today-0day
NotionGithubSiteContact
Korean
Korean
  • Introduction
    • ๐ŸšฉWindows Driver 0-day Research
    • ๐Ÿซ‚Team. ์šฐ๋ฆฌ ์˜ค๋Š˜๋ถ€ํ„ฐ 0-day
  • backgrounds
    • Windows Driver
    • Related Works
  • Our Approach
    • ๊ฐœ์š”
    • ๐Ÿ‡Init Analyzer
    • ๐Ÿ˜กangr-PT
    • ๐ŸฅŒMS Fuzzer
      • Playmaker mode
      • Qemu-nyx
      • Redqueen
      • Multiple Driver Tracing
      • Call Stack Parser
    • How to Use
  • Appendix
    • References
    • Achievments
    • ๐Ÿ”—Team page
    • ๐Ÿ”—CODE BLUE 2024
Powered by GitBook
On this page
  1. backgrounds

Windows Driver

๋“œ๋ผ์ด๋ฒ„๋Š” ์ปดํ“จํ„ฐ์˜ ์šด์˜ ์ฒด์ œ๊ฐ€ ํ•˜๋“œ์›จ์–ด ์žฅ์น˜์™€ ์ƒํ˜ธ ์ž‘์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•˜๋Š” ์†Œํ”„ํŠธ์›จ์–ด์ž…๋‹ˆ๋‹ค. ์ด๋ฅผ ์ด์šฉํ•˜์—ฌ ์ปค๋„ ๋ชจ๋“œ์—์„œ๋งŒ ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋Š” ์ž์›์„ ์‚ฌ์šฉํ•˜๊ฑฐ๋‚˜, ๋ช…๋ น์„ ๋‚ด๋ฆด ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ปค๋„ ๋“œ๋ผ์ด๋ฒ„์—๋Š” ๋Œ€ํ‘œ์ ์œผ๋กœ ๊ทธ๋ž˜ํ”ฝ ๋“œ๋ผ์ด๋ฒ„, ํ”„๋ฆฐํ„ฐ ๋“œ๋ผ์ด๋ฒ„ ๋“ฑ ์žฅ์น˜ ๋“œ๋ผ์ด๋ฒ„ ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ์šด์˜์ฒด์ œ๋ฅผ Low-level์—์„œ ๋ชจ๋‹ˆํ„ฐ๋งํ•ด์•ผ ํ•˜๋Š” ๋ณด์•ˆ ์†”๋ฃจ์…˜(EDR, Anti-Virus)์˜ ๋“œ๋ผ์ด๋ฒ„๋„ ํฌํ•จ๋ฉ๋‹ˆ๋‹ค.

์‹ค์ œ๋กœ ๋ณธ ํ”„๋กœ์ ํŠธ์—์„œ ๋ฐœ๊ฒฌํ•œ Kernel Driver๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๋ถ„์•ผ๋Š” ๋‹ค์Œ 5๊ฐ€์ง€์ž…๋‹ˆ๋‹ค.

  1. Anti-Virus Program

  2. Security Solution (Financial, Game, Document, ...)

  3. OT Program (interacts with PLCs, ...)

  4. Physical Device Control or Monitoring

  5. Driver Development Program

์ปค๋„ ๋“œ๋ผ์ด๋ฒ„๊ฐ€ ํ•„์š”ํ•œ ํ”„๋กœ๊ทธ๋žจ์„ ๊ฐœ๋ฐœํ•˜๋Š” ๋งŽ์€ Vendor๋“ค์€ ๋ณด์•ˆ์„ ๊ณ ๋ คํ•˜์ง€ ์•Š๊ณ , Microsoft๋Š” Vendor์— ์˜์กดํ•˜์—ฌ ๋“œ๋ผ์ด๋ฒ„์˜ ๋ณด์•ˆ์„ฑ์„ ๊ฒ€์ฆํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ๋‹ค์‹œ๋งํ•ด, Windwos Built-in Kernel Driver๊ฐ€ ์•„๋‹Œ 3rd party Kernel Driver๋Š” Kernel ์ˆ˜์ค€์—์„œ ์ค€์ˆ˜ํ•ด์•ผํ•˜๋Š” ๋†’์€ ๋ณด์•ˆ ์ˆ˜์ค€์„ ์ถฉ์กฑํ•˜์ง€ ๋ชปํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ด๋Ÿฌํ•œ ์ƒํ™ฉ์—์„œ Kernel Driver์—์„œ Bug๊ฐ€ ๋ฐœ์ƒํ•˜๊ฒŒ ๋˜๋ฉด ๋งˆ์น˜ Kernel ์ž์ฒด์— ์žˆ๋Š” ๋ฒ„๊ทธ์ฒ˜๋Ÿผ ์ „์ฒด OS์˜ ๋ฌด๊ฒฐ์„ฑ์„ ์†์ƒ์‹œํ‚ฌ ์ˆ˜ ์žˆ๊ธฐ ๋•Œ๋ฌธ์— Windows Kernel Driver์˜ ์ค‘์š”์„ฑ์€ ๋งค์šฐ ๋†’์Šต๋‹ˆ๋‹ค.

์ €ํฌ๋Š” ๋ถ„์•ผ๋ณ„๋กœ ํ”„๋กœ๊ทธ๋žจ์„ ์กฐ์‚ฌํ•˜์—ฌ 100๊ฐœ์˜ ๋ฒค๋”์‚ฌ๋ฅผ ๋Œ€์ƒ์œผ๋กœ 128๊ฐœ์˜ ํ”„๋กœ๊ทธ๋žจ์„ Target์œผ๋กœ ์„ ์ •ํ•˜์˜€์Šต๋‹ˆ๋‹ค. ์„ ์ • ๊ธฐ์ค€์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

  • CVE ๋ฐœ๊ธ‰ ์ด๋ ฅ์ด ์กด์žฌํ•  ๊ฒƒ

  • ์ทจ์•ฝ์ ์„ Handling ํ•  ์ˆ˜ ์žˆ๋Š” PSIRTํŒ€์ด ์กด์žฌํ•˜๊ฑฐ๋‚˜, ์ฐฝ๊ตฌ๊ฐ€ ์กด์žฌํ•  ๊ฒƒ

  • ๋ถ„์•ผ ๋ณ„ ์ตœ์†Œ 20์œ„ ์ด๋‚ด ๊ธฐ์—…์ผ ๊ฒƒ

  • ๊ตญ๋‚ด์™ธ ์˜ํ–ฅ๋ ฅ์„ ๊ณ ๋ ค

  • ๊ณต์‹ ๋ ฅ ์žˆ๋Š” ๊ธฐ๊ด€์ด ์ธ์ฆํ•œ ํ”„๋กœ๊ทธ๋žจ์ผ ๊ฒƒ

PreviousTeam. ์šฐ๋ฆฌ ์˜ค๋Š˜๋ถ€ํ„ฐ 0-dayNextRelated Works

Last updated 2 months ago