This document provides guidelines for preventing the unauthorized modification of Basic Input/Output System (BIOS) firmware on PC client systems. Unauthorized modification of BIOS firmware by malicious software constitutes a significant threat because of the BIOS’s unique and privileged position within the PC architecture. A malicious BIOS modification could be part of a sophisticated, targeted attack on an organization —either a permanent denial of service (if the BIOS is corrupted) or a persistent malware presence (if the BIOS is implanted with malware). As used in this publication, the term BIOS refers to conventional BIOS, Extensible Firmware Interface (EFI) BIOS, and Unified Extensible Firmware Interface (UEFI) BIOS. This document applies to system BIOS firmware (e.g., conventional BIOS or UEFI BIOS) stored in the system flash memory of computer systems, including portions that may be formatted as Option ROMs. However, it does not apply to Option ROMs, UEFI drivers, and firmware stored elsewhere in a computer system. Section 3.1 of this guide provides platform vendors with recommendations and guidelines for a secure BIOS update process. Additionally, Section 3.2 provides recommendations for managing the BIOS in an operational environment. Future revisions to this publication will also address the security of critical system firmware that interact with the BIOS. While this document focuses on current and future x86 and x64 client platforms, the controls and procedures are independent of any particular system design. Likewise, although the guide is oriented toward enterprise-class platforms, the necessary technologies are expected to migrate to consumer-grade systems over time. Future efforts may look at boot firmware security for enterprise server platforms.






























剩余31页未读,继续阅读


- 粉丝: 839
我的内容管理 展开
我的资源 快来上传第一个资源
我的收益
登录查看自己的收益我的积分 登录查看自己的积分
我的C币 登录后查看C币余额
我的收藏
我的下载
下载帮助


最新资源
- 两阶段鲁棒优化下主动配电网动态无功优化的CCG算法仿真研究 两阶段鲁棒优化 v1.2
- hyperf-PHP资源
- 基于d轴高频方波电压注入的无感矢量控制技术解析与应用
- IPD软件交付流程中测试经理的工作内容f8c6e9.pdf
- SAR ADC 10bit高速采样电路设计与仿真实践——基于Cadence工具的深度解析
- G6-JavaScript资源
- SQLAuto-SQL资源
- Demo-计算机二级资源
- 教师教学质量评价系统的设计与实现-毕业设计资源
- CRH2型高铁车辆Simpack模型:基于全轨道谱激励的动力学仿真与数据分析
- 蓝桥杯ACM-ACM资源
- MATLAB实现CNN-LSTM-Attention模型用于多特征输入数据分类预测
- 软件OBP流程下质量经理的阶段工作67f1e9.pdf
- 电子工程领域中COMSOL模拟绝缘材料电击穿及电树枝形成的原理与应用 绝缘材料 v3.0
- 国家级大创 ESP32智慧药房取药系统-大创资源
- 机器人控制运动上位机源码:多运动算法与Marilink通信协议详解 Marilink 终极版


