跳到主要导航 跳到搜索 跳到主要内容

Penetrating Machine Learning Servers via Exploiting BMC Vulnerability

  • Beijing Institute of Technology

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

With the recent significant advancements in machine learning fields, there has been an increasing focus on the data security and availability of servers, which serve as critical hardware infrastructure supporting AI computations. However, most existing security research has primarily focused on upper layers, attempting to defend against attacks from applications and operating system , thereby neglecting research in firmware and lower-level management modules. Nevertheless, these fields are crucial in constructing a comprehensive security chain. To analyze the security of lower-level management modules, this paper introduces a method for privilege escalation through vulnerabilities in the Baseboard Management Controller (BMC) of the server. The BMC is a critical component responsible for managing and monitoring the hardware of the server. This method allows for bypassing the Kernel Address Space Layout Randomization (KASLR) protection of the Linux kernel and implanting a backdoor into the host operating system, thereby gaining root access to the host. Through this method, we can access server memory data or execute malicious programs arbitrarily without physical contact, and reinstalling the system cannot overwrite the modifications made in the BMC. This poses a significant security threat to servers.

源语言英语
主期刊名Machine Learning for Cyber Security - 5th International Conference, ML4CS 2023, Proceedings
编辑Dan Dongseong Kim, Chao Chen
出版商Springer Science and Business Media Deutschland GmbH
163-172
页数10
ISBN(印刷版)9789819724574
DOI
出版状态已出版 - 2024
活动5th International Conference on Machine Learning for Cyber Security, ML4CS 2023 - Yanuca Island, 斐济
期限: 4 12月 20236 12月 2023

丛书

姓名Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
14541 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议5th International Conference on Machine Learning for Cyber Security, ML4CS 2023
国家/地区斐济
Yanuca Island
时期4/12/236/12/23

学术指纹

探究 'Penetrating Machine Learning Servers via Exploiting BMC Vulnerability' 的科研主题。它们共同构成独一无二的学术指纹。

引用此