| View previous topic :: View next topic |
| Author |
Message |
tgoldsmith
Newbie

Joined: Jun 19, 2006
Posts: 35
Location: UK
|
Posted: Thu Feb 21, 2008 4:38 pm Post subject: Cold Boot Attacks on Encryption Keys |
|
Hello folks, and especially those who are all about memory forensics.
I just noticed (ok, so it was on Slashdot) a paper from some Princeton students titled Cold Boot Attacks on Encryption Keys (http://citp.princeton.edu/memory/). I've had a brief look over the white paper and from what I've seen it's a well written and interesting paper. There have been a few papers about this sort of thing before, but it includes some nice experimental data and lots of references, which is what I like to see.
I'm not sure how practical spraying canned air or liquid nitrogen into laptops is (not that you need to do that) but the information on locating keys in memory and error correction is sound and very well researched.
Hope you also find it interesting.
Tom
|
|
| Back to top |
|
 |
hogfly
Senior Member

Joined: Oct 06, 2004
Posts: 288
Location: New York
|
Posted: Thu Feb 21, 2008 4:53 pm Post subject: Re: Cold Boot Attacks on Encryption Keys |
|
Wow that's some great research and it's extremely comprehensive. It would be great if they'd release some code.
|
|
| Back to top |
|
 |
jemartin
Newbie

Joined: Jan 28, 2008
Posts: 16
Location: Nebraska
|
Posted: Thu Feb 21, 2008 5:08 pm Post subject: Re: Cold Boot Attacks on Encryption Keys |
|
Hmmm, wonder how much a case of compressed air is?
We've got WDE running on some test laptops. This could be interesting.
|
|
| Back to top |
|
 |
trewmte
Senior Member

Joined: Jan 25, 2007
Posts: 748
Location: UK
|
Posted: Thu Feb 21, 2008 5:27 pm Post subject: Re: Cold Boot Attacks on Encryption Keys |
|
Yes saw that as well....
Very informative video and supporting paper (.pdf published today 21/02/08) from Princeton University
1) Basically, switch off computer,
2) open cover to reveal RAM,
3) using a multipurpose duster spray (upsidedown) spray on RAM, will cool RAM to -50c
4) all RAM memory could remain for upto 10-mins after switch off computer using this method
4) extract physical RAM and insert into another reader
5) Use a reading app recovers all sorts of things
6) additional method shows recovery of encryption keys: Vista, TrueCrypt and Linux
I like the fact that they had also taken some trouble to identify why some RAM may not return positive results:
"If you don’t see any copies of the pattern, possible explanations include (1) you have ECC (error-correcting) RAM, which the BIOS clears at boot; (2) your BIOS clears RAM at boot for another reason (try disabling the memory test or enabling “Quick Boot” mode); (3) your RAM’s retention time is too short to be noticeable at normal temperatures. In any case, your computer might still be vulnerable — an attacker could cool the RAM so that the data takes longer to decay and/or transfer the memory modules to a computer that doesn’t clear RAM at boot and read them there."
|
|
| Back to top |
|
 |
pbeardmore
Senior Member

Joined: Oct 17, 2007
Posts: 147
Location: Surrey
|
Posted: Fri Feb 22, 2008 7:23 am Post subject: Re: Cold Boot Attacks on Encryption Keys |
|
check out the blog on their website for feedback (some more useful than others)
|
|
| Back to top |
|
 |
datacarver
Senior Member

Joined: Sep 16, 2007
Posts: 120
Location: Southeast, USA
|
Posted: Fri Feb 22, 2008 10:04 am Post subject: Re: Cold Boot Attacks on Encryption Keys |
|
I have not gotten a chance to read the research yet, but I've seen the video they put together. I guess the next question is...Has anyone other than these students successfully tested this process? And could we potential use this for computer forensic purposes?
Some issues I see are:
We could potential cause damage to the original machine by spraying the RAM chips and board with liquid nitrogen, and the process would not be repeatable, the data can not be verified, etc.
|
|
| Back to top |
|
 |
azrael
Senior Member

Joined: Nov 29, 2006
Posts: 472
Location: Faringdon, Oxfordshire, UK
|
Posted: Fri Feb 22, 2008 10:20 am Post subject: Re: Cold Boot Attacks on Encryption Keys |
|
Seems brilliant ... If we can cool chips remove them from a system and image them completely on another machine, there is a real possibility that we can get an exact image e.g. one that hasn't been altered in any way by forensic tools used to image memory ...
Memory dumps are allready non-repeatable so that bit would have little impact, so long as it can be shown to have been done properly ...
Issue :
Carrying around a thermos flask of liquid nitrogen along with your write blockers !
Computers are quite routinely run in supercooled environments, so I doubt that this would be likely to cause much damage. (See www.tomshardware.com/2...z_project/ as one example ... Or marginally less seriously totl.net/Eunuch/index.html [ ok this last one destroys the kit, but you get the point ])
So long as you steer clear of the disk, I don't see how we are likely to be worse off, even if the memory is made non-functional in the process ...
_________________ --
Azrael
-- |
|
| Back to top |
|
 |
hogfly
Senior Member

Joined: Oct 06, 2004
Posts: 288
Location: New York
|
Posted: Fri Feb 22, 2008 10:45 am Post subject: Re: Cold Boot Attacks on Encryption Keys |
|
I tend to think the PXE image idea is one of the more viable solutions that *could* be used in forensics. Unfortunately for us if something is protected by full disk encryption it's pretty much illegal to capture memory in the manner they are or by using the methods they suggest, especially given the current case involving this very thing.
|
|
| Back to top |
|
 |
trewmte
Senior Member

Joined: Jan 25, 2007
Posts: 748
Location: UK
|
Posted: Fri Feb 22, 2008 11:05 am Post subject: Re: Cold Boot Attacks on Encryption Keys |
|
I noted in the video that one of the screens there was "ram2usb"... I thought I could be on to something here, but didn't find anything searching Google...
_________________ Mobile Telephone Evidence & Forensics
trewmte.blogspot.com
Cell Site Analysis
cellsiteanalysis.blogspot.com
Last edited by trewmte on Fri Feb 22, 2008 1:45 pm; edited 1 time in total |
|
| Back to top |
|
 |
kovar
Senior Member

Joined: Sep 08, 2007
Posts: 625
Location: San Francisco, CA * Central Illinois
|
Posted: Fri Feb 22, 2008 11:06 am Post subject: Re: Cold Boot Attacks on Encryption Keys |
|
Greetings,
Here's another approach, through the Firewire port:
www.friendsglobal.com/...s%20XP.pdf
-David
_________________ CISSP, CCE, EnCE, Licensed Private Investigator (CA)
Last edited by kovar on Fri Feb 22, 2008 11:14 am; edited 1 time in total |
|
| Back to top |
|
 |
|