|国家预印本平台
首页|Bringing Forensic Readiness to Modern Computer Firmware

Bringing Forensic Readiness to Modern Computer Firmware

Bringing Forensic Readiness to Modern Computer Firmware

来源:Arxiv_logoArxiv
英文摘要

Today's computer systems come with a pre-installed tiny operating system, which is also known as UEFI. UEFI has slowly displaced the former legacy PC-BIOS while the main task has not changed: It is responsible for booting the actual operating system. However, features like the network stack make it also useful for other applications. This paper introduces UEberForensIcs, a UEFI application that makes it easy to acquire memory from the firmware, similar to the well-known cold boot attacks. There is even UEFI code called by the operating system during runtime, and we demonstrate how to utilize this for forensic purposes.

Tobias Latzo、Florian Hantke、Lukas Kotschi、Felix Freiling

计算技术、计算机技术

Tobias Latzo,Florian Hantke,Lukas Kotschi,Felix Freiling.Bringing Forensic Readiness to Modern Computer Firmware[EB/OL].(2025-05-08)[2025-07-16].https://arxiv.org/abs/2505.05697.点此复制

评论