How Does Firmware Security Protect Enterprises?

464 views
•
March 5, 2019
by
RSAC Cybersecurity
YouTube video player
How Does Firmware Security Protect Enterprises?

TL;DR

Firmware security protects enterprises by exposing vulnerabilities, outdated components, tampering, and persistent malware beneath the operating system, where conventional software controls lack visibility. Eclypsium presents a platform for firmware risk assessment, patch management, supply chain verification, travel-related checks, and forensic analysis across laptops, servers, storage systems, network appliances, data centers, and cloud infrastructure.

Transcript

Defending the foundation of the enterprise, please welcome CEO and founder of Eclypsium, Yuriy Balygin. Hey. Welcome. Thank you. Thanks, appreciate it. Here we go. And Yuriy, your time begins now. Awesome. Hello. My name is Yuriy Balygin, and I'm the CEO and founder of Eclypsium. It's an honor to be here today. Uh, let me ask you this question. How... Read More

Key Insights

  • Firmware is a foundational software layer that governs how a device works beneath its operating system and applications. An implant placed at this level can subvert every layer above it and bypass security controls designed to operate only within conventional software environments.
  • Traditional security loses visibility and control at the firmware and hardware layers. These layers contain dozens of components and millions of lines of proprietary code, while vulnerabilities may remain unpatched for long periods and expose enterprises to persistent or disruptive attacks.
  • Firmware threats are no longer limited to highly customized, targeted operations. Malware campaigns discovered in the wild have infected firmware at scale, and commercial and open source toolkits now allow attackers to develop implants and exploits against this underlying device layer.
  • Eclypsium identifies outdated firmware, known vulnerabilities, and risky device configurations. The resulting visibility is intended to support enterprise risk mitigation and help patch management teams address weaknesses that conventional operating system and application security processes may not detect.
  • Supply chain verification is part of firmware security because a device may be tampered with before its first enterprise use. Eclypsium checks devices when they come out of the box and also examines laptops returning from travel for signs of compromise.
  • Persistent firmware malware is costly and difficult to eradicate or investigate. Eclypsium provides security and forensic teams with tools to discover and analyze firmware infections, including persistent threats such as the LoJax UEFI implant mentioned in the presentation.
  • Firmware risk affects both endpoints and infrastructure because proprietary firmware runs across laptops, storage devices, servers, switches, routers, and other network appliances. An average device has fifteen to twenty separate components that run proprietary firmware code.
  • Hardware vendor protections do not eliminate the need for independent security products. Vendors can enforce measures such as digital signing, but numerous manufacturers and firmware implementations create a fragmented environment that enterprises still need to assess, monitor, and manage centrally.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is enterprise firmware security?

Enterprise firmware security protects and monitors the software and hardware layers beneath operating systems and applications. These foundational layers govern how devices actually work, yet traditional security tools can lose visibility and control there. Effective protection includes finding outdated firmware, identifying vulnerabilities and unsafe configurations, detecting tampering, managing patches, and investigating persistent infections that bypass ordinary software security controls.

Q: Why can firmware attacks bypass traditional security controls?

Firmware attacks can bypass traditional controls because firmware operates beneath the operating system and applications where many conventional defenses run. An implant at this foundational level can subvert the layers above it while remaining outside their normal visibility. The problem is compounded by dozens of firmware components, millions of lines of proprietary code, and vulnerabilities that may remain unpatched for long periods.

Q: How does Eclypsium help protect enterprise devices?

Eclypsium provides visibility into device firmware and hardware so organizations can identify outdated firmware, vulnerabilities, dangerous configurations, and evidence of tampering. Its platform supports risk mitigation and patch management, verifies devices for supply chain interference, checks laptops after travel, and equips security and forensic teams to discover and analyze persistent firmware infections that conventional software controls may miss.

Q: How can organizations detect supply chain device tampering?

Organizations can examine a device when it comes out of the box for the first time to determine whether its firmware or hardware was altered before deployment. Eclypsium presents this verification as part of its platform. The same inspection approach can be applied when laptops return from travel, helping security teams look for compromises introduced outside the organization’s controlled environment.

Q: Which enterprise devices face firmware security risks?

Firmware risk applies to devices throughout an enterprise, not only employee laptops. The presentation identifies storage devices, servers, network appliances, switches, routers, data center systems, and infrastructure running in the cloud as exposed environments. Each device has, on average, fifteen to twenty components running proprietary firmware, which makes the issue equally important for endpoints and centralized infrastructure.

Q: Why are firmware threats considered a current concern?

Firmware threats are a current concern because attackers have advanced beyond highly customized and narrowly targeted operations. Malware campaigns discovered in the wild have infected firmware at scale for persistence and disruption. Commercial and open source toolkits are also available that let attackers create firmware implants and exploits, making attacks on underlying device layers more broadly accessible than before.

Q: Why is persistent firmware malware difficult to remove?

Persistent firmware malware is difficult to eradicate and investigate because it resides beneath the operating system and can evade software-focused security controls. The presentation identifies the LoJax UEFI implant as an example of malware whose persistence can make response costly. Security and forensic teams therefore need specialized visibility and analysis tools that can inspect firmware rather than relying only on higher-level defenses.

Q: Do vendor firmware protections remove the need for Eclypsium?

Vendor protections do not remove the stated need for an independent enterprise security layer. Hardware manufacturers are interested in measures such as digital signing and improved manageability, but enterprises use devices and firmware from many vendors. Eclypsium aims to consolidate manufacturer techniques and independent capabilities into one solution for vulnerability discovery, patching, and detection of firmware or hardware tampering.

Summary & Key Takeaways

  • Enterprise devices contain a foundational firmware and hardware layer beneath their visible software. Because this layer governs how devices operate, a malicious implant can subvert higher layers and bypass software security controls. Proprietary firmware, delayed patching, and limited visibility make this underlying attack surface difficult for traditional security products to monitor and control.

  • Eclypsium identifies outdated firmware, vulnerabilities, unsafe device configurations, and evidence of firmware or hardware tampering. Its platform supports risk mitigation and patch management, checks devices for supply chain interference, examines laptops after travel, and gives security and forensic teams tools to discover and analyze persistent infections such as the LoJax UEFI implant.

  • Firmware exposure affects endpoints, servers, storage devices, switches, routers, network appliances, data centers, and cloud infrastructure. Bulygin argues that the threat is already mainstream because commercial and open source toolkits can help attackers create firmware implants and exploits. Manufacturer security features remain useful, but independent enterprise-wide visibility is still necessary.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚