AI 中文总结
本研究针对TianoCore社区开展调查与访谈,分析其软件安全与维护实践,发现该社区在UEFI固件开发中存在的差距,提出改进安全实践、采用内存安全技术及提升流程自动化等优化方向。
AI 中文摘要
我们研究TianoCore社区中利益相关者采用的软件安全与维护实践,并找出改进固件开发工作流的机会。针对代表独立固件厂商、原始设备制造商、安全专家、固件开发者及学术研究者的参与者,我们开展了一项调查及有限的访谈研究。这个开源开发社区维护着UEFI固件核心的参考实现。我们强调TianoCore生态系统内当前固件开发现状的重要差距,并确定了几个关键领域:改进安全实践、更多采用内存安全技术、提升手动流程的自动化程度,这些都能增强UEFI固件的维护性与安全性。
英文摘要
We investigate the software security and maintenance practices adopted by stakeholders in the TianoCore community and identify opportunities to improve firmware development workflows. We conduct a survey and a limited interview study with participants representing independent firmware vendors, original equipment manufacturers, security experts, firmware developers, and academic researchers. This open-source development community maintains a reference implementation for the core of the UEFI firmware. We highlight important gaps in the current state of firmware development within the TianoCore ecosystem and identify key areas in which improved security practices, greater adoption of memory-safe technologies, and increased automation of manual processes could strengthen the maintenance and security of the UEFI firmware.
CommentsThis work is accepted to be presented in the FTA 2026 workshop but is not published in the proceedings, according to the ACM SIGSOFT policy (https://www2.sigsoft.org/policies/pcpolicy/) that does not allow the work of organizers to be published in the workshop proceedings