Bootkits: Past, Present & Future
نویسندگان
چکیده
Bootkit threats have always been a powerful weapon in the hands of cybercriminals, allowing them to establish a persistent and stealthy presence in their victims’ systems. The most recent notable spike in bootkit infections was associated with attacks on 64-bit versions of the Microsoft Windows platform, which restrict the loading of unsigned kernel-mode drivers. However, these bootkits are not effective against UEFI-based platforms. So, are UEFI-based machines immune against bootkit threats (or would they be)? The aim of this presentation is to show how bootkit threats have evolved over time and what we should expect in the near future. First, we will summarize what we have learned about the bootkits seen in the wild targeting the Microsoft Windows platform: from TDL4 and Rovnix (the one used by the Carberp banking trojan) up to Gapz (which employs one of the stealthiest bootkit infection techniques seen so far). We will review their infection approaches and the methods they have employed to evade detection and removal from the system. Secondly, we will look at the security of the increasingly popular UEFI platform from the point of view of the bootkit author as UEFI becomes a target of choice for researchers in offensive security. Proof-of-concept bootkits targeting Windows 8 using UEFI have already been released. We will focus on various attack vectors against UEFI and discuss available tools and what measures should be taken to mitigate against them.
منابع مشابه
"Nice Boots!" - A Large-Scale Analysis of Bootkits and New Ways to Stop Them
Bootkits are among the most advanced and persistent technologies used in modern malware. For a deeper insight into their behavior, we conducted the first large-scale analysis of bootkit technology, covering 2,424 bootkit samples on Windows 7 and XP over the past 8 years. From the analysis, we derive a core set of fundamental properties that hold for all bootkits on these systems and result in a...
متن کاملClimate Change Modeling and Drought Detection of Lake Neor by Approaching to Past, Present, and Future
این مقاله فاقد چکیده میباشد.
متن کاملTeachers’ Professional Competencies: Past, Present, and Future
Teachers’ Professional Competencies: Past, Present, and Future M. Rezaai, Ph.D.* The purpose of this paper is to review the expected professional competencies throughout the history of teacher training in Iran. As such it covers both the past, covering the period from teacher training inception in 1918 to the Islamic revolution in 1979; and the present, since the revolution. Of course t...
متن کاملMizaj past, present and future
Temperament (Mizaj), as an individual factor, has great importance in traditional medicine and its use in diagnosis and treatment of diseases, as well as the individual lifestyle is very common. Since medicine moves toward Personalized Medicine, the root of individual differences will find its position in different aspects of medicine in early future. In traditional medicine, temperament is ...
متن کامل