Today's computer systems come with a pre-installed tiny operating system, which is also known as UEFI. UEFI has slowly displaced the former legacy PC-BIOS while the main task has not changed: It is responsible for booting the actual operating system. However, features like the network stack make it also useful for other applications. This paper introduces UEberForensIcs, a UEFI application that makes it easy to acquire memory from the firmware, similar to the well-known cold boot attacks. There is even UEFI code called by the operating system during runtime, and we demonstrate how to utilize this for forensic purposes.
翻译:当今计算机系统预装有一个微型操作系统,即统一可扩展固件接口(UEFI)。UEFI已逐步取代传统的PC-BIOS,但其核心任务保持不变:负责启动实际的操作系统。然而,其网络协议栈等特性使其同样适用于其他应用场景。本文介绍UEberForensIcs——一种UEFI应用程序,它能便捷地从固件中获取内存数据,其原理类似于众所周知的冷启动攻击。操作系统在运行期间甚至会调用特定的UEFI代码,我们展示了如何利用这一特性实现取证目的。