PRESENTATIONS
Bootkit-in-front-of-a-bootkit
Enterprise server platforms are the bedrock of the modern internet. It would stand to reason that the foundation of IT infrastructure, the firmware and hardware of those systems, would be especially well audited and secured against advanced attackers. Unfortunately, history shows that the resilience of these components has suffered from an ever-increasing attack surface and insufficient scrutiny; today, this trend is only accelerating with the mass adoption of complex AI infrastructure at unprecedented rates.
In this work, we focus on analyzing the security of the Data Processing Unit (DPU), which has become ubiquitous in AI datacenters. This computer-in-front-of-a-computer promises to shield its host server by offloading networking, encryption, and security-related logic away from the host processor. But what happens when the DPU itself becomes the weak link? In this presentation, we demonstrate a UEFI secure boot bypass on the Nvidia Bluefield 3 DPU, and use it to build the first known DPU bootkit. We then show how it is possible to launch a DMA attack from the DPU targeting the host.

