Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

Host protected area

From Wikipedia, the free encyclopedia
(Redirected fromProtected Area Run Time Interface Extension Services)
Area of hard drive that is not visible to operating system

Thehost protected area (HPA) is an area of ahard drive orsolid-state drive that is not normally visible to anoperating system. It was first introduced in theATA-4 standard CXV (T13) in 2001.[1]

How it works

[edit]
Creation of an HPA. The diagram shows how a host protected area (HPA) is created.
  1. IDENTIFY DEVICE returns the true size of the hard drive. READ NATIVE MAX ADDRESS returns the true size of the hard drive.
  2. SET MAX ADDRESS reduces the reported size of the hard drive. READ NATIVE MAX ADDRESS returns the true size of the hard drive. An HPA has been created.
  3. IDENTIFY DEVICE returns the now fake size of the hard drive. READ NATIVE MAX ADDRESS returns the true size of the hard drive, the HPA is in existence.

The IDE controller hasregisters that contain data that can be queried usingATA commands. The data returned gives information about the drive attached to the controller. There are three ATA commands involved in creating and using a host protected area. The commands are:

  • IDENTIFY DEVICE
  • SET MAX ADDRESS
  • READ NATIVE MAX ADDRESS

Operating systems use the IDENTIFY DEVICE command to find out the addressable space of a hard drive. The IDENTIFY DEVICE command queries a particular register on the IDE controller to establish the size of a drive.

This register however can be changed using the SET MAX ADDRESS ATA command. If the value in the register is set to less than the actual hard drive size then effectively a host protected area is created. It is protected because the OS will work with only the value in the register that is returned by the IDENTIFY DEVICE command and thus will normally be unable to address the parts of the drive that lie within the HPA.

The HPA is useful only if other software or firmware (e.g.BIOS orUEFI) is able to use it. Software and firmware that are able to use the HPA are referred to as 'HPA aware'. The ATA command that these entities use is called READ NATIVE MAX ADDRESS. This command accesses a register that contains the true size of the hard drive. To use the area, the controlling HPA-aware program changes the value of the register read by IDENTIFY DEVICE to that found in the register read by READ NATIVE MAX ADDRESS. When its operations are complete, the register read by IDENTIFY DEVICE is returned to its original fake value.

Use

[edit]
"BEER" redirects here. For other uses, seeBeer (disambiguation).
  • HPA can be used by various booting and diagnostic utilities, normally in conjunction with theBIOS. An example of this implementation is thePhoenixFirstBIOS, which usesBoot Engineering Extension Record (BEER) andProtected Area Run Time Interface Extension Services (PARTIES).[2]
  • HPA can also be used to store data that is deemed illegal and is thus of interest to government and policecomputer forensics teams.[3]
  • Somerootkits hide in the HPA to avoid being detected by anti-rootkit andantivirus software.[2]
  • SomeNSA exploits use the HPA for application persistence.[4]

Identification

[edit]

Identification of HPA on a hard drive can be achieved by a number of tools and methods:

See also

[edit]

References

[edit]
  1. ^"Host Protected Areas"(PDF).Utica.edu.
  2. ^abBlunden, Bill (2009).The rootkit arsenal: escape and evasion in the dark corners of the system.Plano, Texas: Wordware Pub. p. 538.ISBN 978-1-59822-061-2.OCLC 297145864.
  3. ^Nelson, Bill; Phillips, Amelia; Steuart, Christopher (2010).Guide to computer forensics and investigations (4th ed.). Boston: Course Technology, Cengage Learning. p. 334.ISBN 978-1-435-49883-9.
  4. ^"SWAP: NSA Exploit of the Day - Schneier on Security". 6 February 2014.

External links

[edit]
Retrieved from "https://en.wikipedia.org/w/index.php?title=Host_protected_area&oldid=1328492985#PARTIES"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2026 Movatter.jp