Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Jiewen Yao, Vincent Zimmer

Rating No ratings yet

Use this book to build secure firmware. As operating systems and hypervisors have become successively more hardened, malware has moved further down the stack and into firmware. Firmware represents the boundary between hardware and software, and given its persistence, mutability, and opaqueness to today’s antivirus scanning technology, it represents an interesting target for attackers. As platforms are universally network-connected and can contain multiple devices with firmware, and a global supply chain feeds into platform firmware, assurance is critical for consumers, IT enterprises, and governments. This importance is highlighted by emergent requirements such as NIST SP800-193 for firmware resilience and NIST SP800-155 for firmware measurement. This book covers the secure implementation of various aspects of firmware, including standards-based firmware—such as support of the Trusted Computing Group (TCG), Desktop Management Task Force (DMTF), and UnifiedExtensible Firmware Interface (UEFI) specifications—and also provides code samples and use cases. Beyond the standards, alternate firmware implementations such as ARM Trusted Firmware and other device firmware implementations (such as platform roots of trust), are covered. What You Will Learn • Get an overview of proactive security development for firmware, including firmware threat modeling • Understand the details of architecture, including protection, detection, recovery, integrity measurement, and access control • Be familiar with best practices for secure firmware development, including trusted execution environments, cryptography, and language-based defenses • Know the techniques used for security validation and maintenance Who This Book Is For Given the complexity of modern platform boot requirements and the threat landscape, this book is relevant for readers spanning from IT decision makers to developers building firmware.

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A practical, standards-aware guide to designing, building, and validating secure firmware across the full platform boot stack—from threat modeling through resiliency, trusted boot, and device firmware. Best for firmware engineers, platform security architects, and technical decision makers who need to understand why firmware is a high-value attack surface and how to harden it. 【Book Arc】 - **Opening (~0%–15%)**: Establishes why firmware matters—its persistence, mutability, and invisibility to traditional antivirus make it an attractive target—and frames the core concepts: firmware resiliency, measurement and attestation, secure device communication, host vs. non-host vs. device firmware, industry standards, and phased boot handoff. - **Early (~15%–35%)**: Introduces a proactive security development lifecycle: security requirements, threat modeling and architecture, secure coding, security unit tests, code review, fuzzing, and static/dynamic analysis, illustrated with a real threat-model example. - **Middle (~35%–65%)**: Covers the security architecture of firmware resiliency—protection, detection, and recovery—plus authenticated update mechanisms, integrity protection, non-bypassability, and configuration data security, with case studies and attack/mitigation discussions. - **Late (~65%–90%)**: Extends resiliency concepts to the OS, introduces trusted boot, device firmware security (secure communication and attack prevention), the special S3 resume path, access control (boot, device, feature configuration), and confidentiality/integrity/availability of firmware configuration data. - **Ending (~90%–100%)**: Closes with security models—mapping the Clark-Wilson model to existing firmware features—and virtual firmware, including how virtualization may introduce a new threat model. 【Key Takeaways】 - **Firmware is a distinct security domain, not just low-level software** (Opening): its persistence and opacity to antivirus make it a prime target, so it needs its own threat model and assurance requirements. - **Security must be built in proactively, not bolted on** (Early): requirements, threat modeling, secure coding, unit tests, code review, fuzzing, and static/dynamic analysis form a lifecycle, demonstrated through a real example. - **Firmware resiliency rests on three pillars—protection, detection, and recovery** (Middle): each is treated as an architectural concern with case studies and attack/mitigation analysis. - **Updates and integrity are inseparable from non-bypassability** (Middle): authenticated update mechanisms and integrity protection only work if attackers cannot bypass them, and configuration data must be handled with equal care. - **Trusted boot extends firmware trust into the OS** (Late): measurement and attestation concepts connect firmware resiliency to the broader platform boot chain. - **Device firmware and special boot paths need their own defenses** (Late): secure device communication, device attack prevention, and the S3 resume path are distinct risk areas. - **Access control applies across boot, devices, and feature configuration** (Late): firmware must enforce who can do what during and after boot, not just verify code integrity. - **Security models give structure to firmware features** (Ending): mapping Clark-Wilson to firmware features shows how formal models can guide practical design, while virtual firmware may require a fresh threat model. 【Reading Tips】 - Read Part I (Opening–Early) carefully if you are new to firmware security; it defines the vocabulary and lifecycle that the rest of the book assumes. - Treat the threat-modeling and real-example sections as the most actionable early material—apply them to your own platform rather than skimming. - In the architecture chapters, focus on the protection/detection/recovery triad and the case studies; use the attack/mitigation discussions as checklists for your own designs. - Skim the table-of-contents-heavy transitions and revisit specific chapters (trusted boot, device firmware, S3 resume, access control) based on your platform responsibilities. - Keep the standards references (TCG, DMTF, UEFI, NIST SP800-193/155) in mind as you read; they explain why certain requirements exist. 【Coverage Limits】 The excerpts are heavily weighted toward front matter, table of contents, and a final summary; detailed chapter content, code samples, and case-study specifics are not fully represented here. This guide therefore maps the book's structure and themes rather than reproducing its technical depth.
Excerpt 1
security validation and maintenance Who This Book Is For Given the complexity of modern platform boot requirements and the threat landscape, this book is rel...
View in text
Excerpt 2
xxix vi Chapter 2: Proactive Firmware Security Development 17 Requirement Phase 17 Security Requirements 17 Threat Model and Architecture Phase 18 Threat Mod...
View in text
Page 7
158 Table of ConTenTs
View in text
Page 9
270 Table of ConTenTs
View in text
Page 11
416 Table of ConTenTs
View in text
Page 13
598 Table of ConTenTs
View in text
Page 15
790 Table of ConTenTs
View in text
Page 20
the best practices in the security development of firmware. The whole book consists of four parts: Part I: Overview Chapter 1 includes a brief overview of th...
View in text
Tags
AI categories
CybersecurityProgrammingTechnology
Publisher: Apress
Publish Year: 2020
Language: English
Pages: 941
File Format: PDF
File Size: 18.4 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…