Although UEFI (Unified Extensible Firmware Interface) security has been a major issue in recent years, so far, due to various limitations, the detection of malware that threatens it is limited to a very small number of cases.
After detecting the first UEFI rootkit in the wild, known as LoJax, ESET experts wanted to create a system that would allow them to explore the vast UEFI domain and discover emerging and unknown threats in a reliable and efficient manner.
Malware like LoJax – there are millions of UEFI executables in the wild, and only a small percentage of them are malicious. “In the last two years alone, we have discovered over 2.5 million unique UEFI executables, out of a total of 6 billion,” explains Filip Mazán, ESET software engineer responsible for developing the machine learning system.
Based on telemetry data collected by ESET's UEFI scanner, machine learning experts in collaboration with the company's malware researchers designed a customized data processing system for UEFI executables, which detects unusual elements in incoming samples, with the help of machine learning.
“To reduce the number of samples that require human attention, we decided to develop a system that, by detecting unusual characteristics in UEFI executables, brings to the surface samples with atypical behavior,” says Mazán.
To test the feasibility of this method, the researchers tested the resulting system on known suspicious and malicious UEFI executables that had not previously been included in the dataset – most notably the LoJax UEFI driver. The system concluded that the LoJax driver differed in an unprecedented way.
“This successful test provides a level of confidence that, if a similar threat were to appear in UEFI, we would be able to recognize it as unusual, analyze it immediately, and create an appropriate detection system,” Mazán comments.
This machine learning-based approach, in addition to its powerful capabilities in detecting suspicious UEFI executables, has also been found to reduce the workload of ESET analysts by 90% (compared to analyzing every incoming sample).
As each new incoming UEFI executable is added to the dataset, processed, recalibrated, and taken into account for subsequent incoming samples, the solution offers real-time UEFI monitoring.
Using this system to detect UEFI threats, ESET researchers discovered many interesting UEFI elements that can be divided into two categories – UEFI firmware backdoors and OS-level persistence modules.
“Although the UEFI executable file processing system has not yet led to the discovery of new malware, the results it has achieved so far are encouraging,” says Jean-Ian Boutin, senior malware researcher at ESET.
The most notable finding is the ASUS backdoor: a UEFI firmware backdoor found in various ASUS laptop models, which was patched by ASUS after ESET updated it.
More information about this ESET research can be found in the blog post “Needles in a haystack: Picking unwanted UEFI components out of millions of samples” on WeLiveSecurity.com.
_______________________
- Windows 7: support only for 99 days
- Health apps steal user data
- Dona Sarkar leaves Insiders: Microsoft's bet
