首页> 外文OA文献 >A Universal Windows Bootkit: An Analysis of the MBR Bootkit 'HDRoot'
【2h】

A Universal Windows Bootkit: An Analysis of the MBR Bootkit 'HDRoot'

机译:通用Windows Bootkit:mBR Bootkit“HDRoot”的分析

摘要

In October, 2015 Kaspersky released an analysis of the bootkit “HDRoot”. Their analysis highlighted mistakes in the bootkit, which made it ineffective at performing its task. Upon attempts to replicate that analysis however, it appears that these conclusions were in error and the bootkit works with any Windows version in the last 16 years. HDRoot represents a serious commitment in time and effort to develop, and an in-depth analysis reveals the work of a significantly capable threat actor. The sample analyzed here dates to 2013, and is the same sample Kasperky reports to have analyzed in their post. However, all evidence points to Kaspersky performing analysis with a 2006 sample, likely the reason for their conclusions. Additionally, mistakes made in reporting the capability of offensive software, provided without means to verify, hurt the security industry by misleading practitioners and limiting their ability for informed decision making.
机译:2015年10月,卡巴斯基发布了对Bootkit“ HDRoot”的分析。他们的分析突出了Bootkit中的错误,这使其无法有效执行任务。但是,在尝试复制该分析时,这些结论似乎是错误的,并且在过去16年中,bootkit可以与任何Windows版本一起使用。 HDRoot代表着在开发时间和精力上的认真承诺,而深入的分析揭示了强大的威胁参与者的工作。此处分析的样本可追溯到2013年,与Kasperky报告中所分析的样本相同。但是,所有证据都表明卡巴斯基对2006年的样本进行了分析,这很可能是得出结论的原因。此外,在报告攻击性软件功能时所犯的错误(没有提供验证手段)通过误导从业人员并限制其知情决策的能力而伤害了安全行业。

著录项

  • 作者

    Showalter William;

  • 作者单位
  • 年度 2017
  • 总页数
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号