CPC G06F 21/575 (2013.01) [G06F 12/0875 (2013.01); G06F 21/54 (2013.01); G06F 21/64 (2013.01); G06F 2221/034 (2013.01)] | 15 Claims |
1. A method comprising:
detecting, during booting of a computing device having Unified Extensible Firmware Interface (UEFI), execution of a driver associated with a hardware component of the computing device;
computing a first driver hash of a system table of the UEFI, wherein the system table is a data structure storing configuration details of the computing device and UEFI services;
detecting completion of the execution of the driver;
computing a second driver hash of the system table upon completion of the execution of the driver; and
comparing the first driver hash and the second driver hash to determine tampering with the system table of the UEFI.
|