Thunderstrike: EFI firmware bootkits for Apple MacBooks

Thunderstrike: EFI firmware bootkits for Apple MacBooks
复制标题

Thunderstrike:适用于 Apple MacBook 的 EFI 固件启动套件

DOI:
10.1145/2757667.2757673
复制
发表时间:
2015
期刊:
Proceedings of the 8th ACM International Systems and Storage Conference
影响因子:
--
通讯作者:
L. Rudolph
L. Rudolph
中科院分区:
--
文献类型:
--
作者:
T. Hudson;L. Rudolph

文献摘要

被引文献

相似文献

苹果的MacBook固件安全性存在几个缺陷,允许将不受信任的修改写入这些笔记本电脑的SPI闪存靴子ROM。此功能代表了流行的Apple MacBook产品线的一类新的持久固件rootkit或“bootkit”。隐形引导包可以隐藏自己,防止被检测到,并防止软件试图删除它们。对靴子ROM的恶意修改能够在重新安装操作系统甚至更换硬盘驱动器后继续存在。此外,该恶意软件可以将自身的副本安装到其他Thunderbolt设备的Option ROM上,作为在气隙安全边界上进行病毒传播的一种手段。Apple已经修复了其中一些漏洞,作为CVE 2014-4498的一部分,但对于此类漏洞没有简单的解决方案,因为MacBook缺乏可信的硬件来在靴子时执行固件的加密验证。
There are several flaws in Apple's MacBook firmware security that allows untrusted modifications to be written to the SPI Flash boot ROM of these laptops. This capability represents a new class of persistent firmware rootkits, or 'bootkits', for the popular Apple MacBook product line. Stealthy bootkits can conceal themselves from detection and prevent software attempts to remove them. Malicious modifications to the boot ROM are able to survive re-installation of the operating system and even hard-drive replacement. Additionally, the malware can install a copy of itself onto other Thunderbolt devices' Option ROMs as a means to spread virally across air-gap security perimeters. Apple has fixed some of these flaws as part of CVE 2014-4498, but there is no easy solution to this class of vulnerability, since the MacBook lacks trusted hardware to perform cryptographic validation of the firmware at boot time.