메뉴
BL
Ars Technica 42일 전

윈도우 및 리눅스 보안 부팅 키 업데이트 임박

IMP
8/10
핵심 요약

운영체제보다 먼저 실행되는 악성코드인 부트킷(Bootkit)으로부터 시스템을 보호하는 '보안 부팅(Secure Boot)' 인증서가 오는 6월 24일 만료됩니다. 이 인증서가 만료되면 시스템 보안에 취약해질 수 있으므로, 사용자는 만료 전에 암호화 키를 반드시 업데이트해야 합니다.

번역된 본문

윈도우 및 리눅스 사용자가 운영체제(OS)와 악성코드 방지 프로그램이 시작되기 전에 로드되는 악성코드인 UEFI 기반 펌웨어 감염으로부터 시스템을 보호하기 위해 암호화 키를 업데이트해야 하는 마감일이 다가오고 있습니다. 6월 24일부터 시스템 부팅 중에 로드되는 각 펌웨어와 소프트웨어를 암호학적으로 검증하는 세 개의 인증서가 만료될 예정입니다. 마이크로소프트가 서명한 이 인증서들은 마이크로소프트가 설계한 신뢰 체인인 '보안 부팅(Secure Boot)'의 핵심 요소입니다. 보안 부팅은 시스템 시작 중에 로드되는 모든 코드의 디지털 서명을 확인하여, 해당 코드가 시스템이 실행되는 메인보드 제조사와 같은 신뢰할 수 있는 공급자로부터 제공된 것인지 보장합니다. 보안 부팅은 초기 부팅 과정 중에 펌웨어 및 소프트웨어 로드를 담당하는 시스템을 변조하는 악성코드 형태인 부트킷(Bootkit)을 방해하도록 설계되었습니다. 부트킷은 운영체제와 대부분의 다른 코드보다 먼저 로드되기 때문에 탐지하기가 매우 어려울 수 있습니다. 일단 설치되면, 일반적으로 자격 증명을 탈취하거나 시스템에 백도어를 만들거나 기타 악의적인 행동을 수행하는 악성코드를 운영체제에 로드합니다. 운영체제에서 악성코드를 제거하더라도 부트킷은 시스템을 다시 감염시킬 수 있습니다. 부트킷은 운영체제 재설치 시에도 살아남습니다.

부트킷의 짧은 역사 부트킷의 기원은 1980년대 초반으로 거슬러 올라가며, 당시 부팅 과정 중인 애플 II(Apple II) 기기를 표적으로 하는 여러 악성코드가 만들어졌습니다. 이들은 표면적으로 불법 복제된 게임이 들어있는 플로피 디스크를 통해 실제 널리 퍼졌습니다. 윈도우 부트킷은 2000년대 초 공격적 보안 연구원들이 개발한 개념 증명(PoC)으로 주목을 받았습니다. 2005년 블랙햇(Black Hat) 보안 컨퍼런스에서 시연된 부트킷인 BootRoot는 최초의 사례일 가능성이 높습니다. 이 악성코드는 네트워크 드라이버 인터페이스를 감염시켰는데, 이는 TCP/IP 네트워크 어댑터 드라이버와 같은 서비스를 가능하게 하는 네트워크 프로토콜 드라이버 간의 통신을 간소화했습니다. 이후 몇 년 동안 비슷한 개념 증명(PoC)으로는 Vbootkit, Stoned Bootkit 및 Mebroot가 있었습니다. 그 외에도 훨씬 더 많았습니다. 2012년에는 새로운 형태의 부트킷이 시연되었습니다. BIOS나 마스터 부트 레코드(MBR)를 통해 기기를 표적으로 하는 대신, 이러한 부트킷 중 하나는 부팅 과정을 시작하는 펌웨어 패키지인 EFI를 감염시켜 Mac OS X 시스템을 공격했습니다. 두 번째로 매우 원시적인 부트킷은 UEFI 부트킷(UEFI의 전신)을 감염시켜 윈도우 8 기기를 표적으로 삼았습니다. 2013년경, 한 연구원은 Dreamboat라는 윈도우용 고급 UEFI 부트킷을 시연했습니다. UEFI를 표적으로 한 실제 공격의 첫 번째 알려진 사례는 LoJax라는 악성코드가 발견된 2018년에 등장했습니다. LoJack으로 알려진 합법적인 도난 방지 소프트웨어를 변형한 이 악성코드는 Sednit, Fancy Bear, APT 28 등의 이름으로 추적되는 러시아 정부 지원 해커 그룹에 의해 만들어졌습니다. 이 악성코드는 UEFI 펌웨어의 플래시 메모리 부분을 읽고 덮어쓸 수 있는 악성코드 도구를 사용하여 원격으로 설치되었습니다. 2020년, 연구원들은 UEFI를 공격하는 것으로 알려진 두 번째 실제 악성코드 사례를 발견했습니다. 감염된 장치가 재부팅될 때마다 해당 UEFI는 윈도우 시작 폴더에 악성 파일이 있는지 확인하고, 없으면 이를 설치했습니다. 악성코드를 발견한 보안 업체 카스퍼스키(Kaspersky)의 연구원들은 이를 "MosaicRegressor"라고 명명했습니다. 연구원들은 아직도 해킹된 UEFI가 어떻게 감염되었는지 결정하지 못했습니다. 그 이후로 몇 가지 새로운 UEFI 부트킷이 밝혀졌습니다. 이들은 ESpecter, FinSpy 및 MoonBounce와 같은 이름으로 추적되고 있습니다.

필요는 발명의 어머니이다 이러한 위협에 대응하여 마이크로소프트는 기기 제조업체들과 협력하여 암호화 서명을 사용하여 시작 중에 로드되는 각 소프트웨어가 컴퓨터 제조업체에 의해 신뢰할 수 있는지 확인하는 업계 표준인 보안 부팅(Secure Boot)을 개발했습니다. 보안 부팅은 공격자가 의도된 부팅을 교체하는 것을 방지하는 신뢰 체인을 구축하도록 설계되었습니다.

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav The clock is ticking for Windows and Linux users to update cryptographic keys that protect their systems against firmware-based UEFI infections, a pernicious form of malware that loads before operating system and anti-malware protections start. Beginning June 24, three certificates that cryptographically verify that each piece of firmware and software that loads during system boot will expire. The Microsoft-signed certificates are the linchpins of Secure Boot, a Microsoft-designed chain of trust. Secure Boot checks the digital signatures of all code that loads during system startup to ensure it originates from a trusted provider, such as the manufacturer of the motherboard the system runs on. Secure Boot is designed to thwart bootkits, a form of malware that alters the systems responsible for loading firmware and software during the initial boot sequence. Because bootkits load before the OS and most other code, they can be difficult to detect. Once installed, they typically load malware onto the OS that steals credentials, backdoors the system, or performs other malicious actions. Even when the OS is disinfected, the bootkit can reinfect the system. Bootkits survive OS reinstallations as well. A brief history of bootkits The genesis of bootkits dates back to the early 1980s with the creation of several pieces of malware that targeted Apple II machines during the boot process. They spread in the wild through floppy disks that ostensibly contained pirated games. Windows bootkits gained notice in the early 2000s as proofs of concept developed by researchers of offensive security. BootRoot, a bootkit demonstrated at the 2005 Black Hat security conference, is likely the first such instance. The malware infected the Network Driver Interface, which streamlined communications between network protocol drivers enabling service such as TCP/IP network adapter drivers. In the years following, similar PoCs included Vbootkit , the Stoned Bootkit , and Mebroot . There were many more. In 2012, a new form of bootkit was demonstrated. Instead of targeting machines through the BIOS or master boot record, one such bootkit attacked Mac OS X systems by infecting the EFI, a package of firmware that started the boot process. A second very primitive bootkit targeted Windows 8 machines by infecting the​​ UEFI bootkit , the predecessor to the UEFI. Around 2013, a researcher demonstrated a more advanced UEFI bootkit for Windows named Dreamboat . The first known case of a real-world attack targeting the UEFI came in 2018 with the discovery of malware dubbed LoJax . A repurposed version of legitimate anti-theft software known as LoJack, it was created by the Kremlin-backed hacking group tracked under names including Sednit, Fancy Bear, and APT 28. The malware was installed remotely using malware tools that can read and overwrite parts of the UEFI firmware’s flash memory. In 2020, researchers unearthed the second known instance of real-world malware attacking the UEFI. Each time an infected device rebooted, its UEFI checked whether a malicious file was present in the Windows startup folder and, if not, installed it. Researchers from Kaspersky, the security provider that discovered the malware, named it “ MosaicRegressor .” Researchers have yet to determine how the compromised UEFIs became infected. Since then, a handful of new UEFI bootkits have come to light. They are tracked under names including ESpecter, FinSpy, and MoonBounce. Necessity is the mother of invention In response to the threats, Microsoft worked with device makers to develop Secure Boot, an industry-wide standard that uses cryptographic signatures to ensure that each piece of software loaded during startup is trusted by a computer’s manufacturer. Secure Boot is designed to create a chain of trust that prevents attackers from replacing the intended bootup firmware with malicious firmware. If a single link in the startup chain isn’t recognized, Secure Boot will prevent the device from starting. Then in 2023, researchers discovered LogoFail , a series of critical vulnerabilities found UEFIs booting up just about every Windows and Linux system in the world. An image-parsing bug in the software that presented hardware manufacturers’ logos during bootup allowed attackers to bypass Secure Boot and infect the UEFI with malicious firmware. The discovery of LogoFail requires Microsoft to replace the existing cryptographic signatures underpinning Secure Boot with new ones. Three older signatures, which are dated 2011, are being removed. In their place are ones dated 2023. Microsoft is in the process of updating Windows 10 and Windows 11 machines. Linux distributors are also in the process of updating “shims,” a small, first-stage UEFI bootloader that acts as a trusted bridge between Secure Boot keys and the Linux bootloader. Machines that fail to update the Secure Boot-related keys will continue to function, but they will no longer be protected against new UEFI threats. To be clear, they were already vulnerable to new UEFI threats that exploited the industry-wide LogoFail vulnerability. The key refresh is designed to mitigate that risk and prevent unrelated UEFI attacks that may arise in the future. To check the status of the keys on Windows machines, users can open Windows Security settings > Device Security > Secure Boot. A green checkmark means the update has been completed. Most Windows machines automatically update the keys during regular monthly patch distributions, but older machines may require manual attention. Linux users should watch for the release of new shims. If at all possible, users should hold off on installing new motherboard firmware updates until after the new certificates are replaced. Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 12 Comments