CAPEC Definitions

    CAPEC Definitions / CAPEC-672

    CAPEC-672: Malicious Code Implanted During Chip Programming

    During the programming step of chip manufacture, an adversary with access and necessary technical skills maliciously alters a chip’s intended program logic to produce an effect intended by the adversary when the fully manufactured chip is deployed and in operational use. Intended effects can include the ability of the adversary to remotely control a host system to carry out malicious acts.

    Severity:High
    Possibility:Low

    Extended Description

    No Extended Description.

    Mitigations

    Utilize DMEA’s (Defense Microelectronics Activity) Trusted Foundry Program members for acquisition of microelectronic components.

    Ensure that each supplier performing hardware development implements comprehensive, security-focused configuration management of microcode and microcode generating tools and software.

    Require that provenance of COTS microelectronic components be known whenever procured.

    Conduct detailed vendor assessment before acquiring COTS hardware.

    Relationships with other CAPECs

    CAPEC-444: Development Alteration

    Prerequisites

    An adversary would need to have access to a foundry’s or chip maker’s development/production environment where programs for specific chips are developed, managed and uploaded into targeted chips prior to distribution or sale.

    Related Weaknesses

    No related Weaknesses found.

    CAPEC-672: Malicious Code Implanted During Chip Programming | CVE-DB