UEFI firmware vulnerability intelligent identification method based on deep learning large model
Through the intelligent identification method based on deep learning large models, the problems of low efficiency and poor adaptability of UEFI firmware vulnerability detection are solved, and efficient and accurate vulnerability detection and highly adaptable security protection are achieved.
Patent Information
- Application Number
- CN202411927940.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-25
- Publication Date
- 2025-05-06
AI Technical Summary
The prior art is inefficient in UEFI firmware vulnerability detection, it is difficult to cover all vulnerability types, and it is difficult to adapt to the problem of rapid update and iteration of firmware.
The intelligent recognition method based on deep learning large models is adopted, and efficient detection of UEFI firmware vulnerabilities is achieved through steps such as data set construction, deep learning model training and optimization, and intelligent recognition.
It improves detection efficiency and accuracy, is highly adaptable, can promptly detect and repair vulnerabilities in the firmware, and improves the security protection capabilities of the computer system.
Smart Images

Figure CN119939594A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computers, and in particular to an intelligent identification method for UEFI firmware vulnerabilities based on a deep learning large model. Background Art
[0002] With the rapid development of computer technology, the security and stability of Unified Extensible Firmware Interface (UEFI) as the boot and runtime firmware standard of modern computer systems have become particularly important. UEFI firmware is not only responsible for system initialization, hardware configuration, and boot loader management, but also involves key functions such as secure boot and firmware update, so it has become one of the key targets of hacker attacks. In recent years, vulnerability exploits against UEFI firmware have occurred frequently, such as advanced persistent threats such as Bootkit and Rootkit, which seriously threaten user data security and system integrity.
[0003] Traditional UEFI firmware vulnerability detection methods mainly rely on manual auditing, rule matching, and static analysis tools, but these methods are inefficient, difficult to cover all vulnerability types, and difficult to adapt to the rapid update and iteration of firmware. Manual auditing requires a high degree of expertise and a lot of time, and is prone to missing potential vulnerabilities; rule matching is limited to known vulnerability patterns and is difficult to discover new vulnerabilities; although static analysis tools can automatically analyze firmware code, their accuracy and coverage are still limited by the perfection of the analysis algorithm and rule library.
[0004] With the rise of artificial intelligence and deep learning technologies, it has become possible to apply these technologies to UEFI firmware vulnerability detection. With its powerful feature extraction and pattern recognition capabilities, deep learning large models can automatically learn vulnerability features and patterns from a large number of firmware samples, thereby achieving efficient and accurate vulnerability detection. However, applying deep learning to UEFI firmware vulnerability detection faces many challenges, such as the acquisition and preprocessing of firmware samples, the design of model architecture, and the selection of training and optimization strategies. Summary of the invention
[0005] The purpose of the present invention is to overcome the shortcomings of the prior art and provide a method for intelligently identifying UEFI firmware vulnerabilities based on a deep learning large model, comprising the following steps:
[0006] Dataset construction: Collect UEFI firmware samples of operating systems and hardware platforms; Preprocess the collected UEFI firmware samples, including binary file parsing and feature extraction, to build a UEFI firmware dataset for model training; Use data enhancement technology to transform and expand the original data;
[0007] Build a deep learning model, using convolutional neural network as the basic architecture and combining it with long short-term memory network to process sequence data to obtain a deep learning-based large model;
[0008] Model training and optimization: training the large model through the constructed UEFI firmware data set to obtain a trained deep learning large model;
[0009] Intelligent identification deploys the trained large model into the UEFI firmware vulnerability detection system. When the system receives a new UEFI firmware, it automatically extracts the key features of the firmware and inputs them into the model. The model identifies the firmware based on the learned vulnerability pattern and outputs the result of whether there is a vulnerability.
[0010] Furthermore, the UEFI firmware samples of the operating system and hardware platform are collected; the collected UEFI firmware samples are preprocessed, including binary file parsing and feature extraction, to construct a UEFI firmware dataset for model training; and the original data is transformed and expanded using data enhancement technology, including:
[0011] Collect UEFI firmware samples on various operating systems and hardware platforms from multiple sources, perform binary analysis on the collected UEFI firmware samples, and use static analysis tools to extract functions, variables, control flows, byte sequences, strings, and hash values in the firmware; apply enhancement techniques such as random cropping, rotation, flipping, adding noise, and simulated mutation to transform and expand the original data to simulate different firmware variants and vulnerability modes; the multiple sources mentioned include manufacturer official websites, open source communities, and security research institutions.
[0012] Furthermore, the deep learning big model is constructed based on the convolutional neural network as the basic architecture, and the long short-term memory network is combined to process the sequence data to obtain a big model based on deep learning, including:
[0013] A deep convolutional neural network is selected as the backbone network for feature extraction, and a long short-term memory network (LSTM) is combined to process the sequence data in the firmware. In terms of multi-scale feature fusion, a feature pyramid network is used to fuse features at different levels. In terms of attention mechanism, a cross-attention mechanism is introduced to dynamically focus on key areas and vulnerability patterns in the firmware.
[0014] Furthermore, the large model is trained by using the constructed UEFI firmware data set to obtain a trained deep learning large model, including:
[0015] The preprocessed data set is divided into training set, validation set and test set according to the set ratio; when initializing the model parameters, the Xavier initialization method or the He initialization method is used, and the pre-trained weights are loaded to accelerate the training process;
[0016] Select Adam optimizer, set dynamic learning rate adjustment strategy, use batch normalization and residual connection to reduce gradient vanishing and explosion problems; apply regularization and Dropout technology to prevent overfitting; evaluate the accuracy, recall rate, and F1 score of the model on the validation set, adjust the hyperparameters through grid search, obtain the optimal model configuration, and obtain the trained deep learning large model.
[0017] Furthermore, it also includes a continuous learning mechanism to incrementally update or retrain the model by regularly collecting new firmware samples and vulnerability information.
[0018] The beneficial effects of the present invention are: improving detection efficiency: through the automated feature extraction and pattern recognition capabilities of the deep learning large model, efficient detection of UEFI firmware vulnerabilities is achieved. Compared with manual auditing and rule matching methods, the detection time is greatly shortened and the detection efficiency is improved.
[0019] Enhanced detection accuracy: The deep learning model can learn the characteristics and patterns of vulnerabilities from a large number of firmware samples, and has a strong ability to identify new vulnerabilities and variant vulnerabilities. Compared with static analysis tools, it improves the accuracy and coverage of detection.
[0020] Strong adaptability: By building a large-scale UEFI firmware dataset and using data enhancement technology, the model can adapt to UEFI firmware of different operating systems and hardware platforms, as well as the ever-changing vulnerability patterns. At the same time, the continuous learning mechanism ensures that the model can keep up with new trends in firmware security and vulnerability development.
[0021] Improve security protection capability: Applying the present invention to the UEFI firmware vulnerability detection system can timely discover and repair vulnerabilities in the firmware, effectively prevent hackers from exploiting the vulnerabilities to attack, and improve the security protection capability of the computer system. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 It is a flowchart of an intelligent identification method of UEFI firmware vulnerabilities based on a deep learning large model;
[0023] Figure 2 This is a schematic diagram of the construction process of a deep learning large model;
[0024] Figure 3 Schematic diagram of the training process of a large deep learning model. DETAILED DESCRIPTION
[0025] The technical solution of the present invention is further described in detail below in conjunction with the accompanying drawings, but the protection scope of the present invention is not limited to the following.
[0026] The features and performance of the present invention are further described in detail below in conjunction with the embodiments.
[0027] like Figure 1 As shown, a method for intelligently identifying UEFI firmware vulnerabilities based on a deep learning large model includes the following steps:
[0028] Dataset construction: Collect UEFI firmware samples of operating systems and hardware platforms; Preprocess the collected UEFI firmware samples, including binary file parsing and feature extraction, to build a UEFI firmware dataset for model training; Use data enhancement technology to transform and expand the original data;
[0029] Build a deep learning model, using convolutional neural network as the basic architecture and combining it with long short-term memory network to process sequence data to obtain a deep learning-based large model;
[0030] Model training and optimization: training the large model through the constructed UEFI firmware data set to obtain a trained deep learning large model;
[0031] Intelligent identification deploys the trained large model into the UEFI firmware vulnerability detection system. When the system receives a new UEFI firmware, it automatically extracts the key features of the firmware and inputs them into the model. The model identifies the firmware based on the learned vulnerability pattern and outputs the result of whether there is a vulnerability.
[0032] The method comprises collecting UEFI firmware samples of operating systems and hardware platforms; preprocessing the collected UEFI firmware samples, including binary file parsing and feature extraction, and constructing a UEFI firmware dataset for model training; and transforming and expanding the original data using data enhancement technology, including:
[0033] Collect UEFI firmware samples on various operating systems and hardware platforms from multiple sources, perform binary analysis on the collected UEFI firmware samples, and use static analysis tools to extract functions, variables, control flows, byte sequences, strings, and hash values in the firmware; apply enhancement techniques such as random cropping, rotation, flipping, adding noise, and simulated mutation to transform and expand the original data to simulate different firmware variants and vulnerability modes; the multiple sources mentioned include manufacturer official websites, open source communities, and security research institutions.
[0034] like Figure 2 As shown, the deep learning big model is constructed based on the convolutional neural network as the basic architecture, and the long short-term memory network is combined to process the sequence data to obtain a big model based on deep learning, including:
[0035] A deep convolutional neural network is selected as the backbone network for feature extraction, and a long short-term memory network (LSTM) is combined to process the sequence data in the firmware. In terms of multi-scale feature fusion, a feature pyramid network is used to fuse features at different levels. In terms of attention mechanism, a cross-attention mechanism is introduced to dynamically focus on key areas and vulnerability patterns in the firmware.
[0036] like Figure 3 As shown, the large model is trained by using the constructed UEFI firmware data set to obtain a trained deep learning large model, including:
[0037] The preprocessed data set is divided into training set, validation set and test set according to the set ratio; when initializing the model parameters, the Xavier initialization method or the He initialization method is used, and the pre-trained weights are loaded to accelerate the training process;
[0038] Select Adam optimizer, set dynamic learning rate adjustment strategy, use batch normalization and residual connection to reduce gradient vanishing and explosion problems; apply regularization and Dropout technology to prevent overfitting; evaluate the accuracy, recall rate, and F1 score of the model on the validation set, adjust the hyperparameters through grid search, obtain the optimal model configuration, and obtain the trained deep learning large model.
[0039] It also includes a continuous learning mechanism to incrementally update or retrain the model by regularly collecting new firmware samples and vulnerability information.
[0040] The present invention provides a method for intelligently identifying UEFI firmware vulnerabilities based on a deep learning large model, which specifically includes the following steps:
[0041] Collect UEFI firmware samples for operating systems and hardware platforms
[0042] We collect UEFI firmware samples on various operating systems (such as Windows, Linux, etc.) and hardware platforms (such as Intel, AMD, ARM, etc.) from multiple sources. These sources include but are not limited to manufacturer official websites, open source communities, security research institutions, etc. Through the diverse sample sources, we ensure the comprehensiveness and representativeness of the data set, providing a rich sample foundation for model training.
[0043] Perform binary analysis on the collected UEFI firmware samples, and use static analysis tools (such as Ghidra, IDA Pro, etc.) to extract key information such as functions, variables, and control flows in the firmware. At the same time, extract features such as byte sequences, strings, and hash values, which are crucial for identifying malicious code and vulnerability patterns in the firmware.
[0044] The preprocessed UEFI firmware samples are organized into a structured dataset, including the binary files of the firmware samples, the parsed feature information, and the corresponding labels (whether there is a vulnerability). The dataset should contain enough positive samples (firmware with vulnerabilities) and negative samples (firmware without vulnerabilities) to ensure the balance and accuracy of model training.
[0045] The original data is transformed and expanded by applying enhancement techniques such as random cropping, rotation, flipping, adding noise, and simulated mutation. These enhancement techniques can simulate different firmware variants and vulnerability patterns, improving the generalization and robustness of the model. For example, the simulated mutation technique can generate vulnerability samples with different variant forms, enabling the model to better identify and respond to variant vulnerabilities in the actual environment.
[0046] The deep convolutional neural network (CNN) is selected as the backbone network for feature extraction, and its powerful local feature extraction capability is used to extract rich feature representations from firmware samples. At the same time, the long short-term memory network (LSTM) is combined to process the sequence data in the firmware, such as control flow, byte sequence, etc., to capture the timing dependencies and context information in the firmware.
[0047] In the feature extraction stage, the feature pyramid network (FPN) is used to fuse features at different levels. Through upsampling and downsampling operations, feature maps at different levels are fused to form a multi-scale feature representation. This fusion method can capture both local detail information and global context information in the firmware, improving the recognition accuracy of the model.
[0048] A cross-attention mechanism is introduced to dynamically focus on key areas and vulnerability patterns in the firmware. By calculating the correlation between different features, higher weights are assigned to important features, thereby enhancing the model's sensitivity and recognition ability for key vulnerability features.
[0049] The preprocessed dataset is divided into training set, validation set and test set according to the set ratio. The training set is used for model training, the validation set is used for model selection and hyperparameter adjustment, and the test set is used to evaluate the final performance of the model.
[0050] When initializing model parameters, Xavier initialization or He initialization method is used to ensure that the initial distribution of model parameters is reasonable. At the same time, pre-trained weights are loaded to accelerate the training process and improve the convergence speed and final performance of the model.
[0051] The Adam optimizer is selected for model training. It combines momentum terms and adaptive learning rate adjustment strategies to quickly converge to the optimal solution. At the same time, dynamic learning rate adjustment strategies such as learning rate decay or cosine annealing are set to further optimize the training process. Batch normalization and residual connection technology are used to reduce gradient vanishing and explosion problems and improve model stability and training efficiency.
[0052] Regularization and Dropout techniques are applied to prevent model overfitting. Regularization technology limits the complexity of model parameters by adding regularization terms to the loss function, preventing the model from being too complex on the training set and performing poorly on the test set. Dropout technology randomly discards some neurons during the training process to make the model more robust and generalized.
[0053] Evaluate the model's performance indicators such as accuracy, recall, and F1 score on the validation set, and adjust hyperparameters (such as learning rate, batch size, Dropout ratio, etc.) through grid search to obtain the optimal model configuration. Repeat this process until the model performance reaches the optimal state.
[0054] Deploy the trained deep learning model into the UEFI firmware vulnerability detection system. The system can be an independent software tool or integrated into the existing security protection platform to realize the automatic detection of UEFI firmware vulnerabilities.
[0055] When the system receives a new UEFI firmware, it automatically extracts the key features of the firmware and inputs them into the model. The model identifies the firmware based on the learned vulnerability patterns and feature representations, and outputs the results of whether there is a vulnerability. At the same time, the system can also provide detailed information on the vulnerability (such as vulnerability type, location, etc.) so that users can perform subsequent security processing.
[0056] New UEFI firmware samples and vulnerability information are regularly collected from manufacturer official websites, open source communities, security research institutions, etc. These new samples and vulnerability information reflect the latest development trends and threat situations of the firmware, providing an important basis for the continuous learning of the model.
[0057] Based on the newly collected samples and vulnerability information, the model is incrementally updated or retrained. Incremental update means that the model parameters are fine-tuned or new features are added to adapt to new samples and vulnerability patterns while keeping the original model structure unchanged. Retraining is to rebuild and train the entire model to make full use of new samples and vulnerability information. Through the continuous learning mechanism, it is ensured that the model can keep up with the new trends in firmware security and vulnerability development and maintain efficient recognition capabilities.
[0058] Example
[0059] 1. Dataset Construction
[0060] 1. Collect UEFI firmware samples for operating systems and hardware platforms
[0061] In this example, we collected a total of 5,000 UEFI firmware samples from the official websites of the three major hardware platforms, Intel, AMD, and ARM, well-known open source communities (such as GitHub, GitLab, etc.), and professional security research institutions (such as Mitre, Trend Micro, etc.). These samples cover multiple operating systems such as Windows and Linux, ensuring the diversity and comprehensiveness of the data set.
[0062] 2. UEFI firmware sample preprocessing
[0063] Static analysis tools such as Ghidra and IDA Pro are used to perform binary analysis on the collected UEFI firmware samples to extract key information such as functions, variables, and control flows. At the same time, custom scripts are used to extract features such as byte sequences, strings, and hash values. These features are saved in a structured data format for subsequent processing.
[0064] 3. Build UEFI firmware dataset
[0065] The preprocessed UEFI firmware samples were labeled according to whether they had vulnerabilities, and 2,500 positive samples (firmware with vulnerabilities) and 2,500 negative samples (firmware without vulnerabilities) were obtained. The data set was divided into training set, validation set, and test set in a ratio of 7:2:1 to ensure the balance and accuracy of model training.
[0066] 4. Data Augmentation
[0067] Enhancement techniques such as random cropping, rotation, flipping, adding noise, and simulated mutation are applied to the samples in the training set. For example, 10 vulnerability samples with different mutation forms are generated through simulated mutation technology, which increases the number of training set samples to 1.5 times the original number, improving the generalization ability and robustness of the model.
[0068] 2. Building a Deep Learning Model
[0069] 1. Model architecture design
[0070] ResNet-50 is selected as the backbone network of the deep convolutional neural network (CNN) to extract local features of firmware samples. At the same time, the bidirectional long short-term memory network (Bi-LSTM) is combined to process the sequence data in the firmware, such as control flow, byte sequence, etc., to capture the timing dependencies and context information in the firmware.
[0071] 2. Multi-scale feature fusion
[0072] In the feature extraction stage, the feature pyramid network (FPN) is used to fuse the features of different levels of ResNet-50. Through upsampling and downsampling operations, the high-resolution information of the low-level feature map is fused with the semantic information of the high-level feature map to form a multi-scale feature representation, which improves the recognition accuracy of the model.
[0073] 3. Attention Mechanism
[0074] The cross-attention mechanism is introduced to assign higher weights to important features by calculating the correlation between the feature map extracted by CNN and the sequence features output by Bi-LSTM. This mechanism can dynamically focus on key areas and vulnerability patterns in the firmware, enhancing the model's sensitivity and recognition ability for key vulnerability features.
[0075] 3. Model training and optimization
[0076] 1. Data partitioning
[0077] The preprocessed and enhanced dataset is divided into training set, validation set and test set in the ratio of 7:2:1.
[0078] 2. Model Initialization
[0079] The Xavier initialization method is used to initialize the model parameters, and the ResNet-50 weights pre-trained on the ImageNet dataset are loaded to accelerate the training process and improve the convergence speed and final performance of the model.
[0080] 3. Optimization strategy
[0081] The Adam optimizer is selected for model training, the initial learning rate is set to 0.001, and the learning rate decay strategy is adopted. At the same time, batch normalization and residual connection techniques are used to reduce the gradient disappearance and explosion problems.
[0082] 4. Prevent overfitting
[0083] Add L2 regularization term to the loss function to limit the complexity of model parameters. At the same time, use Dropout technology in the training process to randomly discard some neurons, and the Dropout ratio is set to 0.5.
[0084] 5. Model evaluation and adjustment
[0085] The model's performance indicators such as accuracy, recall, and F1 score were evaluated on the validation set. The optimal model configuration was obtained by adjusting hyperparameters such as learning rate, batch size, and Dropout ratio through grid search. After multiple iterations of training, the model achieved an accuracy of 95%, a recall of 93%, and an F1 score of 94% on the validation set.
[0086] 4. Intelligent Identification
[0087] 1. Model deployment
[0088] The trained deep learning model is deployed to the self-developed UEFI firmware vulnerability detection system. The system integrates functions such as model loading, feature extraction, and vulnerability identification, and realizes the automated detection of UEFI firmware vulnerabilities.
[0089] 2. Vulnerability identification
[0090] When the system receives a new UEFI firmware, it automatically extracts the key features of the firmware and inputs them into the model. The model identifies the firmware based on the learned vulnerability patterns and feature representations, and outputs the result of whether there is a vulnerability. At the same time, the system also provides detailed information on the vulnerability (such as vulnerability type, location, etc.) so that users can perform subsequent security processing.
[0091] 5. Continuous Learning Mechanism
[0092] 1. New sample collection
[0093] Regularly collect new UEFI firmware samples and vulnerability information from manufacturer official websites, open source communities, security research institutions, etc. Collect at least 100 new samples and related vulnerability information every month.
[0094] 2. Model Update
[0095] The model is incrementally updated based on newly collected samples and vulnerability information. Model parameters are fine-tuned or new features are added to adapt to new samples and vulnerability patterns. Model updates are performed every three months to ensure that the model can keep up with new trends in firmware security and vulnerability development.
[0096] The above is only a preferred embodiment of the present invention. It should be understood that the present invention is not limited to the form disclosed herein, and should not be regarded as excluding other embodiments, but can be used in various other combinations, modifications and environments, and can be modified within the scope of the concept described herein through the above teachings or the technology or knowledge of the relevant field. The changes and modifications made by those skilled in the art shall not deviate from the spirit and scope of the present invention, and shall be within the scope of protection of the claims attached to the present invention.
Claims
1. A method for intelligently identifying UEFI firmware vulnerabilities based on a deep learning large model, characterized in that: The following steps are involved: Dataset construction, collecting UEFI firmware samples of operating systems and hardware platforms; Preprocess the collected UEFI firmware samples, including binary file parsing and feature extraction, to build a UEFI firmware dataset for model training; Use data enhancement technology to transform and expand the original data; Build a deep learning model, using convolutional neural network as the basic architecture and combining it with long short-term memory network to process sequence data to obtain a deep learning-based large model; Model training and optimization: training the large model through the constructed UEFI firmware data set to obtain a trained deep learning large model; Intelligent identification, deploying the trained large model into the UEFI firmware vulnerability detection system; When the system receives a new UEFI firmware, it automatically extracts the key features of the firmware and inputs them into the model; The model identifies the firmware based on the learned vulnerability patterns and outputs the result of whether the vulnerability exists.
2. According to claim 1, a method for intelligently identifying UEFI firmware vulnerabilities based on a deep learning large model is characterized in that: The UEFI firmware samples of the collected operating system and hardware platform; Preprocess the collected UEFI firmware samples, including binary file parsing and feature extraction, to build a UEFI firmware dataset for model training; Data enhancement techniques are used to transform and expand the original data, including: Collect UEFI firmware samples on various operating systems and hardware platforms from multiple sources, perform binary analysis on the collected UEFI firmware samples, and use static analysis tools to extract functions, variables, control flows, as well as byte sequences, strings, and hash values in the firmware; The raw data is transformed and expanded by applying enhancement techniques such as random cropping, rotation, flipping, adding noise, and simulating mutations to simulate different firmware variants and vulnerability patterns. The multiple sources mentioned include the manufacturer's official website, open source community, and security research institutions.
3. According to claim 1, a method for intelligently identifying UEFI firmware vulnerabilities based on a deep learning large model is characterized in that: The deep learning big model is constructed based on the convolutional neural network as the basic architecture, and the long short-term memory network is combined to process the sequence data to obtain a big model based on deep learning, including: A deep convolutional neural network is selected as the backbone network for feature extraction, and a long short-term memory network (LSTM) is combined to process the sequence data in the firmware. In terms of multi-scale feature fusion, a feature pyramid network is used to fuse features at different levels. In terms of attention mechanism, a cross-attention mechanism is introduced to dynamically focus on key areas and vulnerability patterns in the firmware.
4. According to claim 3, a method for intelligently identifying UEFI firmware vulnerabilities based on a deep learning large model is characterized in that: The method of training the large model by using the constructed UEFI firmware data set to obtain the trained deep learning large model includes: The preprocessed data set is divided into training set, validation set and test set according to the set ratio; when initializing the model parameters, the Xavier initialization method or the He initialization method is used, and the pre-trained weights are loaded to accelerate the training process; Select Adam optimizer, set dynamic learning rate adjustment strategy, use batch normalization and residual connection to reduce gradient vanishing and explosion problems; apply regularization and Dropout technology to prevent overfitting; evaluate the accuracy, recall rate, and F1 score of the model on the validation set, adjust the hyperparameters through grid search, obtain the optimal model configuration, and obtain the trained deep learning large model.
5. According to claim 1, a method for intelligently identifying UEFI firmware vulnerabilities based on a deep learning large model is characterized in that: It also includes a continuous learning mechanism to incrementally update or retrain the model by regularly collecting new firmware samples and vulnerability information.
Citation Information
Cited By
Adaptive fusion attention-based convolutional neural network firmware vulnerability detection method
CN121328630A
Deformable convolution-based convolutional neural network firmware vulnerability detection method
CN121328631A