Hide metadata

dc.contributor.authorHoel, Kathrine
dc.date.accessioned2022-08-24T22:02:06Z
dc.date.available2022-08-24T22:02:06Z
dc.date.issued2022
dc.identifier.citationHoel, Kathrine. Hiding in the Shadows - Towards Understanding Modern UEFI Bootkits. Master thesis, University of Oslo, 2022
dc.identifier.urihttp://hdl.handle.net/10852/95659
dc.description.abstractMalware is an increasingly big problem in the world. Bootkits are a group of especially advanced and complex malware and are on the rise together with attack on firmware. Despite this, research efforts in modern UEFI bootkits have been scarce. The aim of this thesis is to help fill this hole. The thesis investigates what modern UEFI bootkits are, how they can be analyzed and in what ways security can be improved in order to be better prepared for future. A workflow and lab environment to help debug UEFI and analyze modern bootkits are outlined and evaluated. A case study of two modern UEFI bootkits called MoonBounce and ESPecter is also performed. The results point to hooking and loading of malicious kernel drivers to be two big techniques used by UEFI bootkits. Additionally, it is found that the bootkits analyzed manage to bypass several security measures. In the light of existing research within the field, it is speculated that vulnerabilities in UEFI and a complex supply chain is tightly linked to how bootkits infect systems in the first place. Several areas for further research are identified, and a conclusion is made that all the parts of the UEFI ecosystem has to cooperate more in order to improve. By doing this, the state of security in the boot process can be improved and we can be better prepared for the future.eng
dc.language.isoeng
dc.subjectUEFI
dc.subjectReverse engineering
dc.subjectMalware
dc.subjectHardware
dc.subjectFirmware
dc.subjectSecurity
dc.subjectVulnerabilities
dc.subjectBootkits
dc.titleHiding in the Shadows - Towards Understanding Modern UEFI Bootkitseng
dc.typeMaster thesis
dc.date.updated2022-08-25T22:00:33Z
dc.creator.authorHoel, Kathrine
dc.identifier.urnURN:NBN:no-98166
dc.type.documentMasteroppgave
dc.identifier.fulltextFulltext https://www.duo.uio.no/bitstream/handle/10852/95659/1/Thesis_kathrhoe.pdf


Files in this item

Appears in the following Collection

Hide metadata