Hidden in Plain Sight - Persistent Alternative Mass Storage Data Streams as a Means for Data Hiding With the Help of UEFI NVRAM and Implications for IT Forensics


연구 분야: Strategies



학회: IH&MMSec '22: Proceedings of the 2022 ACM Workshop on Information Hiding and Multimedia Security


초록

This article presents a first study on the possibility of hiding data using the UEFI NVRAM of today's computer systems as a storage channel. Embedding and extraction of executable data as well as media data are discussed and demonstrated as a proof of concept. This is successfully evaluated using 10 different systems. This paper further explores the implications of data hiding within UEFI NVRAM for computer forensic investigations and provides forensics measures to address this new challenge.


Author Profile
Stefan Kiltz

Otto-von-Guericke University Magdeburg Germany

Germany
Author Profile
Robert Altschaffel

Otto-von-Guericke University Magdeburg Germany

Germany
Author Profile
Jana Dittmann

Otto-von-Guericke University Magdeburg Germany

Germany

📄 논문 정보

발행 연도 2022년
인용수 2
출판 국가 Germany
사이트 ACM
좋아요 수 0

연관 논문 목록 (114건)