Ataques de firmware na cadeia de produção

Loading...
Thumbnail Image

Date

Journal Title

Journal ISSN

Volume Title

Publisher

Universidade Federal de São Carlos
UFSCar
Campus São Carlos
Ciência da Computação - CC

DOI

Abstract

Description

This work is about the process of identifying and corrupting a piece of firmware to attack a supply chain. In it, it is explained what is a supply chain and the relevance and impact of studying its security. Then, it establishes a test environemnt and studies several motherboard components in order to pinpoint one which could be revelant as an attack vector. After a vector is found, the research then takes apart and infects the selected chip in order to do a proof of concept on how this chip could end up being compromised by a malicious supplier. Finally, it reintroduces the chip in the test environment and shows the end result.
Outra
Esse trabalho trata do procedimento de identificar e corromper firmware para atacar uma cadeia de produção. Nele, explica-se o que é uma cadeia de produção e qual a relevância e impacto de atacá-la. Em seguida, estabelece-se um ambiente de teste e realiza-se o estudo de diversos componentes da placa mãe visando encontrar um vetor de ataque. O trabalho então determina um vetor e realiza diversos experimentos de forma a ilustrar como um fornecedor malicioso poderia vir a infectar o chip, mostrando também o resultado final quando o chip é restabelecido no ambiente de testes do projeto.
FAI-UFSCar nº 15341, ProEx nº 4924/2023-18

Citation

Collections

Endorsement

Review

Supplemented By

Referenced By

Rights and licensing

Attribution 3.0 Brazil
http://creativecommons.org/licenses/by/3.0/br/