| |

Advanced Persistent Threats Panel

February 25, 2013, TCG Security Sessions, San Francisco—A panel considered the implications of advanced persistent threats (APT) with respect to the NIST 800-147 and -155 standards. Paul Roberts from The Security Ledger moderated the panel. Members were; Frank Molsberry from Dell, Stacy Cannady from Digital Management, Sunil Gottumukka from Microsoft, and Robert Thibadeau from Wave Systems.

APT challenges the relevance of TPM and connections?
Thibideau responded that APT have existed for a long time as Trojans and jailbreaks. Each has tried to tamper with the master boot record after the operating system starts. The NSA studies of the threat vectors show that successful attacks cause a total compromise of the OS and could even destroy the machine.

These attacks are similar to root and jailbreak of normal devices to enable other capabilities. TPM is designed to stop the feed forward of information through hardware to alert the systems that some aspects of the boot or OS are inconsistent.

Microsoft has a secure boot, boot locker, and can accept TPM?
Gottamukka agreed that the OS does a BIOS check to confirm integrity. The secure boot goes from the BIOS through a checker and to the OS, so no third party software is in the loop before the OS.

Weave into hardware and system?
Molsberry commented TPM is driving more users to use self-encrypting drives, and Windows 8 is much more secure. The industry is moving security into the process much earlier.

Secure BIOS, boot, hardware root of trust?
Cannady noted that the BIOS is the target. NIST -147 and -155 are guidance on best practices. In addition, NIST 800-164 calls out the hardware root of trust. Users can rely on their vendors to support all levels of security. Although CTIA and NIST differ on implementations, TPM can run firmware in the trust zone state.
Thibideau added all Nokia Windows phones use this technology.

Mobile devices are consumer-driven, and not IT, what is the need to define standards?
Molsberry disagreed that all mobile devices are driven by consumers. Many areas are related to government standards and other top-down standards.
Cannady appended that services depend upon policy definitions and implementations. Users need the software tools for analysis, but can ask for hardware security.
Gottamukka offered that Windows 8 has an OEM version that is default to prefer TPM. The secure boot function is a requirement in all Windows 8 platforms. TPM is required for RT and is an option for professional versions. All devices have data go through a bit blocker, but the existing TPM platforms need underlying policies to leverage the secure boot capabilities. Enterprise systems can take advantage of TPM in a smart card infrastructure, and TPM is provisioned automatically.

Measurements of TPM and “Orange book”?
Cannady answered that you can have a highly rated OS without TPM. With TPM, you can ensure a trusted state, as a part of the BIOS measures the system before allowing any further actions. The process compares any software with a golden standard for that device and performs predefined actions for a non-trusted device if the software and the standard don’t match. For example, at time of boot, the device can be allowed limited entry to the network, or can be allowed some functions after log-in.
Thibideau noted that TPM and the orange book are orthogonal. PCM 4 and 8 in the master boot record are target areas for and APT, so a check with hardware pre-boot can block access.

ARM trust zone checks for hardware intrusion, but doesn’t check for firmware?
Cannady suggested that TPM is in the servers. The TPM specification allows for software implementations and a secure operating state depends upon the underlying processor.
Thibideau added that a large number of servers have TPM built in, even virtualized servers. This condition has been around for many years.
Molsberry agreed that this level of security has been around for a while, and is now in ARM servers. The TPM increases the level of hardware security, but is a platform decision.

Users care about trust of apps?
Cannady offered that this is an operational state, a secure state that isn’t readily apparent to the user. Freescale depends upon the principle of trusted bot to verify the state of the system, but not a complete TPM. Apps have to meet the TCG mobile specifications for a software TPM and startup after the hardware has verified that the software is ok.

The technology exists to reduce risk, but is not used. Third party software without TPM?
Thibideau commented that all iPhones can encrypt all user data with a PIN. This encryption is part of the long-term storage policy and is part of the OPAL standard. Other competitors are following Apple’s lead and moving towards an industry standard. Often an industry starts with proprietary standards and moves towards a general one.
Molsberry added that the TCP specification starts off in an opt-in mode. Future version so of the standard will call for auto-provisioning and other options like opt-out and management tools will be addressed.
Gottamukka OFFERED THAT Windows technology makes TCP easy to use. Bit locker is getting more user friendly.

Export to countries violate the hardware encryption regulations?
Molsberry responded that TCG is working on this issue with various government contacts. In general, these issues need to go through the company’s export compliance group to ensure compliance.
Thibideau added that TPM 2.0 is designed for security

Similar Posts