UEFI Security Analysis

Arxiv pdf 2023-11-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

The Unified Extensible Firmware Interface (UEFI) plays a crucial role in modern computing systems, governing secure system initialization and booting. A sharp spike in UEFI-related attacks and vulnerabilities has been observed in recent years [21]. To respond to this alarming trend, we believe that the cybersecurity community should be equipped with the knowledge to understand the UEFI landscape, the related attacks, and potential defenses. Over the years UEFI has been a niche topic in cybersecurity, attracting little research and lacking a comprehensive overview. The knowledge that exists on the topic is scattered across official documentation, blog posts, papers, and books which are not necessarily security focused, creating a barrier to entry for cybersecurity professionals who want to learn about the topic. This paper aims to correct that problem by exploring the UEFI from a security point of view, including the UEFI landscape, the UEFI development lifecycle, distribution, supply chain, and booting process. We investigate a wide range of real-world UEFI attacks and potential attack vectors that could exploit vulnerabilities at the various stages of the UEFI lifecycle that we examine in this paper. Inspired by the MITRE ATT&CK framework, we present a taxonomy delineating the tactics, techniques, and sub-techniques of UEFI attacks based on the commonalities and patterns observed in our examination of the attacks. Further to outlining attacks and defenses, we perform a risk analysis to identify the techniques that pose the greatest threat to UEFI security. Prioritizing the most critical risks will enable future research aimed at addressing the most vulnerable aspects of the UEFI and contributing to its security.

Loading executive summary...

LINK COPIED TO CLIPBOARD