BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2026//talk//SKB7U8
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20251022T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:A Generalized Fingerprinting Framework for Deriving Searchable Fea
 tures to Identify Publicly Exposed Infrastructure - Bilal\, Bob van der Ka
 mp
DTSTART;TZID=Europe/Luxembourg:20261022T163000
DTEND;TZID=Europe/Luxembourg:20261022T170000
DTSTAMP:20261009T054123Z
UID:pretalx-hack-lu-2026-SKB7U8@pretalx.com
DESCRIPTION:Scanning of internet-exposed infrastructure has become a core 
 methodology in\nnetwork security research\, vulnerability assessment\, and
  threat intelligence.\nThreat intelligence analysts and researchers routin
 ely scan the public internet to identify\nexposed services\, characterize 
 device types\, and infer software versions in\norder to assess security po
 sture and systemic risk. When a new vulnerability is disclosed\,\nnational
  security teams face the task of identifying the hosts that run the vulner
 able version.\nHere\, time and reliability are key\, because vulnerable in
 frastructure has to be found before\nattackers find it. Under NIS2\, which
  significantly expands the number and\ndiversity of organizations under su
 pervision\, this task has become even more\nimportant.\n\nTherefore\, this
  talk presents parts of the results of a master thesis performed at the re
 quest\nof and in close collaboration with the National Cyber Security Cent
 re (NCSC-NL).\nIt gives insights into a proposed methodology that guides t
 hreat intelligence\nanalysts to a fast and reliable search engine query\, 
 in this case Censys\, in\norder to identify vulnerable infrastructure. We 
 present part of the methodology\,\nwhich is modeled as a decision tree who
 se leaves result either in an effective query\nor in the conclusion that n
 o suitable query can be derived. Alongside it\, we present\nthe comprehens
 ive feature table\, in which features across domains were aggregated to\nd
 epict the most promising fingerprinting features. Certificates\, exposed H
 TML code\,\nand even TTL values of OT devices can all be used as fingerpri
 nting features to identify a specific\nvulnerable product. Finally\, we pr
 esent parts of the prototype: a CLI-based\ntool that allows researchers an
 d experts to automatically identify suitable\nfeatures and the resulting q
 uery.
LOCATION:Europe
URL:https://pretalx.com/hack-lu-2026/talk/SKB7U8/
END:VEVENT
END:VCALENDAR
