Vietnam.vn - Nền tảng quảng bá Việt Nam

The 'golden' boys in the security village

Báo Thanh niênBáo Thanh niên12/02/2024

Surpassing experts from prestigious technology corporations and leading security experts, young engineers from Viettel Cyber ​​Security Company have won the world's largest and most prestigious cyber attack competition Pwn2Own 2023, bringing the name of Vietnamese "white hat hackers" to the world...

"Eat, sleep with… holes"

2023 is the 4th year that Viettel team participated in the Pwn2Own Competition and glory really came to them. If the first competition was just for practice, then in the 2nd competition (2021) the team entered the top 5 and in the 2022 competition, the team lost to the champion team with regret, receiving second prize. Ngo Anh Huy (team captain) shared: "Pwn2Own is the world's largest and most prestigious cyber attack competition, the "World Cup" of the security world with a total prize of up to millions of USD. The attack targets are all popular devices and software in the world, from leading suppliers such as Microsoft, Apple, Google, Samsung, Xiaomi...".
Những chàng trai 'vàng' trong làng bảo mật- Ảnh 1.

Ha Anh Hoang (left) and Nguyen Xuan Hoang (right) represent Team Viettel to Canada to receive the trophy and prize of 180,000 USD

Pwn20wn Competition The competition took place from October 24 to 27, 2023 in Toronto (Canada), 14 young men, the youngest of whom was only 20 years old, were determined to achieve the championship goal. Instead of focusing on finding many vulnerabilities like previous competitions, in this competition, the group of young engineers built a methodical strategy, finding errors that few people discovered and exploited. One of the things that team leader Ngo Anh Huy was most concerned and worried about was how to connect members to work in a team (teamwork). In the last 2 weeks before the competition, the whole team worked 20 hours/day, almost eating and sleeping on the spot, having to prepare reports to send to the organizing committee and checking for updates to patch vulnerabilities. "The vulnerabilities can be found and patched by the manufacturer before the competition. Therefore, we often have to find as many vulnerabilities as possible and prepare backup attack plans if we want to achieve the highest score," added member Ha Anh Hoang. Everything was carefully prepared, just waiting for the day to leave for Canada to compete, but the most regrettable thing was that close to the competition date, the whole team still did not receive an entry visa. "Instead of competing directly, Team Viettel had to stay home and compete online. This is also a disadvantage compared to competing directly, which is that we can only check the equipment remotely via camera. If we compete directly, we can consult on the spot or ask the organizers to immediately check any arising situations. In addition, the online process can have unexpected problems related to machines and equipment...", Hoang recounted.

Breathtaking, convincing victory

After 3 months of "eating, sleeping and finding vulnerabilities", finally, the G hour has come, the Vietnamese team must demonstrate the ability to attack security vulnerabilities in a short time. Member Nguyen Xuan Hoang said: "In other security competitions, there is usually no time limit, but in this competition, we have to demonstrate finding vulnerabilities within 30 minutes. Pwn2Own brings together the most advanced targets and devices from major technology companies and is installed with the latest software versions. The task of the teams is to find attack directions and find vulnerabilities that have never been discovered". Each team can only hack once for each target. The more difficult the target, the higher the score. At the end of the competition, the individual or organization with the highest score will win the prize. "Our biggest worry is that there will be duplicate errors or that the manufacturer has discovered and patched the holes in time. The team members have prepared different holes, the more points we have to prepare for the category, the more errors we have to prepare. In this part, the team received the maximum total score, no duplicate errors like last year, which were deducted points. We were so happy that we cried," said Ha Anh Hoang. The most exciting part was the final round, SOHO Smashup (small office equipment). The obstacle for the team was the psychological problem, because they missed the championship last year, so they were a bit cautious. There were even a few times when things did not go as planned. Everyone was sweating with worry. Although they had prepared 3 holes, the first 2 performances failed. It was not until the 3rd time that they succeeded that the members burst into joy... The opponents also had to admire the persistent fighting of the Vietnamese team.
Những chàng trai 'vàng' trong làng bảo mật- Ảnh 2.

14 boys of Team Viettel

T. Tho

This was the first time Dinh Quang Vu participated in the competition, but he made an important contribution to help his team win the mobile phone vulnerability category. This is a new category in the competition. Vu shared: "Our team chose 2 mobile devices from Samsung and Xiaomi. Although we had researched, prepared quite carefully and had passed the manufacturer's patches before the competition day, we failed the first attempt with Samsung. The feeling at that time was suffocating and heartbreaking, fortunately, we were calm and passed the competition to win with the Xiaomi mobile device". After 4 nights of intense competition with the strongest teams from many places around the world, at 1:00 a.m. on October 27, Team Viettel successfully completed the competition with a total score of 30, 12.75 points ahead of the second place team. Young Vietnamese engineers convincingly won the Pwn2Own championship, scoring absolute points in all 7 registered categories, bringing home a prize of 180,000 USD. The products found with flaws included Xiaomi 13 Pro, QNAP storage systems, Canon, HP, Lexmark printers, Sonos smart speakers and SOHO Smashup. This victory also marked a new breakthrough for the Vietnamese information security industry when it won the championship for the first time at a prestigious international tournament. In addition to the awards at Pwn2Own, young engineers of VSC Company also discovered more than 400 Zero-day security vulnerabilities in major information technology platforms and systems such as Microsoft, Oracle, Google, Apache, VMWare, etc.

Aspiration to conquer new heights

Not "resting on their laurels", after the competition, the whole team started preparing for the next competition scheduled to be held in Tokyo (Japan) in early 2024 with determination to conquer new heights. Ha Anh Hoang confided: "To achieve victory today, we have conquered step by step, going from easy to difficult. The victory of the whole team is very convincing, but we cannot ignore the opponents of this competition, because in terms of expertise, there are still some research areas, some capabilities that foreign teams have, Viettel team cannot do. The immediate goal of the team is to find new research topics, find security vulnerabilities of giant suppliers such as: Apple, Google... And the further goal is to lead in the world security arena". As one of the young security experts of Vietnam recognized by the international community, invited to work by many famous technology companies with a salary of thousands of USD, Ngo Anh Huy still stays with Team Viettel. "For me, conquering the challenge is not only to assert myself and achieve a new security ranking, I want to stay in Vietnam to continue writing new pages of history about the information security industry with young people who share the same passion, making Vietnam famous in international arenas," Huy shared. According to Colonel Tao Duc Thang, Chairman of the Board of Directors and General Director of Viettel, this is not a competition to find the right answer, but like a game of "catch the picture and catch the word", young engineers have to "fight" with the world's leading suppliers and manufacturers of technology equipment. Behind the suppliers is a very large group such as Canon, Xiaomi... Victory is not easy because it is very possible that at the last minute the supplier suddenly releases patches, making the competing teams passive and unable to react. Colonel Tao Duc Thang believes that the championship achievement of Pwn2Own 2023 is just the beginning. The road ahead for "white hat hackers" is still long because the field of cyber security is very large, cyberspace is vast and there are many challenges waiting for young engineers ahead. Not only stopping at the IoT field, there are also fields of industry, energy, electricity, safety... young engineers have the opportunity to assert themselves.
According to Mr. Nguyen Son Hai, Director of VSC Company: "The competition is still just a game, there are still other goals that Team Viettel needs to conquer. The victory at Pwn2Own is just the beginning, we are realizing the mission of becoming a solid shield to ensure network security so that people can live and work more safely in the network environment, bringing the Vietnamese security industry to affirm a solid position on the world network security map. If we have a far enough vision, big enough faith, determination not to give up, and practical enough actions, we will achieve the goal".

Thanhnien.vn

Source link

Comment (0)

No data
No data

Same tag

Same category

Son Doong Cave is among the top 'surreal' destinations like on another planet
Wind power field in Ninh Thuan: Check-in "coordinates" for summer hearts
Legend of Father Elephant Rock and Mother Elephant Rock in Dak Lak
View of Nha Trang beach city from above

Same author

Heritage

Figure

Business

No videos available

News

Political System

Local

Product