3.1CRJun 25
SoK: Security Below the OS -- A Security Analysis of UEFIPriyanka Prakash Surve, Oleg Brodt, Mark Yampolskiy et al.
The Unified Extensible Firmware Interface (UEFI) is a linchpin of modern computing systems, governing secure system initialization and booting. This paper is urgently needed because of the surge in UEFI-related attacks and vulnerabilities in recent years. Motivated by this urgent concern, we undertake an extensive exploration of the UEFI landscape, dissecting its distribution supply chain, booting process, and security features. We carefully study a spectrum of UEFI-targeted attacks and proofs of concept (PoCs) for exploiting UEFI-related vulnerabilities. Building upon these insights, we construct a comprehensive attack threat model encompassing threat actors, attack vectors, attack types, vulnerabilities, attack capabilities, and attacker objectives. Drawing inspiration from the MITRE ATT&CK framework, we present a MITRE ATT&CK-like taxonomy delineating tactics, techniques, and sub-techniques in the context of UEFI attacks. This taxonomy can provide a road map for identifying existing gaps and developing new techniques for rootkit prevention, detection, and removal. Finally, the paper discusses existing countermeasures against UEFI attacks including a variety of technical and operational measures that can be implemented to lower the risk of UEFI attacks to an acceptable level. This paper seeks to clarify the complexities of UEFI and equip the cybersecurity community with the necessary knowledge to strengthen the security of this critical component against a growing threat landscape.
8.1ROJun 19
RogueRover: Autonomous Rogue Device Localization for Incident ResponsePriyanka Prakash Surve, Asaf Shabtai, Yuval Elovici
Physically localizing unauthorized wireless devices remains a critical bottleneck in cyber-physical security operations, where rogue access points can provide entry points for lateral movement and persistent compromise. While such devices can often be detected through network-side mechanisms, determining their physical location typically requires dense sensing infrastructure, site-specific RF fingerprinting, or manual inspection, limiting timely incident response. We investigate whether a single commodity robot can autonomously detect and localize rogue wireless devices under zero-configuration constraints, without RF fingerprinting, pre-installed sensors, or site calibration. We present RogueRover, an end-to-end system in which a quadruped robot autonomously patrols, collects spatially labeled RSSI measurements via a standard 802.11 interface, and estimates device locations offline. We evaluate the system across 11 patrol runs in a real indoor environment, with 6 rogue devices deployed under heterogeneous propagation conditions. Across 62 AP-patrol sessions, RogueRover achieves a median single-patrol localization error of 1.62 m without prior RF knowledge. Under multi-run aggregation, five of six devices are localized within 1 m. A blind trial validates the full pipeline, correctly identifying rogue devices among 73 observed BSSIDs and localizing them with errors of 0.34 m and 1.84 m. Across environments, simple weighted-centroid estimators perform comparably to, or better than, parametric path-loss models, indicating that measurement coverage from autonomous patrols is the primary determinant of localization accuracy under zero-prior constraints. Our results demonstrate that infrastructure-free, autonomous localization is feasible in practice, enabling rapid physical incident response in cyber-physical environments without additional sensing infrastructure.
5.2CYJun 19
CEDAR-42001: From ISO/IEC 42001 Conformity to Architecture-Aware, Audit-Visible Assurance Posture for AI Cyber-Physical SystemsPriyanka Prakash Surve, Asaf Shabtai, Yuval Elovici
AI-enabled cyber-physical systems (AI-CPS) turn data-driven decisions into physical actions, creating assurance challenges across sensing, computation, control, human oversight, and governance. ISO/IEC 42001:2023 specifies requirements for an artificial intelligence management system (AIMS), but conformity assessment alone does not show which architectural layers are affected, whether practices are mature enough for the risk context, or what actions should follow. We present CEDAR-42001 (Control-Evidence Decision and Action Reasoning), a two-stage method that converts ISO/IEC 42001 audit evidence into an architecture-aware assurance posture traceable to the audit record. Stage A preserves the conformity determination. Stage B adds four outputs to each audit row: (i) attribution to a governance stratum or one of seven AI-CPS layers; (ii) a five-dimensional maturity profile with binding-constraint identification; (iii) a risk-proportionate target maturity; and (iv) a rulebook-derived action recommendation. The enriched rows are aggregated into strategic, operational, and tactical decision products. We evaluate CEDAR-42001 using a synthetic autonomous-fleet AIMS and by comparing conformity-only results with the enriched outputs. Although 89.9 percent of audit rows were conforming, only 34.3 percent of conforming rows reached the baseline High-assurance category; across alternative operationalizations, this proportion ranged from 22.4 percent to 46.2 percent. A retrospective application to the 2023 Cruise robotaxi incident shows how the method captures documented concerns across governance, perception, decision-making, and human oversight and maps them to layer-specific actions. CEDAR-42001 does not estimate exploitability or replace technical CPS-security testing; it identifies where audit evidence warrants deeper technical assurance, organizational improvement, or remediation.