How to Bypass Verified Boot Security in Chromium OS

نویسندگان

  • Mohammad Iftekhar Husain
  • Lokesh Mandvekar
  • Chunming Qiao
  • Ramalingam Sridhar
چکیده

Verified boot is an interesting feature of Chromium OS that should detect any modification in the firmware, kernel or the root file system (rootfs) by a dedicated adversary. However, by exploiting a design flaw in verified boot, we show that an adversary can replace the original rootfs by a malicious rootfs containing exploits such as a spyware and still pass the verified boot process. The exploit is based on the fact that although a kernel partition is paired with a rootfs, verification of kernel partition and rootfs are independent of each other. We experimentally demonstrate an attack using both the base and developer version of Chromium OS in which the adversary installs a spyware in the target system to send cached user data to the attacker machine in plain text which are otherwise inaccessible in encrypted form. We also discuss possible directions to mitigate the vulnerability.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Scalable Security Architecture for Trusted Software

.................................................................................................................................IV ACKNOWLEDGEMENTS ......................................................................................................... V CONTENTS .................................................................................................................................VI...

متن کامل

A Practical Hardware-Assisted Approach to Customize Trusted Boot for Mobile Devices

Current efforts to increase the security of the boot sequence for mobile devices fall into two main categories: (i) secure boot: where each stage in the boot sequence is evaluated, aborting the boot process if a non expected component attempts to be loaded; and (ii) trusted boot: where a log is maintained with the components that have been loaded in the boot process for later audit. The first a...

متن کامل

Security Technology for Smartphones

Service functions are implemented on smartphones by storing on them personal information, network-operator information, corporate information, and so on. Most smartphones use an open source operating system (OS), and anyone can obtain the OS source code; consequently, smartphone users are exposed to the threat of receiving fraudulent information from people with malicious intent. Aimed at count...

متن کامل

Improving system security through TCB reduction

The OS (operating system) is the primary target of todays attacks. A single exploitable defect can be sufficient to break the security of the system and give fully control over all the software on the machine. Because current operating systems are too large to be defect free, the best approach to improve the system security is to reduce their code to more manageable levels. This work shows how ...

متن کامل

Uefi Secure Boot in Modern Computer Security Solutions

OVERVIEW What is the UEFI Forum? The Unified Extensible Firmware Interface (UEFI) Forum is a world-class non-profit industry standards body that works in partnership to enable the evolution of platform technologies. The UEFI Forum champions firmware innovation through industry collaboration and the advocacy of a standardized interface that simplifies and secures platform initialization and firm...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • CoRR

دوره abs/1202.5282  شماره 

صفحات  -

تاریخ انتشار 2012