The Unified Extensible Firmware Interface (UEFI) is a linchpin of modern computing systems, governing secure system initialization and booting. This paper is urgently needed because of the surge in UEFI-related attacks and vulnerabilities in recent years. Motivated by this urgent concern, we undertake an extensive exploration of the UEFI landscape, dissecting its distribution supply chain, booting process, and security features. We carefully study a spectrum of UEFI-targeted attacks and proofs of concept (PoCs) for exploiting UEFI-related vulnerabilities. Building upon these insights, we construct a comprehensive attack threat model encompassing threat actors, attack vectors, attack types, vulnerabilities, attack capabilities, and attacker objectives. Drawing inspiration from the MITRE ATT&CK framework, we present a MITRE ATT&CK-like taxonomy delineating tactics, techniques, and sub-techniques in the context of UEFI attacks. This taxonomy can provide a road map for identifying existing gaps and developing new techniques for rootkit prevention, detection, and removal. Finally, the paper discusses existing countermeasures against UEFI attacks including a variety of technical and operational measures that can be implemented to lower the risk of UEFI attacks to an acceptable level. This paper seeks to clarify the complexities of UEFI and equip the cybersecurity community with the necessary knowledge to strengthen the security of this critical component against a growing threat landscape.
翻译:统一可扩展固件接口(UEFI)是现代计算系统的关键组件,负责管理系统的安全初始化和引导过程。鉴于近年来UEFI相关攻击与漏洞的激增,本文的研究具有紧迫性。基于这一迫切需求,我们系统性地探究了UEFI生态体系,深入剖析了其分发供应链、引导流程及安全机制。通过全面研究针对UEFI的攻击手段及利用相关漏洞的概念验证(PoCs),我们构建了包含威胁主体、攻击向量、攻击类型、漏洞类型、攻击能力与攻击者目标的综合攻击威胁模型。借鉴MITRE ATT&CK框架,我们提出了类似MITRE ATT&CK的分类体系,明确划分了UEFI攻击中的战术、技术与子技术类别。该分类可为识别现有防御空白、开发新型rootkit预防、检测与清除技术提供路线图。最后,本文讨论了当前针对UEFI攻击的防御措施,涵盖可降低UEFI攻击风险至可接受水平的多项技术与操作方案。本研究旨在阐明UEFI的复杂性,为网络安全社区提供必要知识以强化这一关键组件在日益严峻威胁环境中的安全性。