Lune

S&P2026顶会

SoK: All You Ever Wanted to Know About Bootloader Security but Were Afraid to Ask

Connor Glosner, Aravind Machiry

2026年份

摘要

Bootloaders are present in every device, from IoT and edge devices to datacenter servers, making them critical to system security. Modern platforms establish hardware root of trust via vendor-specific mechanisms such as CPU microcode and authenticated code modules before bootloader execution. This SoK focuses on the software boot chain that follows that hardware-rooted integrity handoff. Prior work has focused on subsets of bootloaders, often using inconsistent terminology, leaving gaps in understanding their structure and interactions.

We analyze 43 bootloaders and categorize them into three types based on their architecture and role in the boot process. We define attack surfaces for each type using our open-source dataset, BOOTBENCH, which includes 3,658 vulnerabilities and associated commits. Leveraging BOOTBENCH, we evaluate existing vulnerability detection techniques and highlight open problems, and examine limitations in defensive techniques for hardening bootloaders.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext dbc0aa49-25ee-48d7-b782-e6d567b11bbe

它引用的顶会 Paper21

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖