World’s Top Student Teams Take on Microchip Security at NYU And IIT Kanpur Cyber Security Awareness Week Games

Finalists in the Embedded Security Contest brought their research as well as programmable computer boards to see if they could hack into an example of what may well become the next generation of voting systems, protected by homomorphic encryption.

Elite teams from seven universities won finalist slots in the ninth annual Embedded Security Challenge (ESC). The oldest and largest hardware hacking competition in the world, ESC is also the most difficult event at New York University Tandon School of Engineering’s annual Cyber Security Awareness Week (CSAW) games for students.

The event, founded in 2008 by NYU Tandon Professor of Electrical and Computer Engineering Ramesh Karri and his students, is a cornerstone program of NYU’s hardware security group. Part of NYU Center for Cyber Security and comprising researchers at NYU Tandon and NYU Abu Dhabi, the group has become a leading force in microchip security.  

The ESC for the first time includes the Indian Institute of Technology, Kanpur (IIT Kanpur). Finalists will travel to IIT Kanpur or NYU Tandon to compete before a panel of security experts during CSAW (November 10-12, 2016).

The seven finalist teams are:

Grenoble INP-ESISAR (France)
Team members: Cyril Bresch, Adrien Michelet-Gignoux, Thomas Meyer, Laurent Amato
Mentor: David Hely

Indian Institute of Technology Kharagpur
Team members: Manaar Alam, Vidya Govindan, Sarani Bhattacharya, Debapriya Basu Roy
Mentors: Rajat Subhra Chakraborty, Debdeep Mukhopadhyay

Indian Institute of Technology Madras
Team members: Prasanna Karthik, Patanjali SLPSK, Gnanambikai Krishnakumar
Mentor: Chester Rebeiro

Pennsylvania State University
Team members: Nolan Betts, Eric Pauley, Andy Luo
Mentor: Swaroop Ghosh

The University of Central Florida (Orlando)
Team members: Orlando Arias, Dean Sullivan, Heather Lawrence, Kelvin Ly
Mentor: Yier Jiin

The University of New Hampshire
Team members: Sean Kramer, Zhiming Zhang
Mentor: Qiaoyan Yu

The University of Texas at Dallas
Team members: Tri Minh Cao, Danqing Liu
Mentors: Jeyavijayan Rajendran, Yiorgos Makris

The ESC tournament employs a “red team, blue team” format that mimics real-world attacks. This year’s challenge was designed by a team of top NYU security faculty and students mentored by Assistant Professor Michail Maniatakos and Nektarios Tsoutsos, a computer science doctoral candidate studying under Maniatakos at NYU Abu Dhabi. The contest requires the competitors to defend against one of the most common security bugs: memory corruption, by which a hacker subverts a microchip by changing critical data in its memory. The teams will attempt to enhance a basic chip design so that memory corruption can’t harm the system.

"The Embedded Security Challenge at CSAW is not just about academic bragging rights,” said Karri. “Because the attack and defense models and ideas that ESC generate apply to the real world — real scenarios, real technology, and real threats — they can be used to generate security tools for the chip design process and tactics for defending against theft of chip design and sabotage during fabrication." 

The preliminary event required teams to design their own vulnerable computer programs, show how to exploit those vulnerabilities, and offer hardware defensive techniques to prevent such attacks.

The ESC judges are Ryan Craven, program officer, Cyber Security Division, Office of Naval Research, U.S. Navy; Xiaofei Guo, senior security researcher, Security Center of Excellence, Intel Corporation; Antonis Stampoulis, senior software engineer/programming languages researcher, Originate NYC.; and Michael Locasto, senior computer scientist, SRI International.

Sponsors for CSAW 2016 are: Gold Level — U.S. Department of Homeland Security, Trend Micro, and Palo Alto Networks; Silver Level — IBM, Google, Kroll, Bridgewater; Bronze Level — Navy Civilian Careers, NCC Group, Raytheon, Facebook; Supporting Level — Bloomberg, Cubic, Intel, National Security Agency, Optiv, Sandia National Laboratories, U.S. Secret Service, EY, and The Ruth & Jerome A. Siegel Foundation; Contributing — Cigital, ACSA, Altera.

