SoK: All You Ever Wanted to Know About Bootloader Security but Were Afraid to Ask
Connor Glosner, Aravind Machiry
摘要
Bootloaders are present in every device, from IoT and edge devices to datacenter servers, making them critical to system security. Modern platforms establish hardware root of trust via vendor-specific mechanisms such as CPU microcode and authenticated code modules before bootloader execution. This SoK focuses on the software boot chain that follows that hardware-rooted integrity handoff. Prior work has focused on subsets of bootloaders, often using inconsistent terminology, leaving gaps in understanding their structure and interactions.
We analyze 43 bootloaders and categorize them into three types based on their architecture and role in the boot process. We define attack surfaces for each type using our open-source dataset, BOOTBENCH, which includes 3,658 vulnerabilities and associated commits. Leveraging BOOTBENCH, we evaluate existing vulnerability detection techniques and highlight open problems, and examine limitations in defensive techniques for hardening bootloaders.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper21
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel 等USENIX Security 2017 · 被引用 324 次
- SoK: Understanding the Prevailing Security Vulnerabilities in TrustZone-assisted TEE SystemsDavid Cerdeira, Nuno Santos, Pedro Fonseca, Sandro PintoS&P 2020 · 被引用 231 次
- What You Corrupt Is Not What You Crash: Challenges in Fuzzing Embedded DevicesMarius Muench, Jan Stijohann, Frank Kargl, Aurélien Francillon 等NDSS 2018 · 被引用 202 次
- SoK: Sanitizing for SecurityDokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na 等S&P 2019 · 被引用 196 次
- PAC it up: Towards Pointer Integrity using ARM Pointer AuthenticationHans Liljestrand, Thomas Nyman, Kui Wang, Carlos Chinea Perez 等USENIX Security 2019 · 被引用 168 次
相关 Paper
- BootStomp: On the Security of Bootloaders in Mobile DevicesNilo Redini, Aravind Machiry, Dipanjan Das, Yanick Fratantonio 等USENIX Security 2017 · 被引用 66 次
- A Comprehensive Memory Safety Analysis of BootloadersJianqiang Wang, Meng Wang, Qinying Wang, Nils Langius 等NDSS 2025
- Anchors that Don't Lift: Understanding Supply Chain Driven Kernel Lock-In and Governance-Mediated Mitigation Strategies in SOHO DevicesRitwik Badola, Rajdeep Ghosh, Ashita Gupta, Chester Rebeiro 等USENIX Security 2026
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 被引用 428 次
- Hardware Trojans from Invisible Inversions: On the Trojanizability of Standard Cell LibrariesKolja Dorschel, René Walendy, Lukas Plätz, Thorben Moos 等S&P 2026
