Skip to content
This repository has been archived by the owner on Oct 2, 2024. It is now read-only.

look into retreiving bios information from a system #91

Open
djhaynes opened this issue Aug 19, 2013 · 2 comments
Open

look into retreiving bios information from a system #91

djhaynes opened this issue Aug 19, 2013 · 2 comments

Comments

@djhaynes
Copy link
Contributor

We should look into retreiving BIOS information from a system with OVAL. NIST
has a draft spec on BIOS measurement that we should take a look at.

http://csrc.nist.gov/publications/drafts/800-155/draft-SP800-155_Dec2011.pdf

It also looks like DTMF CIM has a spec on BIOS. I am not sure if there is any
overlap, but, it is probably worth checking out as well.

http://www.dmtf.org/standards/search?keys=bios&dsp=&tid=All

@djhaynes
Copy link
Contributor Author

It looks like we can retrieve bios information on Windows systems with WMI.

http://msdn.microsoft.com/en-us/library/windows/desktop/aa394077(v=vs.85).aspx

@LuisNunez
Copy link
Contributor

Additional related items to this tracker.
Topic on the OVAL Developers list related to OVAL firmware checks.
http://making-security-measurable.1364806.n2.nabble.com/OVAL-firmware-was-Device-Unique-Identifiers-td7580741.html

NIST 800-147 BIOS Protection Guidelines http://csrc.nist.gov/publications/nistpubs/800-147/NIST-SP800-147-April2011.pdf

MITRE research into the topic. Host-based Security: BIOS Chronomancy - http://www.mitre.org/capabilities/cybersecurity/overview/cybersecurity-blog/host-based-security-bios-chronomancy

MITRE research tool on BIOS. Copernicus: Question Your Assumptions about BIOS security - http://www.mitre.org/capabilities/cybersecurity/overview/cybersecurity-blog/copernicus-question-your-assumptions-about

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants