邪恶八进制信息安全团队技术讨论组's Archiver

EvilOctal 2006-11-21 23:55

[转载]Implementing and Detecting a PCI Rootkit

信息来源:[url]www.ngssoftware.com[/url]

This paper discusses means of persisting a rootkit on a PCI device containing a flashable expansion ROM. Previous work in the Trusted Computing field has noted the feasibility of expansion ROM attacks (which is in part the problem that this field has set out to solve), however the practicalities of implementing such attacks has not been discussed in detail. Furthermore, there is little knowledge of how to detect and prevent such attacks on systems that do not contain a Trusted Platform Module (TPM). Whilst the discussion mainly focuses on the Microsoft Windows platform, it should be noted that the techniques are equally likely to apply to other operating systems.

页: [1]
© 1999-2008 EvilOctal Security Team