PCI cards the next haven for rootkits?

安全研究员John Heasman发布了一篇论文,详细介绍了如何利用图形卡和网络卡上的扩展内存来隐藏恶意代码,使其能够躲避检测并在操作系统完全重装后依然存活。Heasman还提出了针对这种攻击的潜在防御措施。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

Security researcher John Heasman released a paper this week describing a way to hide malicious code on graphics and network cards in such a way as to avoid detection and survive a full re-installation of the operating system.

The paper (PDF), published on Wednesday, builds on the work presented by Heasman earlier this year, describing ways to use the Advanced Configuration and Power Interface (ACPI) functions available on almost all motherboards to store and run a rootkit that could survive a reboot. The current paper outlines ways to use the expansion memory available on Peripheral Component Interconnect (PCI) cards, such as graphics cards and network cards.

Heasman, a researcher at Next-Generation Security Software, does not believe that such techniques will become commonplace.

"(Because) enough people do not regularly apply security patches to Windows and do not run anti-virus software, there is little immediate need for malware authors to turn to these techniques as a means of deeper compromise," he wrote in the paper. "If a user detects the malware and removes it, there are plenty more unsuspecting targets on the Internet."

Heasman also described a potential defense against the rootkit technique in the paper. By auditing the expansion memory and system memory, an administrator could look for suspiciously obfuscated code, the presence of 32-bit code, and odd class codes, among other telling signs of compromise. Moreover, computers that use the Trusted Computing Module to protect the boot process will be immune to this type of rootkit compromise, he wrote.

 
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值