice. Chiao has extensive experience as a NASA Astronaut and prior to that, as a Research Engineer. 


Flip for less
Lars Fröder
Researcher, Cellebrite Labs
Talk: iOS Hacking in 2024 - An Overview
Flip for more
Lars Fröder
Developer of Dopamine Jailbreak, TrollStore and some jailbreak tweaks.

This talk aims to provide an up-to-date high level overview over the most recent tools to archive code execution and jailbreak on iOS and their internals, including the vulnerabilities they exploit.


Follow @opa334dev
Flip for less
Peter Geissler
Independent Security Researcher
Talk: 

Galactic Dead Ends: Retrofitting Encrypted Firmware    

Flip for more
Peter Geissler

Peter “blasty” Geissler is an independent security researcher from the Netherlands. He’s well known for facilitating code execution on various platforms, writing exploits for popular software packages, competing in pwn2own and being a founding member of the Eindbazen CTF team.



Follow @bl4sty
Flip for less
Shawn Hoffman
Hacker, symbrkrs
Talk: Beyond Oberon: Exploiting PlayStation 5's EFC and EMC
Flip for more
Shawn Hoffman
Shawn has experience exploiting a variety of targets, but game consoles have always held a special interest. 
The talk will provide a high level overview of the system architecture of the Playstation 5 console, with focus on the efc/eap ("titania") and emc ("salina") chips. Exploits allowing code execution on salina and titania will be detailed, along with release of a tool which implements the exploits. The process of initial exploration/discovery will also be briefly covered. 
From a security researcher point of view, the exploits are interesting as they cover a hard-to-spot bug in a firmware state machine, and abusing hardware misconfiguration to bypass memory protection measures. The exploits/tooling allow for further research into the system.


Follow @shuffle2
Flip for less
Zhao Guangyuan
Senior researcher at NSFOCUS
Talk: The Invisible Blade in the Age of the Internet of Everything: IoT Botnets in the Service of APT
Flip for more
Zhao Guangyuan
Senior researcher at NSFOCUS, specializing in botnet and APT (Advanced Persistent Threat) detection and tracking for 8 years. Discovered multiple new APT attacks and organizations. Delivered keynote speeches at renowned conferences such as Botconf, ISC, SAS, PacSec, and KCON.



Flip for less

Agenda

Tuesday,October 22

14:00

-21:00

Registration for #TheSAS2024

Kecak Ballroom prefunction area

15:00

-00:00

Hotel check in

Sofitel Bali Nusa Dua Beach Resort

19:30

-22:00

Welcome dinner

Retreat Garden, Sofitel Bali Nusa Dua Beach Resort

F.A.Q.

What is SAS?

The Security Analyst Summit is an exclusive, invitation-only three-day conference for leading anti-malware researchers, global law enforcement, CERTs and senior executives from financial services, technology, healthcare, academia and government agency backgrounds.

The conference provides an exclusive atmosphere that encourages debate, information sharing and displays of cutting-edge research and new technologies, as participants explore ways to improve collaboration in the fight against cybercrime.

Why should I join?

At the conference, speakers share exclusive talks and insights for the first time; for instance, by joining, you will be among the first to hear about recent APT discoveries!

SAS boasts lively and laid-back ambiance in equal measure. Here, in-depth research topics intersect with countless opportunities to network and share knowledge. As we love to say: work hard, play hard! We know how to break the ice and create a close-knit community of professional relationships that last a lifetime.

Is it safe to join a conference?

Absolutely - more than 800 SAS participants since first SAS participants over 15 events can’t be wrong! As a global private cybersecurity company, Kaspersky is valued as a trusted industry partner worldwide and, over many years, it has established ongoing support and collaboration with numerous international organizations and initiatives, continuing to strengthen global security...

International visibility and collaboration around cybersecurity are core values of SAS, and we believe that not only are cyber threats not confined by borders, they are a global concern that requires a coordinated, international response.

And you can rest assured that we treat the safety and comfort of our guests as our number one priority; we are working hard - in both the physical and cyber spaces - to create a wonderful event where knowledge can be shared freely in an agenda-free environment. You can learn more about our principles in our Code of Conduct.

What is included in the attendee package?

Your package includes access to the entire SAS conference, accommodation from October 22-25 and all meals and activities within the program: Arrival day Welcome Dinner, Gala Dinner following the keynote day, our activity program and Farewell dinner.

What does the speaker’s package include?

If you are chosen to join us at SAS, we’ll cover your ticket to Bali (Economy class) and accommodation from October 21-25 (allowing one additional day for rehearsal), as well as the whole event program, all dinners and activities.

What topics will be covered at SAS?

This year, our focus is on:

  • Advanced cyberthreats, APT actors and cyberwarfare
  • Critical infrastructure and ICS/OT security
  • IoT attacks and security
  • Supply chain attacks and open-source software security
  • Ransomware incidents and how to stay protected
  • Zero-day vulnerabilities and exploits
  • Dark web trends and analytics
  • Artificial intelligence, machine learning and cybersecurity

This year we want to expand cybersecurity discussions to galaxies far, far away, so we would be particularly interested to see applications about cyber-hacks in space, attacks on space infrastructure, space probes, sensors, satellites, etc.

Are there any topics that can’t be covered at SAS?

We welcome a wide variety of presentation topics with minimal restrictions. However, please be aware that our program committee prioritizes technical research and impartial content. Consequently, we must respectfully decline any presentations perceived as politically motivated or manipulative, or those primarily aimed at marketing or product promotion. For those looking to promote a product or service, we provide a range of tailored sponsorship opportunities.

What is the format of the presentations?

There two types:

  • Classic: A 20-minute presentation (including time for questions). If you feel that your topic needs additional time to present, please leave us a note and we will discuss how this can be accommodated within the timing of the conference.
  • Pecha-kucha: A storytelling format in which a presenter shows 20 slides with 20 seconds of commentary for each. Therefore, the duration of each presentation is limited to 400 seconds max. We recommend this format if you have interesting thoughts or ideas you would like to pitch in a more engaging way. Also, this can be a great personal challenge/achievement for you as a speaker. Plus, we identify the best Pecha-Kucha speaker after all the talks in this format via audience voting for added incentive!

Why should we sponsor SAS?

This is a unique opportunity to gain visibility – both at the conference and far beyond – among subject matter experts, cyber security influencers and key decision makers in one of the most topical and fastest-growing industries!

SAS 2024 provides multiple promotional opportunities across the conference venue, as well as the opportunity to feature prominently in SAS publicity campaigns through media partners.

Will you have an online broadcast?

No, we and our guests value greatly the offline experience of the SAS - no additional prying eyes! However, we are open for knowledge sharing afterwards and provide recordings of all the presentations where our speakers have given their approval.

What is SAS CTF?

This year, we are holding the SAS CTF - an international competition for cybersecurity experts.

The competition consists of an online Jeopardy qualification stage and on-site A/D finals, taking place at the SAS conference in Bali, Indonesia October 22-25, 2024.

Our SAS CTF 2024 Finals prize pool will be $18.000. You can also contribute to CTF community by becoming a SAS CTF partner. Partnership fee (starting from $5000) will go straight to our CTF community; all SAS CTF Partner funds are pooled together to make our prize pool for SAS CTF even bigger.

Learn more details at the SAS CTF web-site.

Can I invite additional guests to join me at SAS?

If you would like to invite a peer or colleague from the industry to attend the entire conference program – please fill in an additional attendee form. In the event that we approve their application to attend, they will need to buy an additional ticket.

If you would like to bring along your “plus one” to Welcome Dinner, Gala Dinner and our activity program, there will be a possibility to buy tickets to these informal events separately, during your registration and payment process. Please be aware that the number of additional seats is limited.

I'm a journalist. Can I register for the event?

For media/press accreditation, please contact thesascon@thesascon.com

If you have any additional questions about SAS 2024, please contact thesascon@thesascon.com

Sign up for important updates

The information for participants will be published shortly. In the meantime, you can submit your abstracts to become SAS 2024 speaker! We also encourage you to join our exclusive training courses delivered by top world-level researchers.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service