Thunderstrike: EFI firmware bootkits for Apple MacBooks
Thunderstrike: EFI firmware bootkits for Apple MacBooks
复制标题
Thunderstrike:适用于 Apple MacBook 的 EFI 固件启动套件
DOI:
10.1145/2757667.2757673
复制
发表时间:
2015
期刊:
影响因子:
--
通讯作者:
L. Rudolph
中科院分区:
文献类型:
--
作者:
T. Hudson;L. Rudolph
There are several flaws in Apple's MacBook firmware security that allows untrusted modifications to be written to the SPI Flash boot ROM of these laptops. This capability represents a new class of persistent firmware rootkits, or 'bootkits', for the popular Apple MacBook product line. Stealthy bootkits can conceal themselves from detection and prevent software attempts to remove them. Malicious modifications to the boot ROM are able to survive re-installation of the operating system and even hard-drive replacement. Additionally, the malware can install a copy of itself onto other Thunderbolt devices' Option ROMs as a means to spread virally across air-gap security perimeters. Apple has fixed some of these flaws as part of CVE 2014-4498, but there is no easy solution to this class of vulnerability, since the MacBook lacks trusted hardware to perform cryptographic validation of the firmware at boot time.