Skip to main content

Showing 1–1 of 1 results for author: Villatel, M

Searching in archive cs. Search in all archives.
.
  1. Co-processor-based Behavior Monitoring: Application to the Detection of Attacks Against the System Management Mode

    Authors: Ronny Chevalier, Maugan Villatel, David Plaquin, Guillaume Hiet

    Abstract: Highly privileged software, such as firmware, is an attractive target for attackers. Thus, BIOS vendors use cryptographic signatures to ensure firmware integrity at boot time. Nevertheless, such protection does not prevent an attacker from exploiting vulnerabilities at runtime. To detect such attacks, we propose an event-based behavior monitoring approach that relies on an isolated co-processor. W… ▽ More

    Submitted 7 March, 2018; originally announced March 2018.

    Comments: The final version of this paper has been published in the Proceedings of the 33rd Annual Computer Security Applications Conference (ACSAC), 2017. 13 pages, 5 figures