The Experts below are selected from a list of 684 Experts worldwide ranked by ideXlab platform

Andrea Lanzi - One of the best experts on this subject based on the ideXlab platform.

  • BootKeeper: Validating Software Integrity Properties on Boot Firmware Images
    2019
    Co-Authors: Ronny Chevalier, Stefano Cristalli, Christophe Hauser, Yan Shoshitaishvili, Christopher Kruegel, Giovanni Vigna, Danilo Bruschi, Ruoyu Wang, Andrea Lanzi
    Abstract:

    Boot Firmware, like UEFI-compliant Firmware, has been the target of numerous attacks, giving the attacker control over the entire system while being undetected. The measured boot mechanism of a computer platform ensures its integrity by using cryptographic measurements to detect such attacks. This is typically performed by relying on a Trusted Platform Module (TPM). Recent work, however, shows that vendors do not respect the specifications that have been devised to ensure the integrity of the Firmware’s loading process. As a result, attackers may bypass such measurement mechanisms and successfully load a modified Firmware Image while remaining unnoticed. In this paper we introduce BootKeeper, a static analysis approach verifying a set of key security properties on boot Firmware Images before deployment, to ensure the integrity of the measured boot process. We evaluate BootKeeper against several attacks on common boot Firmware implementations and demonstrate its applicability.

Lanzi Andrea - One of the best experts on this subject based on the ideXlab platform.

  • BootKeeper: Validating Software Integrity Properties on Boot Firmware Images
    'Association for Computing Machinery (ACM)', 2019
    Co-Authors: Chevalier Ronny, Cristalli Stefano, Hauser Christophe, Shoshitaishvili Yan, Wang Ruoyu, Kruegel Christopher, Vigna Giovanni, Bruschi Danilo, Lanzi Andrea
    Abstract:

    International audienceBoot Firmware, like UEFI-compliant Firmware, has been the target of numerous attacks, giving the attacker control over the entire system while being undetected. The measured boot mechanism of a computer platform ensures its integrity by using cryptographic measurements to detect such attacks. This is typically performed by relying on a Trusted Platform Module (TPM). Recent work, however, shows that vendors do not respect the specifications that have been devised to ensure the integrity of the Firmware’s loading process. As a result, attackers may bypass such measurement mechanisms and successfully load a modified Firmware Image while remaining unnoticed. In this paper we introduce BootKeeper, a static analysis approach verifying a set of key security properties on boot Firmware Images before deployment, to ensure the integrity of the measured boot process. We evaluate BootKeeper against several attacks on common boot Firmware implementations and demonstrate its applicability

Minár Tomáš - One of the best experts on this subject based on the ideXlab platform.

  • Over the Air Firmware Upgrade for Wireless Sensor Networks
    Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií, 2014
    Co-Authors: Minár Tomáš
    Abstract:

    This diploma thesis is dedicated to one of the problems in wireless sensor networks – over the air upgrade (OTAU) of nodes. The requirements for upgrade and possible ways how to transfer new Firmware Image to nodes are stated in the first chapter. The second chapter is focused on solving the problem of Firmware dissemination to whole network based on analysis of known protocols. The practical part of this thesis deals with OTAU design and implementation in Lightweight Mesh software stack from Atmel. Proposed system was tested on deRFnode platform with plugged in deRFmega128 module. The upgrade process of designed system is evaluated on test network in last part. Practical test results are compared with OTAU solution for BitCloud

  • Over the Air Firmware Upgrade for Wireless Sensor Networks
    Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií, 2014
    Co-Authors: Minár Tomáš
    Abstract:

    Diplomová práca je venovaná jednej z problematík bezdrôtových senzorových sietí – preprogramovanie firmwaru uzlov rádiovým prenosom (OTAU). V prvej kapitole sú rozobrané požiadavky a formy prenosu firmwaru do jednotlivých uzlov. Druhá kapitola je venovaná najmä riešeniu problému rozoslania firmwaru do siete na základe analýzy dostupných protokolov. Praktická časť práce pozostáva v návrhu a realizácii systému na aktualizovanie uzlov siete v prostredí Lightweight Mesh od spoločnosti Atmel. Implementácia bola realizovaná na platforme deRFnode s modulmi deRFmega128. V závere je vyhodnotenie procesu aktualizácie navrhnutého systému na testovacej sieti. Praktické výsledky testov sú porovnané z riešením OTAU v BitCloud.This diploma thesis is dedicated to one of the problems in wireless sensor networks – over the air upgrade (OTAU) of nodes. The requirements for upgrade and possible ways how to transfer new Firmware Image to nodes are stated in the first chapter. The second chapter is focused on solving the problem of Firmware dissemination to whole network based on analysis of known protocols. The practical part of this thesis deals with OTAU design and implementation in Lightweight Mesh software stack from Atmel. Proposed system was tested on deRFnode platform with plugged in deRFmega128 module. The upgrade process of designed system is evaluated on test network in last part. Practical test results are compared with OTAU solution for BitCloud.

Ronny Chevalier - One of the best experts on this subject based on the ideXlab platform.

  • BootKeeper: Validating Software Integrity Properties on Boot Firmware Images
    2019
    Co-Authors: Ronny Chevalier, Stefano Cristalli, Christophe Hauser, Yan Shoshitaishvili, Christopher Kruegel, Giovanni Vigna, Danilo Bruschi, Ruoyu Wang, Andrea Lanzi
    Abstract:

    Boot Firmware, like UEFI-compliant Firmware, has been the target of numerous attacks, giving the attacker control over the entire system while being undetected. The measured boot mechanism of a computer platform ensures its integrity by using cryptographic measurements to detect such attacks. This is typically performed by relying on a Trusted Platform Module (TPM). Recent work, however, shows that vendors do not respect the specifications that have been devised to ensure the integrity of the Firmware’s loading process. As a result, attackers may bypass such measurement mechanisms and successfully load a modified Firmware Image while remaining unnoticed. In this paper we introduce BootKeeper, a static analysis approach verifying a set of key security properties on boot Firmware Images before deployment, to ensure the integrity of the measured boot process. We evaluate BootKeeper against several attacks on common boot Firmware implementations and demonstrate its applicability.

Chevalier Ronny - One of the best experts on this subject based on the ideXlab platform.

  • BootKeeper: Validating Software Integrity Properties on Boot Firmware Images
    'Association for Computing Machinery (ACM)', 2019
    Co-Authors: Chevalier Ronny, Cristalli Stefano, Hauser Christophe, Shoshitaishvili Yan, Wang Ruoyu, Kruegel Christopher, Vigna Giovanni, Bruschi Danilo, Lanzi Andrea
    Abstract:

    International audienceBoot Firmware, like UEFI-compliant Firmware, has been the target of numerous attacks, giving the attacker control over the entire system while being undetected. The measured boot mechanism of a computer platform ensures its integrity by using cryptographic measurements to detect such attacks. This is typically performed by relying on a Trusted Platform Module (TPM). Recent work, however, shows that vendors do not respect the specifications that have been devised to ensure the integrity of the Firmware’s loading process. As a result, attackers may bypass such measurement mechanisms and successfully load a modified Firmware Image while remaining unnoticed. In this paper we introduce BootKeeper, a static analysis approach verifying a set of key security properties on boot Firmware Images before deployment, to ensure the integrity of the measured boot process. We evaluate BootKeeper against several attacks on common boot Firmware implementations and demonstrate its applicability