Page 580 - (ISC)² CISSP Certified Information Systems Security Professional Official Study Guide
P. 580

facilitate version updates. The process of updating the BIOS is known
               as “flashing the BIOS.”

               There have been a few examples of malicious code embedding itself

               into BIOS/firmware. There is also an attack known as phlashing, in
               which a malicious variation of official BIOS or firmware is installed
               that introduces remote control or other malicious features into a
               device.

               Since 2011, most system manufacturers have replaced the traditional
               BIOS system on their motherboards with Unified Extensible Firmware
               Interface (UEFI). UEFI is a more advanced interface between

               hardware and the operating system, which maintains support for
               legacy BIOS services.


               Device Firmware

               Many hardware devices, such as printers and modems, also need some
               limited processing power to complete their tasks while minimizing the
               burden placed on the operating system itself. In many cases, these
               “mini” operating systems are entirely contained in firmware chips

               onboard the devices they serve. As with a computer’s BIOS, device
               firmware is frequently stored on an EEPROM device so it can be
               updated as necessary.
   575   576   577   578   579   580   581   582   583   584   585