UEFI Security Threats Introduced by S3 and Mitigation Measure

Weihua Jiao, Qingbao Li, Zhifeng Chen, Fei Cao · 2022 7th International Conference on Signal and Image Processing (ICSIP) · 2022

UEFI is widely used as the new generation BIOS, except for some new features, it also brings some security issues. The threat brought by S3 sleep jeopardizes the security of computer platforms seriously. An attacker can disable the write protection of UEFI by tampering with the S3 boot script or execute arbitrary code by exploiting dispatch opcodes with the entry point out of SMRAM. Therefore, it is vital to solve the security issue related to S3 and propose effective mitigation measures. Based on the S3 related modules and the risk propagation between modules, we propose the MBPE algorithm to identify the key vulnerability of the platform through formal analysis. Aiming at this critical vulnerability, based on the LockBox protection mechanism, we propose a mitigation measure. It includes changing the storage time of the boot script, the changed storage address of the boot script and a specific UEFI variable. After taking this mitigation measure, the attacker cannot obtain the boot script and its location simultaneously. Such, it can protect the boot script from being tampered with and further attackers. Finally, based on the real attack cases, we evaluate the mitigation measure by the abstraction of attack path and mathematical methods. Based on the evaluation finding, the mitigation measures can prevent S3related attacks and effectively improve platform security.

Read the paper · More papers on PaperTik