摘要
指出了UEFI中源代码、自身扩展模块及来自网络的安全隐患,分析了传统的BIOS与已有的UEFI恶意代码检测方法的不足,定义了结合UEFI平台特点的攻击树与威胁度,构建了动态扩展的威胁模型库与恶意行为特征库相结合的攻击树模型,设计了针对UEFI恶意行为检测的加权最小攻击树算法。实验证明了模型的有效性与可扩展性。
The potential risk from source code, extension modules of Unified Extensible Firmware Interface (UEFI) and network is pointed out. The shortcomings of existing BIOS and UEFI malicious code detection methods are ana- lyzed, UEFI attack tree and threat level are defined, a UEFI threats model database and malicious behavior character database are built together as an attack tree model with dynamic expansion, weighted minimal attack tree algorithm is designed for UEFI malicious behavior detection. The experimental results show the effectiveness and the expand- ability of this proposed model.
出处
《计算机工程与应用》
CSCD
2012年第32期14-17,46,共5页
Computer Engineering and Applications
基金
国家科技支撑计划课题(No.2012BAH14B02)
中科院知识创新重点方向项目(No.YYYJ-1013)
关键词
统一可扩展固件接口
恶意代码
攻击树
安全风险
Unified Extensible Firmware Interface(UEFI)
malicious code
attack tree
security risk