Method and system for automatically detecting security of computer firmware
By installing a firmware security detection client on the computer and automatically detecting firmware using the mirror files obtained from the server, the problem of lack of automation and universality of firmware security detection in the prior art is solved, and comprehensive security detection of computer firmware in various architectures is achieved, thereby improving the security and reliability of the firmware system.
Patent Information
- Application Number
- CN202311749813.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-19
- Publication Date
- 2025-06-20
AI Technical Summary
In the prior art, the security detection of firmware lacks automation and versatility, making it difficult to fully detect the security status of computer firmware of various architectures.
By installing a firmware security detection client on the computer, the client obtains the mirror files corresponding to the computer architecture from the firmware security detection server, uses these mirror files to automatically detect the firmware, generates a detection report and sends it to the server for web page display.
It realizes automatic detection of computer firmware in various architectures, improves the security and reliability of firmware systems, and is versatile and efficient.
Smart Images

Figure CN120180437A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer security, and particularly to a method and system for automatically detecting the security of computer firmware. Background Art
[0002] Firmware (PC firmware) refers to the firmware or Basic Input / Output System (BIOS) on a personal computer (PC), which is software code embedded in the hardware of a computing device and is responsible for controlling and managing the operation of hardware devices. However, due to the particularity and underlying position of firmware, they are often vulnerable to attacks or have vulnerabilities. Therefore, ensuring the security of firmware is crucial for protecting the security of the entire computer system and network.
[0003] Currently, since firmware is located below the operating system and has many functions for operating hardware, the security status of the firmware itself is rarely involved in penetration testing / fuzz testing. Even if the firmware is within the scope of evaluation, it is mostly functional testing and the testing methods are generally limited to manual operations. Some firmware manufacturers provide security evaluation tools, but they can generally only be used for the firmware of their own manufacturers and do not have universality. In short, the existing firmware detection means do not have automation and universality. Summary of the Invention
[0004] The present invention provides a method for automatically detecting the security of computer firmware, aiming to automatically detect the firmware of computers with various architectures.
[0005] The method for automatically detecting the security of computer firmware provided by the present invention includes: a firmware security detection client installed on a computer obtains an image file corresponding to the architecture of the computer for detecting the firmware of the computer from a firmware security detection server; the firmware security detection client uses the obtained image file to automatically detect the firmware of the computer and generates a detection result including a firmware detection report file and a firmware binary file of the computer;
[0006] The firmware security detection client sends the detection result including the firmware detection report file and the firmware binary file of the computer to the firmware security detection server for web display by the firmware security detection server.
[0007] Preferably, the method further includes: storing multiple image files corresponding to multiple architectures respectively in the firmware security detection server in advance, where each image file is used to automatically detect the firmware of a computer with one architecture.
[0008] Preferably, the firmware security detection client obtains the mirror file for detecting the firmware of the computer from the firmware security detection server, which includes: the firmware security detection client obtains the architecture of the computer, and selects the mirror file corresponding to the architecture of the computer from multiple mirror files respectively corresponding to multiple architectures stored in the firmware security detection server; the firmware security detection client downloads the mirror file corresponding to the architecture of the computer that has been selected from the firmware security detection server.
[0009] Preferably, the method further includes: storing multiple startup files respectively corresponding to multiple architectures in the firmware security detection server in advance, where each startup file is used to automatically obtain a mirror file corresponding to one architecture.
[0010] Preferably, the method further includes: the firmware security detection client obtains the architecture of the computer, and obtains the startup file corresponding to the architecture of the computer from multiple startup files respectively corresponding to multiple architectures stored in the firmware security detection server, so as to obtain the mirror file corresponding to the architecture of the computer from the firmware security detection server through the obtained startup file corresponding to the architecture of the computer.
[0011] Preferably, the mirror file for detecting the firmware of the computer includes a security detection tool for detecting the firmware of the computer and a command line interpreter Shell environment for automatically running the security detection tool.
[0012] Preferably, the firmware security detection client automatically detects the firmware of the computer by using the obtained mirror file, and generates a detection result including a firmware detection report file and a firmware binary file of the computer, which includes: the firmware security detection client creates a dedicated partition for the virtual memory disk, and loads the mirror file for detecting the firmware of the computer into the dedicated partition; after the firmware security detection client loads the mirror file for detecting the firmware of the computer into the dedicated partition, it starts the Shell environment for automatically running the security detection tool in the mirror file to automatically run the security detection tool for detecting the firmware of the computer in the mirror file, and obtains the firmware detection report file of the computer; after obtaining the firmware detection report file of the computer, it obtains the firmware binary file from the FLASH of the computer.
[0013] Preferably, the firmware security detection client sends the detection results of the firmware detection report file and the firmware binary file of the computer to the firmware security detection server, so that the firmware security detection server can display the results on a web page, including: after receiving the detection results of the firmware detection report file and the firmware binary file of the computer, the firmware security detection server parses the firmware detection report file and the firmware binary file in the detection results to obtain the parsing results of the firmware detection report file and the firmware binary file; the firmware security detection server displays the parsing results of the firmware detection report file and the firmware binary file of the computer to the user through the web page.
[0014] Preferably, the method further includes: after obtaining the firmware binary file from the FLASH of the computer, automatically repairing the firmware security-related configuration; wherein, automatically repairing the firmware security-related configuration includes: detecting whether the first boot order of the computer is the hard disk; if it is detected that the first boot order of the computer is not the hard disk, automatically modifying the first boot order of the computer to the hard disk.
[0015] A system for automatically detecting the security of computer firmware provided by the present invention includes a firmware security detection client and a firmware security detection server installed on the computer, where:
[0016] The firmware security detection client installed on the computer is used to obtain the image file corresponding to the architecture of the computer for detecting the firmware of the computer from the firmware security detection server, and use the obtained image file to automatically detect the firmware of the computer, generate the detection results of the firmware detection report file and the firmware binary file of the computer, and send the detection results of the firmware detection report file and the firmware binary file of the computer to the firmware security detection server;
[0017] The firmware security detection server is used to display the detection results of the received firmware detection report file and the firmware binary file of the computer on a web page.
[0018] Through the method and system of the present invention, the firmware security detection clients installed on computers of various architectures can all use the image files corresponding to their own architectures obtained from the firmware security detection server to automatically detect the firmware, ensuring the security and reliability of the firmware systems of computers of various architectures. Description of the Drawings
[0019] Figure 1 is a flowchart of the method for automatically detecting firmware security provided by the present invention;
[0020] Figure 2 It is the overall framework diagram of the system for automatically detecting firmware security provided by the present invention;
[0021] Figure 3 It is the flow chart of automatic distribution of detection tools provided by the present invention;
[0022] Figure 4 It is the flow chart of vulnerability scanning and correction provided by the present invention;
[0023] Figure 5 It is the flow chart of uploading detection results provided by the present invention. Specific embodiments
[0024] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0025] With the wide application of computer systems and networks, firmware, as the software code that controls the operation of hardware devices, faces increasingly severe security challenges. Malicious attackers may exploit firmware vulnerabilities to obtain unauthorized access, tamper with data, or disrupt normal system operation. Security vulnerabilities existing in the firmware layer have become one of the important threat factors in the information security industry, and attacks using them have inherent characteristics such as being difficult to remove, detect, and having strong destructiveness. Therefore, researching attacks based on the firmware layer to provide strong security guarantees for computer security from the bottom layer has important application value and research significance. The present invention provides a method and system for automatically detecting firmware security, which is applicable to computing devices, not just computers. This method and system can conduct comprehensive security analysis on the firmware of computing devices with various architectures and take corresponding measures to eliminate potential vulnerabilities and risks. Specifically, it uses security detection tools to automatically execute steps such as firmware data collection, vulnerability scanning, and risk assessment, conduct in-depth security analysis on the firmware, and eliminate potential vulnerabilities and risks through means such as rule matching and automatic repair, realizing comprehensive security analysis of the firmware, and can be widely applied at multiple levels such as enterprises, organizations, and individuals to improve the security of computer systems and networks.
[0026] See Figure 1, the present invention provides a method for automatically detecting the security of computer firmware. The method may include: 1) The firmware security detection client installed on the computer obtains the mirror file corresponding to the architecture of the computer for detecting the firmware of the computer from the firmware security detection server; 2) The firmware security detection client uses the obtained mirror file to automatically detect the firmware of the computer and generates a detection result including the firmware detection report file and the firmware binary file of the computer; 3) The firmware security detection client sends the detection result including the firmware detection report file and the firmware binary file of the computer to the firmware security detection server for web display by the firmware security detection server.
[0027] Further, a plurality of mirror files respectively corresponding to multiple architectures are pre-stored in the firmware security detection server, and each mirror file is used to automatically detect the firmware of a computer of one architecture. Correspondingly, the foregoing step 1) may include: The firmware security detection client obtains the architecture of the computer and selects and downloads the mirror file corresponding to the architecture of the computer from the multiple mirror files respectively corresponding to multiple architectures stored in the firmware security detection server.
[0028] Further, the method may further include: A plurality of startup files respectively corresponding to multiple architectures are pre-stored in the firmware security detection server, and each startup file is used to automatically obtain the mirror file corresponding to one architecture. In this way, in the foregoing step 1), the firmware security detection client can use the startup file to obtain the required mirror file. Specifically, the firmware security detection client obtains the architecture of the computer and obtains the startup file corresponding to the architecture of the computer from the multiple startup files respectively corresponding to multiple architectures stored in the firmware security detection server, so as to obtain the mirror file corresponding to the architecture of the computer from the firmware security detection server through the obtained startup file corresponding to the architecture of the computer.
[0029] Furthermore, the image file for detecting the firmware of the computer includes a security detection tool for detecting the firmware of the computer and a Shell environment for automatically running the security detection tool. Here, Shell is a command-line interface provided by the UEFI firmware, similar to the command-line terminal in an operating system, which allows users to directly interact with the firmware when the computer starts up. The UEFI Shell provides a set of commands that can perform various management and debugging tasks, such as hardware configuration, firmware settings, boot management, etc. Correspondingly, the aforementioned step 2) may include: the firmware security detection client creates a dedicated partition and loads the image file for detecting the firmware of the computer into the dedicated partition. After loading the image file for detecting the firmware of the computer into the dedicated partition, the firmware security detection client starts the Shell environment in the image file for automatically running the security detection tool to automatically run the security detection tool for detecting the firmware of the computer in the image file, obtains the firmware detection report file of the computer, and after obtaining the firmware detection report file of the computer, obtains the firmware binary file of the computer from the FLASH of the computer. Here, Flash is a non-volatile memory technology used to store and read data. The aforementioned step 3) may include: after receiving the detection result containing the firmware detection report file and the firmware binary file of the computer, the firmware security detection server parses the firmware detection report file and the firmware binary file in the detection result to obtain the parsing result of the firmware detection report file and the parsing result of the firmware binary file, and displays the parsing result of the firmware detection report file and the parsing result of the firmware binary file of the computer to the user through a web page.
[0030] Furthermore, the method can also automatically repair some security-related configurations of the firmware. For example, after obtaining the firmware binary file from the FLASH of the computer, the firmware security detection client uses the security detection tool to detect whether the first boot order of the computer is the hard disk. If it is detected that the first boot order of the computer is not the hard disk, the first boot order of the computer is automatically modified to the hard disk.
[0031] Among them, the aforementioned architecture includes but is not limited to the X86 architecture, LS architecture, ARM architecture, and MIPS architecture. The firmware security detection server pre-stores the corresponding boot files and image files for each architecture respectively, so that firmware security detection clients of different architectures can all use the image files obtained from the firmware security detection server to automatically perform comprehensive firmware security detection and firmware repair, providing security guarantees for computers of various architectures under the firmware security detection server from the bottom layer and ensuring the security and reliability of the firmware system.
[0032] In addition, the present invention further provides a system for automatically detecting the security of computer firmware, and the system may include:
[0033] A firmware security detection client installed on the computer, configured to obtain, from a firmware security detection server, an image file corresponding to the architecture of the computer for detecting the firmware of the computer, and use the obtained image file to automatically detect the firmware of the computer, generate a detection result including a firmware detection report file and a firmware binary file of the computer, and send the detection result including the firmware detection report file and the firmware binary file of the computer to the firmware security detection server;
[0034] A firmware security detection server, configured to perform web display on the received detection result of the firmware detection report file and the firmware binary file of the computer.
[0035] Furthermore, a plurality of image files respectively corresponding to multiple architectures are pre-stored in the firmware security detection server, and each image file is used to automatically detect the firmware of a computer of one architecture. In this way, after obtaining the architecture of the computer, the firmware security detection client can select and download the image file corresponding to the architecture of the computer from the plurality of image files respectively corresponding to multiple architectures stored in the firmware security detection server.
[0036] Furthermore, a plurality of boot files respectively corresponding to multiple architectures are pre-stored in the firmware security detection server, and each boot file is used to automatically obtain an image file corresponding to one architecture. In this way, the firmware security detection client can use the boot file to obtain the required image file. Specifically, after obtaining the architecture of the computer, the firmware security detection client obtains the boot file corresponding to the architecture of the computer from the plurality of boot files respectively corresponding to multiple architectures stored in the firmware security detection server, and thus, through the obtained boot file corresponding to the architecture of the computer, obtains the image file corresponding to the architecture of the computer from the firmware security detection server.
[0037] Further, the image file for detecting the firmware of the computer includes a security detection tool for detecting the firmware of the computer and a Shell environment for automatically running the security detection tool. In this way, after the firmware security detection client loads the image file for detecting the firmware of the computer into the dedicated partition it creates, it starts the Shell environment in the image file for automatically running the security detection tool to automatically run the security detection tool in the image file for detecting the firmware of the computer, obtains the firmware detection report file of the computer, and after obtaining the firmware detection report file of the computer, obtains the firmware binary file of the computer from the FLASH of the computer, and then sends the detection result including the firmware detection report file and the firmware binary file of the computer to the firmware security detection server. After receiving the detection result including the firmware detection report file and the firmware binary file of the computer, the firmware security detection server parses the firmware detection report file and the firmware binary file in the detection result to obtain the parsing result of the firmware detection report file and the parsing result of the firmware binary file, and displays the parsing result of the firmware detection report file and the parsing result of the firmware binary file of the computer to the user through a web page.
[0038] Further, the firmware security detection client can also use the security detection tool to automatically repair some security-related configurations of the firmware. For example, after the firmware security detection client uses the security detection tool to obtain the firmware binary file from the FLASH of the computer, it detects whether the first boot order of the computer is the hard disk. If it detects that the first boot order of the computer is not the hard disk, it automatically modifies the first boot order of the computer to the hard disk.
[0039] Among them, the foregoing architectures include but are not limited to the X86 architecture, LS architecture, ARM architecture, and MIPS architecture. The firmware security detection server pre-stores the corresponding boot files and image files for each architecture, so that firmware security detection clients of different architectures can all use the image files obtained from the firmware security detection server to automatically perform comprehensive firmware security detection and firmware repair, providing security guarantees for computers of various architectures under the firmware security detection server from the bottom layer and ensuring the security and reliability of the firmware system.
[0040] The following will be combined with Figures 2 to 5 , and the present invention will be described in detail.
[0041] The present invention provides a method and system for automatically detecting the security of computer firmware, adopting a C / S architecture, that is, a client (or firmware security detection client, firmware detection client) and a server architecture. One server can correspond to multiple clients. The main function of the server is to save the startup file and the mirror file containing the security detection tool (or detection tool), and is responsible for analyzing the received detection result file. The client is the machine to be detected (or the machine under test). Using the network startup function of the client, the server can remotely detect the firmware security of multiple computing devices.
[0042] See Figure 2 , taking one server and one firmware detection client as an example for detailed description.
[0043] Server: First, build a firmware security detection server (or firmware detection server) on the server so that the client can automatically select startup files for different platforms according to the architecture. When the client boots up, it will download the corresponding startup file from the server and then run the program. The program on the server is mainly divided into two parts: the front end and the back end. The back end is responsible for real-time detection of whether there are new files uploaded, and parsing the startup firmware binary file and the firmware detection report file. The front end is mainly responsible for web interface display and presenting the results parsed by the back end to the user.
[0044] Client, that is, the machine under test. When starting up through the network, it downloads the corresponding mirror file from the server according to the actual architecture, loads the mirror file and runs the detection tool therein (detect the security of the firmware and generate a firmware detection report file), obtains the binary file of the firmware, and uploads both the generated firmware detection report file and the firmware binary file to the server.
[0045] The present invention can be used in various scenarios that require scanning for vulnerabilities in UEFI-based firmware, and can be used for system security assessment and risk management, so as to ensure the security and reliability of the firmware system.
[0046] The functions / modules of the method and system of the present invention include automatic distribution of detection tools, vulnerability scanning and correction, upload of detection results and analysis of detection results. The automatic distribution of detection tools includes functions / modules such as downloading mirror files and running the detection tools in the mirror files, specifically as follows:
[0047] 1. Automatic distribution of detection tools: The mirror file and the network startup file / program have been placed in the specified directory under the server platform system. The client (or client machine) uses the network startup file / program to automatically download the detection tool suitable for itself.
[0048] See Figure 3, the relevant steps of the detection tool automatic distribution function / module may include: 1) The client requests an IP address and a boot file name from the DHCP server. If the DHCP successfully assigns an IP address, according to the boot file name, download the boot file from the firmware security detection server, and through the boot file, automatically download the image file containing the detection tool suitable for itself from the firmware security detection server; 2) Create a virtual private partition to load the image file; 3) Start the UEFI Shell program; 4) The shell program will automatically execute the security detection script, and this script will call the corresponding programs in sequence according to the process to complete the firmware security detection function, and obtain the detection report file (log), the firmware binary file (bin), and the hardware information; 5) Upload all the obtained files to the firmware security detection server. If the upload fails, repeat steps 1) to 4) until the upload is successful; 6) Exit the firmware and restart.
[0049] The client starts up through the network, sends a DHCP request to the DHCP server to obtain the IP address and the information of the boot server, starts the target computer through the network, and loads the dedicated partition image deployed remotely. The detection tool automatic distribution module is the hub of the whole system and is responsible for the communication between the client and the server.
[0050] 2. Vulnerability scanning and correction: After the client (or the client computer) downloads the detection tool, it will automatically run the corresponding tool, and the shell program inside will automatically call the corresponding script to perform security detection on the firmware and automatically repair some security-related configurations.
[0051] See Figure 4 , the relevant steps of the vulnerability scanning and correction function / module may include: 1) The Shell program runs automatically, performs security detection on the firmware and generates a report. Specifically, the image file downloaded by the client contains all the firmware security detection programs. When the Shell program runs, the shell program will automatically call the corresponding script, and this script will call the corresponding programs in the order of the flowchart to complete the firmware security detection function; 2) Obtain the binary file of the firmware (bios) from the Flash; 3) Automatically repair the firmware security-related configurations. For example, detect the boot order. If the first boot order is not the hard disk, automatically modify it so that the hard disk is the first boot item; 4) Obtain the SMBIOS and hardware information; 5) Exit the Shell program. Among them, the full English name of SMBIOS is System Management BIOS, which is a standard interface used to describe the hardware information of a computer system and provides a unified and portable method to obtain and report the computer hardware configuration information.
[0052] 3. Detection result upload: After the client executes the detection tool and obtains the firmware detection report file (log), the firmware binary file (bin), and the hardware information, all the obtained files are uploaded to the server through the firmware security detection client.
[0053] See Figure 5 , the relevant steps of the detection result upload function / module may include: 1) The Shell program runs automatically to perform security detection on the firmware and generate a report; 2) Obtain the binary file of the firmware (bios) from the Flash; 3) Automatically repair the firmware security-related configurations. For example, detect the boot order. If the first boot order is not the hard disk, automatically modify the hard disk to the first boot item; 4) Obtain the SMBIOS and hardware information; 5) Exit the Shell program; 6) After the client executes the security detection tool and obtains the detection report file (log), the firmware binary file (bin), and the hardware information, all the obtained files are uploaded to the server; 7) The client reboots.
[0054] 4. Detection result analysis: The firmware security detection server analyzes the detection results uploaded by the client (or the client machine), and after the analysis is completed, it is displayed through the server front-end program.
[0055] The relevant steps of the detection result analysis function / module may include: 1) The client uploads the detection results (or all the obtained files) to the server through the TFTP service; 2) After the server receives the detection results (or all the obtained files) uploaded by the client, through the backend program deployed in the server, it parses / analyzes the detection results (or all the obtained files) uploaded by the client; 3) After the parsing / analysis is completed, it is displayed by the front-end program deployed in the server.
[0056] Among them, the server determines whether there is a new file uploaded by judging the file name. If the END file is received, it proves that all files have been uploaded, and the parsing / analysis work of the detection results is carried out.
[0057] The present invention can be applied to scenarios such as automated vulnerability scanning of various architecture platforms, and has at least the following advantages:
[0058] 1. The method and system of the present invention can automatically run necessary programs and scripts at startup, reducing the time and workload of manual operations, and realizing rapid data collection and vulnerability detection and risk assessment;
[0059] 2. Using the automated solution of the present invention, the system can be monitored regularly or in real time, and new vulnerabilities and risks can be discovered and reported in a timely manner. This enables the administrator to understand the security status of the system earlier and take corresponding measures in a timely manner to reduce potential threats;
[0060] 3. Through the data collected by the present invention and the vulnerability scanning results, comprehensive risk assessment and management are carried out. The administrator can formulate corresponding risk prevention strategies according to the assessment results, and prioritize the handling of high-risk vulnerabilities and problems, thereby improving the security of the system;
[0061] 4. The present invention can expand and customize security detection tools according to actual needs. The administrator can write custom scripts and algorithms according to specific business requirements or environmental requirements to conduct in-depth analysis and evaluation of vulnerabilities and risks in different fields;
[0062] 5. The present invention deploys a set of server environments on the server side, and at the same time supports the extraction of firmware for multiple models of X86, ARM, LS, and MIPS architectures, which is convenient for the daily maintenance of the server environment;
[0063] 6. Compared with the cumbersome software and hardware tools, the way of automatically extracting firmware and parsing detection results in the present invention avoids mistakes caused by manual settings;
[0064] 7. The detection results of the present invention are clear and support the export of test reports, which is convenient for test engineers to view the results.
[0065] The preferred embodiments of the present invention have been described above with reference to the accompanying drawings, and the scope of the rights of the present invention is not limited thereby. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and essence of the present invention shall be within the scope of the rights of the present invention.
Claims
1. A method for automatically detecting the security of computer firmware, characterized in that, The method includes: The firmware security detection client installed on the computer obtains the mirror file corresponding to the architecture of the computer for detecting the firmware of the computer from the firmware security detection server; The firmware security detection client uses the obtained mirror file to automatically detect the firmware of the computer, and generates a detection result including the firmware detection report file and the firmware binary file of the computer; The firmware security detection client sends the detection result including the firmware detection report file and the firmware binary file of the computer to the firmware security detection server for web display by the firmware security detection server.
2. The method according to claim 1, characterized in that, The method further includes: Multiple mirror files corresponding to multiple architectures are stored in the firmware security detection server in advance, where each mirror file is used to automatically detect the firmware of a computer of one architecture.
3. The method according to claim 2, characterized in that, The firmware security detection client obtaining the mirror file corresponding to the architecture of the computer for detecting the firmware of the computer from the firmware security detection server includes: The firmware security detection client obtains the architecture of the computer, and selects the mirror file corresponding to the architecture of the computer from the multiple mirror files corresponding to multiple architectures stored in the firmware security detection server; The firmware security detection client downloads the selected mirror file corresponding to the architecture of the computer from the firmware security detection server.
4. The method according to any one of claim 3, characterized in that, The method further includes: Multiple startup files corresponding to multiple architectures are stored in the firmware security detection server in advance, where each startup file is used to automatically obtain the mirror file corresponding to one architecture.
5. The method according to claim 4, characterized in that, The method further includes: The firmware security detection client obtains the architecture of the computer, and obtains the startup file corresponding to the architecture of the computer from the multiple startup files corresponding to multiple architectures stored in the firmware security detection server, so as to obtain the mirror file corresponding to the architecture of the computer from the firmware security detection server through the obtained startup file corresponding to the architecture of the computer.
6. The method according to claim 1, characterized in that, The mirror file for detecting the firmware of the computer includes a security detection tool for detecting the firmware of the computer and a command-line interpreter Shell environment for automatically running the security detection tool.
7. The method according to claim 6, characterized in that, The firmware security detection client using the obtained mirror file to automatically detect the firmware of the computer and generating a detection result including the firmware detection report file and the firmware binary file of the computer includes: The firmware security detection client creates a dedicated partition for the virtual memory disk, and loads the mirror file for detecting the firmware of the computer into the dedicated partition; After the firmware security detection client loads the mirror file for detecting the firmware of the computer into the dedicated partition, it starts the Shell environment in the mirror file for automatically running the security detection tool to automatically run the security detection tool in the mirror file for detecting the firmware of the computer, and obtains the firmware detection report file of the computer; After obtaining the firmware detection report file of the computer, obtain the firmware binary file of the computer from the FLASH of the computer.
8. The method according to claim 7, characterized in that, The firmware security detection client sends the detection results including the firmware detection report file and the firmware binary file of the computer to the firmware security detection server, so that the firmware security detection server can perform web display including: After receiving the detection results including the firmware detection report file and the firmware binary file of the computer, the firmware security detection server parses the firmware detection report file and the firmware binary file in the detection results to obtain the parsing result of the firmware detection report file and the parsing result of the firmware binary file; The firmware security detection server displays the parsing result of the firmware detection report file and the parsing result of the firmware binary file of the computer to the user through the web page.
9. The method according to claim 7, characterized in that, The method further includes: after obtaining the firmware binary file from the FLASH of the computer, automatically repairing the firmware security-related configuration; Among them, automatically repairing the firmware security-related configuration includes: detecting whether the first startup order of the computer is the hard disk; if it is detected that the first startup order of the computer is not the hard disk, automatically modify the first startup order of the computer to the hard disk.
10. A system for automatically detecting the security of computer firmware, characterized in that, The system includes a firmware security detection client and a firmware security detection server installed on a computer, where: The firmware security detection client installed on the computer is used to obtain the image file for detecting the firmware of the computer corresponding to the architecture of the computer from the firmware security detection server, use the obtained image file to automatically detect the firmware of the computer, generate the detection results including the firmware detection report file and the firmware binary file of the computer, and send the detection results including the firmware detection report file and the firmware binary file of the computer to the firmware security detection server; The firmware security detection server is used to perform web display on the received detection results of the firmware detection report file and the firmware binary file of the computer.