How to Bypass Verified Boot Security in Chromium OS
نویسندگان
چکیده
Verified boot is an interesting feature of Chromium OS that should detect any modification in the firmware, kernel or the root file system (rootfs) by a dedicated adversary. However, by exploiting a design flaw in verified boot, we show that an adversary can replace the original rootfs by a malicious rootfs containing exploits such as a spyware and still pass the verified boot process. The exploit is based on the fact that although a kernel partition is paired with a rootfs, verification of kernel partition and rootfs are independent of each other. We experimentally demonstrate an attack using both the base and developer version of Chromium OS in which the adversary installs a spyware in the target system to send cached user data to the attacker machine in plain text which are otherwise inaccessible in encrypted form. We also discuss possible directions to mitigate the vulnerability.
منابع مشابه
Scalable Security Architecture for Trusted Software
.................................................................................................................................IV ACKNOWLEDGEMENTS ......................................................................................................... V CONTENTS .................................................................................................................................VI...
متن کاملA Practical Hardware-Assisted Approach to Customize Trusted Boot for Mobile Devices
Current efforts to increase the security of the boot sequence for mobile devices fall into two main categories: (i) secure boot: where each stage in the boot sequence is evaluated, aborting the boot process if a non expected component attempts to be loaded; and (ii) trusted boot: where a log is maintained with the components that have been loaded in the boot process for later audit. The first a...
متن کاملSecurity Technology for Smartphones
Service functions are implemented on smartphones by storing on them personal information, network-operator information, corporate information, and so on. Most smartphones use an open source operating system (OS), and anyone can obtain the OS source code; consequently, smartphone users are exposed to the threat of receiving fraudulent information from people with malicious intent. Aimed at count...
متن کاملImproving system security through TCB reduction
The OS (operating system) is the primary target of todays attacks. A single exploitable defect can be sufficient to break the security of the system and give fully control over all the software on the machine. Because current operating systems are too large to be defect free, the best approach to improve the system security is to reduce their code to more manageable levels. This work shows how ...
متن کاملUefi Secure Boot in Modern Computer Security Solutions
OVERVIEW What is the UEFI Forum? The Unified Extensible Firmware Interface (UEFI) Forum is a world-class non-profit industry standards body that works in partnership to enable the evolution of platform technologies. The UEFI Forum champions firmware innovation through industry collaboration and the advocacy of a standardized interface that simplifies and secures platform initialization and firm...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- CoRR
دوره abs/1202.5282 شماره
صفحات -
تاریخ انتشار 2012