全网唯一标准王
Special Publication 800- 155 (Draft) BIOS Integrity Measurement Guidelines (Draft) Recommendations of the National Institute of Standards and Technology AndrewRegenscheid KarenScarfone NIST Special Publication 800- 155 (Draft) BIOS Integrity Measurement Guidelines (Draft) Recommendations of the National Institute of Standards and Technology Andrew Regenscheid Karen Scarfone C O M P U T E R S E C U R I T Y Computer Security Division Information Technology Laboratory National Institute of Standards and Technology Gaithersburg, MD 20899- 8930 December 2011 U.S. Department of Commerce John Bryson, Secretary National Institute of Standards and Technology Patrick D. Gallagher, Under Secretary for Standards and Technology and Director BIOS I NTEGRITY MEASUREMENT GUIDELINES (DRAFT) Reports on Computer Systems Technology The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) promotes the U.S. economy and public welfare by providing technical leadership for the nation’s measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of concept implementations, and technical analysis to advance the development and productive use of information technology. ITL’s responsibilities include the development of technical, physical, administrative, and management standards and guidelines for the cost- effective security and privacy of sensitive unclassified information in Federal computer systems. This Special Publication 800-series reports on ITL’s research, guidance, and outreach efforts in computer security and its collaborative activities with industry, government, and academic organizations. National Institute of Standards and Technology Special Publication 800-155 (Draft) 47 pages (Dec. 2011) Certain commercial entities, equipment, or materials may be identified in this document in order to describe an experimental procedure or concept adequately. Such identification is not intended to imply recommendation or endorsement by the National Institute of Standards and Technology, nor is it intended to imply that the entities, materials, or equipment are necessarily the best available for the purpose. iii BIOS I NTEGRITY MEASUREMENT GUIDELINES (DRAFT) Acknowledgments The authors wish to thank their colleagues who reviewed drafts of this document and contributed to its technical content. In particular, the authors would like to acknowledge the contributions of Greg Kazmierczak and Robert Thibadeau of Wave Systems, and Kurt Roemer from Citrix, who provided helpful comments and feedback on early drafts of this document. We would also like to thank our colleagues at NIST that reviewed early drafts of this document, including Bill Burr, Donna Dodson, Tim Polk, Matthew Scholl, Murugiah Souppaya, Bill Burr, and David Waltermire. Abstract This document outlines the security components and security guidelines needed to establish a secure Basic Input/Output System (BIOS) integrity measurement and reporting chain. Unauthorized modification of BIOS firmware constitutes a significant threat because of the BIOS’s unique and privileged position within the PC architecture. The document focuses on two scenarios: detecting changes to the system BIOS code stored on the system flash

pdf文档 NIST.SP.800-155_Dec2011 draft BIOS Integrity Measurement Guidelines

文档预览
中文文档 47 页 50 下载 1000 浏览 0 评论 0 收藏 3.0分
温馨提示:本文档共47页,可预览 3 页,如浏览全部内容或当前文档出现乱码,可开通会员下载原始文档
NIST.SP.800-155_Dec2011 draft BIOS Integrity Measurement Guidelines 第 1 页 NIST.SP.800-155_Dec2011 draft BIOS Integrity Measurement Guidelines 第 2 页 NIST.SP.800-155_Dec2011 draft BIOS Integrity Measurement Guidelines 第 3 页
下载文档到电脑,方便使用
本文档由 思安 于 2022-12-05 09:07:28上传分享
友情链接
站内资源均来自网友分享或网络收集整理,若无意中侵犯到您的权利,敬请联系我们微信(点击查看客服),我们将及时删除相关资源。