کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
6884504 1444268 2017 13 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Forensic limbo: Towards subverting hard disk firmware bootkits
ترجمه فارسی عنوان
لایحه قانونی: برای خلاص شدن از بوت کیت های سخت افزاری سخت افزاری
کلمات کلیدی
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
چکیده انگلیسی
We discuss the problem posed by malicious hard disk firmware towards forensic data acquisition. To this end, we analyzed the Western Digital WD3200AAKX model series (16 different drives) in depth and outline methods for detection and subversion of current state of the art bootkits possibly located in these particular hard disks' EEPROMs. We further extend our analysis to a total of 23 different hard drive models (16 HDDs and 7 SSDs) from 10 different vendors and provide a theoretical discussion on how hard disk rootkits residing in the firmware overlays and/or modules stored in the special storage area on a HDD called the Service Area could be detected. To this end, we outline the various debug interfacing possibilities of the various hard disk drives and how they can be used to perform a live analysis of the hard disk controller, such as dumping its memory over JTAG or UART, or how to access the Service Area via vendor specific commands over SATA.
ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Digital Investigation - Volume 23, December 2017, Pages 138-150
نویسندگان
,