Vulnerabilities of computer systems – a threat to the information security of society

Authors

  • Cespedes Garcia N.V. https://orcid.org/0000-0002-9068-5837 , Институт проблем математических машин и систем НАН Украины, г. Киев, Украина
  • Cespedes Garcia P.D. https://orcid.org/0000-0001-6591-2199 , Институт проблем математических машин и систем НАН Украины, г. Киев, Украина

DOI:

https://doi.org/10.34121/1028-9763-2019-4-3–8

Keywords:

vulnerability of computer systems, information security, Intel ME, Intel AMT, Supermicro microchip, vulnerability Meltdown, Specter, ZombieLoad, вразливість комп'ютерних систем, інформаційна безпека, мікрочіп Supermicro, вразливість Meltdown, Spectre

Abstract

This article provides a description for a certain computer equipment components which allow remotely gain unauthorized access to computers. These components are Intel Management Engine (Intel ME) and Intel AMT. Intel ME is an independent subsystem included in almost all Intel processor chips since 2008. The chip is always connected to a power source, because the subsystem continues to work even when the computer is turned off. Vulnerabilities were discovered in Intel AMT, thereafter many computers using Intel processors became available for remote and local intruders. The article also describes Chinese microchips that have been implemented into Supermicro equipment. This equipment was supplied not only to US commercial organizations, but also to governmental. Supermicro Chinese microchips have the ability to edit the code stream that heads to the processor by inserting their own code, or else it can change the instructions order for the processor. The microchip can intercept communication security coding, as well as prevent the restoration of the security system as a whole. The article also provides an overview for recent sensational vulnerabilities Meltdown, Spectre and ZombieLoad in Intel and ARM processors that allows to manipulate a computer to one degree or another. These vulnerabilities are similar to each other, they allow a malicious application to read any type of computer memory, including kernel. It became feasible thanks to a speculative code execution system. Personal user data can be stolen, such as browser history, website content, passwords, or system data, such as disk encryption keys. Security experts should take into account the points above, as in certain cases this could possibly translate into a national scale problems, both financial and political.

References

1. Intel Management Engine. URL: https://ru.wikipedia.org/wiki/Intel_Management_Engine.

2. Большой взлом: как Китай проникал в американские сети через микрочип (Ч. 1). URL: https://telekritika.ua/smi/bolshoi-vzlom-kak-kitai-pronikal-v-amerikanskie-seti-cherez-mikrochip-chast-1/.

3. Большой взлом: как Китай проникал в американские сети через микрочип (Ч. 2). URL: https://telekritika.ua/smi/bolshoi-vzlom-kak-kitai-pronikal-v-amerikanskie-seti-cherez-mikrochip-chast-2/.

4. Apple признала уязвимость всех iPhone. URL: https://lenta.ru/news/2018/01/05/meltdown_spectre/.

5. Microsoft выпустила обновление Windows и убила компьютеры. URL: https://lenta.ru/news/2018/01/09/microsoft/.

6. Миллионы компьютеров с процессорами Intel оказались под угрозой. URL: https://lenta.ru/news/2019/05/15/intel//.

Downloads

Views: 43
Downloads: 9

Published

2019-12-01

How to Cite

Vulnerabilities of computer systems – a threat to the information security of society. (2019). Mathematical Machines and Systems, 4, 3–8. https://doi.org/10.34121/1028-9763-2019-4-3–8