BetaONE will rise again!


 
Prev Previous Post   Next Post Next
  #1  
Old 6th Mar 07, 02:38 PM
Alpine's Avatar
Alpine Alpine is offline
Retired Crew
 
Join Date: Feb 2002
Location: Run Forest, RUN!!
Posts: 3,601
Alpine is on a distinguished road
Send a message via ICQ to Alpine Send a message via AIM to Alpine
Hardware cannot protect you from rootkits
Rethink needed

A SECURITY expert, Joanna Rutkowska, who is a specialist in rootkits, says that hardware rootkit protection cannot find the more serious stuff.


Hardware rootkit detection has been touted as a much more reliable way of finding the nasty stuff than software methods.

But, speaking at this year's Black Hat DC conference, Rutkowska demonstrated three different attacks against a computer showing how the image of volatile memory (RAM) can be made different from the real contents of the physical memory as seen by the CPU.

According to ZDNET the demonstration showed that the current use of hardware-based RAM acquisition was not the best way to sniff out a rootkit on a compromised machine.

She said that to deal with rootkits required both hardware and software to work in tandem during forensics.

Rutkowska pointed out that sophisticated rootkits can be incredibly dangerous as forensic examiners cannot rely on images collected from RAM.

In one of her attack scenarios she showed how a rootkit could even provide fake information to an examiner.

What is required to make computers completely safe, says Rutkowska is a rethink of design so that they are somehow more verifiable. Hardware vendors come up with a special "auditing" interface dedicated only to memory acquisition.

She said that motherboard manufacturers should consider adding a special port which would allow for direct access to RAM and potentially some other critical resources like e.g. CPU system registers and maybe even caches. More here.
Reply With Quote
 


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
M$ gives hardware wonks a Vista break Alpine BetaONE News 0 31st Oct 06 08:59 PM
No DirectX 10 hardware yet available Alpine BetaONE News 0 19th Jun 06 07:35 PM
The truth about Windows Vista hardware Alpine BetaONE News 0 15th Jun 06 09:41 PM
Intel Researchers Sneak Up on Rootkits NewsBot NeoWin News 0 14th Dec 05 12:30 AM
Microsoft Hardware Is Coming Soon to a Living Room Near You NewsBot NeoWin News 0 13th Jul 05 10:00 AM


All times are GMT +1. The time now is 06:46 AM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.