Protecting Data In-Use from Firmware and Physical Attacks
Stephen A. Weis · 2014
Defending computers from unauthorized physical access, malicious hardware devices, or other low-level attacks has proven extremely challenging. The risks from these attacks are exacerbated in cloud-computing environments, where users lack physical control over servers executing their workloads. This paper reviews several rmware and physical attacks against x86 platforms, including bootkits, cold booting, and malicious devices. We discuss several existing tools and technologies that can mitigate these risk such as Trusted Execution Technology (TXT) and main memory encryption. We will also discuss upcoming technologies that may help protect against rmware and physical threats.