Webcam interception and protection in kernel mode in Windows (partner presentation)

Presented at VB2019, Oct. 3, 2019, noon (30 minutes)

When we talk about digital privacy, the computer's webcam is one of the most relevant components. We all have a tiny fear that someone might be looking through our computer's camera, spying on us and watching our every move. And while some of us think these scenarios are restricted to the realm of the movies, malware authors and threat actors don't shy away from incorporating such capabilities into their malware arsenal. In this talk, we will dive into the internals of webcam-related architecture across *Windows* versions and look at how they evolved. We will look at how it is implemented in both user mode and kernel mode, and what are some of the existing APIs to interact with it. We will see the different possibilities facing an attacker who wants to gain camera access, what limitations are imposed on such an attacker, some of the methods that are used to overcome these limitations, and what can be done to defend ourselves and catch the intruders. We will look at existing webcam protection solutions on the market and will demonstrate ways to bypass them. We hope that sharing this information will help others in their fight against malware.

Presenters:

  • Michael Maltsev - Reason Cybersecurity
    Michael Maltsev Michael Maltsev is a developer and researcher at Reason Cybersecurity, a leading cybersecurity company focusing on end-user protection. He is a part of the R&D team responsible for the development of the Reason Antivirus product. Michael's latest major contribution is the development of the camera protection feature. Prior to Reason Cybersecurity, Michael served as a founder and developer of Unchecky, a one-person company with the goal of preventing accidental installation of PUPs (potentially unwanted programs). Michael has extensive experience in the field of cybersecurity and in Windows internals, and holds a B.Sc. in computer science from the Technion - Israel Institute of Technology.

Links:

Similar Presentations: