Special Publication 800- 155
(Draft)
BIOS Integrity
Measurement
Guidelines (Draft)
Recommendations of the National Institute
of Standards and Technology
AndrewRegenscheid
KarenScarfone
NIST Special Publication 800- 155
(Draft) BIOS Integrity Measurement Guidelines
(Draft)
Recommendations of the National
Institute of Standards and Technology
Andrew Regenscheid
Karen Scarfone
C O M P U T E R S E C U R I T Y
Computer Security Division
Information Technology Laboratory
National Institute of Standards and Technology
Gaithersburg, MD 20899- 8930
December 2011
U.S. Department of Commerce
John Bryson, Secretary
National Institute of Standards and Technology
Patrick D. Gallagher,
Under Secretary for Standards and Technology
and Director
BIOS I NTEGRITY MEASUREMENT GUIDELINES (DRAFT)
Reports on Computer Systems Technology
The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology
(NIST) promotes the U.S. economy and public welfare by providing technical leadership for the nation’s
measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of
concept implementations, and technical analysis to advance the development and productive use of
information technology. ITL’s responsibilities include the development of technical, physical,
administrative, and management standards and guidelines for the cost- effective security and privacy of
sensitive unclassified information in Federal computer systems. This Special Publication 800-series
reports on ITL’s research, guidance, and outreach efforts in computer security and its collaborative activities with industry, government, and academic organizations.
National Institute of Standards and Technology Special Publication 800-155 (Draft)
47 pages (Dec. 2011)
Certain commercial entities, equipment, or materials may be identified in this
document in order to describe an experimental procedure or concept adequately. Such
identification is not intended to imply recommendation or endorsement by the
National Institute of Standards and Technology, nor is it intended to imply that the
entities, materials, or equipment are necessarily the best available for the purpose.
iii
BIOS I NTEGRITY MEASUREMENT GUIDELINES (DRAFT)
Acknowledgments
The authors wish to thank their colleagues who reviewed drafts of this document and contributed to its
technical content. In particular, the authors would like to acknowledge the contributions of Greg
Kazmierczak and Robert Thibadeau of Wave Systems, and Kurt Roemer from Citrix, who provided
helpful comments and feedback on early drafts of this document. We would also like to thank our
colleagues at NIST that reviewed early drafts of this document, including Bill Burr, Donna Dodson, Tim
Polk, Matthew Scholl, Murugiah Souppaya, Bill Burr, and David Waltermire.
Abstract
This document outlines the security components and security guidelines needed to establish a secure
Basic Input/Output System (BIOS) integrity measurement and reporting chain. Unauthorized
modification of BIOS firmware constitutes a significant threat because of the BIOS’s unique and
privileged position within the PC architecture. The document focuses on two scenarios: detecting changes to the system BIOS code stored on the system flash
NIST.SP.800-155_Dec2011 draft BIOS Integrity Measurement Guidelines
文档预览
中文文档
47 页
50 下载
1000 浏览
0 评论
0 收藏
3.0分
温馨提示:本文档共47页,可预览 3 页,如浏览全部内容或当前文档出现乱码,可开通会员下载原始文档
本文档由 思安 于 2022-12-05 09:07:28上传分享