Vulnerability Model and Evaluation of the UEFI Platform Firmware Based on Improved Attack Graphs
Fei Cao, Qingbao Li, Zhifeng Chen · 2018
Targeted at the situation of rampant attack on UEFI Platform Firmware, this paper summarizes the UEFI platform firmware framework structure as well as its potential security problems. Then the vulnerability factors of UEFI platform firmware are described using the modeling language. This paper proposes an improved Attack Graphs model based on Finite State Machine (AGFSM), which can be used to evaluate the reliability of UEFI, as well as calculate the expected exploitation cost and expected attack loss. Finally, based on the AGFSM model, we realize the evaluation of a set of attack strategies for the UEFI platform firmware and verify the rationality of the model and the validity of the evaluation. The research is conducive to the rapid detection of the vulnerability of UEFI Platform Firmware, predict the attack paths and deploy the security strategy targeted to safeguard the firmware.