硬體安全錯誤

電腦裡的硬體安全錯誤是指會產生漏洞硬體錯誤或是缺陷,這類漏洞會影響中央处理器(CPU)或是其他可以進行直接記憶體存取的裝置,因此可以在未經授權的情形下讀寫資料。安全分析師一般會將這類漏洞視為災難級的漏洞[1][2][3]

推測性執行弱點

從2017年開始,出現了一系列利用常見處理器架構中,推測性執行實現方式而有的安全弱點,這些弱點可以讓其他軟體有特權提昇的效果。

這類弱點包括

Intel VISA

研究者在2019年發現有一種稱為VISA的製造商除錯模式,在英特尔平台的Controller Hub上(大部份英特爾主機板會有的晶片組,其中有直接記憶體存取功能),可能會讓該主機板出現安全弱點[4]

相關條目

參考資料

  1. ^ Bruce Schneier. Spectre and Meltdown Attacks Against Microprocessors – Schneier on Security. www.schneier.com. January 5, 2018 [February 4, 2019]. Spectre and Meltdown are pretty catastrophic vulnerabilities, ... 
  2. ^ This Week in Security: Internet Meltdown Over Spectre of CPU Bug. Cylance.com. 2018-01-05 [February 4, 2019]. The security implications of the Meltdown and Spectre vulnerabilities are indeed catastrophic for systems engineering. 
  3. ^ Meltdown, Spectre: here's what you should know. Rudebaguette.com. January 8, 2018 [February 4, 2019]. [sic]: The effects of these vulnerabilities are catastrophic: « at best, the vulnerability can be used by malwares and hackers to exploit other security linked bugs. At worse, the flaw can be used by software and authentified users to read the kernel’s memory 
  4. ^ Lucian Armasu. Intel Chipsets' Undocumented Feature Can Help Hackers Steal Data. Tom's Hardware. 29 March 2019. 
Prefix: a b c d e f g h i j k l m n o p q r s t u v w x y z 0 1 2 3 4 5 6 7 8 9

Portal di Ensiklopedia Dunia

Kembali kehalaman sebelumnya