当前位置:首页 > 报告详情

针对机密虚拟机的反洗钱注入攻击.pdf

上传人: 竿*** 编号:981578 2025-11-29 47页 8.28MB

1、#BHEU BlackHatEventsAML Injection Attackson Confidential VMsSpeaker(s):Satoru Takekoshi1,Manami Mori2,Takaaki Fukai3,Takahiro Shinagawa11 The University of Tokyo,2 Tokyo Metropolitan University,3 National Institute of Advanced Industrial Science and Technology#BHEU BlackHatEventsInformation Classifi

2、cation:GeneralOutline Introduction to a Confidential VM(Virtual Machine)Overview of AML(ACPI Machine Language)Our Proposal:AML Injection Attack Case studies:Linux and Windows Mitigation Strategies Takeaways2#BHEU BlackHatEventsInformation Classification:GeneralIntroduction to a Confidential VM3#BHEU

3、 BlackHatEventsInformation Classification:GeneralVirtual Machine(VM)Traditional Virtual MachineSensitive DataCloud vendorfull access4Cloud useruploadUse the cloud.Trust us!E.g.,Amazon EC2 and Google GCP#BHEU BlackHatEventsInformation Classification:GeneralConfidential VM(CVM)Confidential Virtual Mac

4、hineSensitive DataCloud vendor5Cloud useruploadKeep my secret!No need totrust us!#BHEU BlackHatEventsInformation Classification:GeneralCVMEncryption in CVMCloud userCloud vendorUsers Sensitive Data6CPU#BHEU BlackHatEventsInformation Classification:GeneralCVMAttestation in CVMAttestationCloud vendorC

5、loud user7Guest OSFirmwareCPUOS and firmware are legitimate!#BHEU BlackHatEventsInformation Classification:GeneralThreat Model in CVMCloud vendorCloud user8CPUUntrustedTrustedCVM#BHEU BlackHatEventsInformation Classification:GeneralCommercialized CVM9Amazon EC2 instancewith AMD SEV-SNPGCP Confidenti

6、al VMinstancesAzureConfidential VMsAMD SEV-SNPIntel TDXCloud VendorsCPU Vendors#BHEU BlackHatEventsInformation Classification:GeneralOverview of AML10#BHEU BlackHatEventsInformation Classification:General11 ACPI=Advanced Configuration and Power InterfaceACPI Machine Language(AML)FirmwareOS KernelAML

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
根据报告的内容,全文主要内容概括如下: 1. **Confidential VM (CVM) 简介**:与传统虚拟机相比,CVM提供更高的安全性,通过加密和验证确保数据安全。 2. **AML (ACPI Machine Language) 概述**:AML是用于控制硬件的固件语言,可被用于注入恶意代码。 3. **AML注入攻击**:攻击者可利用AML注入攻击在CVM中执行任意代码。 4. **案例研究**:Linux和Windows系统均存在AML注入攻击的风险。 5. **缓解策略**:包括使用vTPM进行测量启动、使所有代码可验证、改进AML安全性等。 6. **关键点**: - AML注入攻击可导致任意代码执行。 - 使用vTPM进行测量启动可提高安全性。 - 云服务提供商应使所有代码可验证并发布可验证代码。 - 需要长期努力来提高AML安全性。
AML注入攻击风险" AML漏洞如何防范?" 你的虚拟机安全吗?"
客服
商务合作
小程序
服务号
折叠