作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (16): 114-116. doi: 10.3969/j.issn.1000-3428.2007.16.039

• 安全技术 • 上一篇    下一篇

计算机BIOS安全风险分析与检测系统研究

周振柳1,刘宝旭1,池亚平2,许榕生1   

  1. (1. 中国科学院高能物理所计算中心,北京100049;2. 北京电子科技学院,北京 100070)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-08-20 发布日期:2007-08-20

Research on Computer BIOS Security Risk Analysis and Detection System

ZHOU Zhen-liu1, LIU Bao-xu1, CHI Ya-ping2, XU Rong-sheng1   

  1. (1. Computing Center, Institute of High Energy Physics, Chinese Academy of Sciences, Beijing 100049; 2. Beijing Electronic Science and Technology Institute, Beijing 100070)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-08-20 Published:2007-08-20

摘要: 介绍了计算机BIOS安全风险的形成及特点,总结了BIOS安全风险的分类,提出了BIOS安全威胁模型和基于BIOS安全隐患扫描和代码完整性度量的BIOS安全检测模型。实现了一个基于BIOS安全隐患库与BIOS标准代码样本库的BIOS安全检测系统。指出BIOS在信息安全基础解决方案中的进一步安全增强和安全扩展的研究方向。

关键词: BIOS, 安全风险, 安全隐患, 安全检测

Abstract: This article introduces the progress and characteristics of BIOS security threat, summarizes the BIOS security risk classification, advances a model of BIOS security threat and a model of BIOS security detection which based on scanning of BIOS vulnerabilities and measuring of BIOS code integrity. A BIOS security detection system, based on the libraries of BIOS vulnerabilities and BIOS standard code samples, is implemented. Further study directions about enhancing and extending BIOS security role in information security fundamental solution are also presented.

Key words: BIOS, security risk, security vulnerability, security detection

中图分类号: