El área protegida del host ( HPA ) es un área de un disco duro o unidad de estado sólido que normalmente no es visible para un sistema operativo . Se introdujo por primera vez en el estándar ATA-4 CXV (T13) en 2001. [ 1 ]
Cómo funciona

- IDENTIFY DEVICE devuelve el tamaño real del disco duro. READ NATIVE MAX ADDRESS devuelve el tamaño real del disco duro.
- SET MAX ADDRESS reduce el tamaño informado del disco duro. READ NATIVE MAX ADDRESS devuelve el tamaño real del disco duro. Se ha creado un HPA.
- IDENTIFY DEVICE devuelve el tamaño ahora falso del disco duro. READ NATIVE MAX ADDRESS devuelve el tamaño real del disco duro, el HPA existe.
El controlador IDE tiene registros que contienen datos que se pueden consultar mediante comandos ATA . Los datos devueltos proporcionan información sobre la unidad conectada al controlador. Hay tres comandos ATA involucrados en la creación y el uso de un área protegida de host. Los comandos son:
- IDENTIFICAR DISPOSITIVO
- ESTABLECER DIRECCIÓN MÁXIMA
- LEER DIRECCIÓN NATIVA MAX
Los sistemas operativos utilizan el comando IDENTIFY DEVICE para averiguar el espacio direccionable de un disco duro. El comando IDENTIFY DEVICE consulta un registro específico del controlador IDE para determinar el tamaño de la unidad.
Este registro, sin embargo, puede modificarse mediante el comando SET MAX ADDRESS ATA. Si el valor del registro es inferior al tamaño real del disco duro, se crea un área protegida por el sistema operativo. Esta área está protegida porque el sistema operativo solo trabajará con el valor del registro que devuelve el comando IDENTIFY DEVICE y, por lo tanto, normalmente no podrá acceder a las partes del disco que se encuentran dentro del área protegida por el sistema operativo.
El HPA solo es útil si otro software o firmware (por ejemplo, BIOS o UEFI ) puede utilizarlo. El software y el firmware que pueden utilizar el HPA se denominan "compatibles con HPA". El comando ATA que utilizan estas entidades se llama READ NATIVE MAX ADDRESS. Este comando accede a un registro que contiene el tamaño real del disco duro. Para utilizar el área, el programa compatible con HPA modifica el valor del registro leído por IDENTIFY DEVICE al valor del registro leído por READ NATIVE MAX ADDRESS. Una vez completadas sus operaciones, el registro leído por IDENTIFY DEVICE vuelve a su valor original ficticio.
Usar
- HPA can be used by various booting and diagnostic utilities, normally in conjunction with the BIOS. An example of this implementation is the PhoenixFirstBIOS, which uses Boot Engineering Extension Record (BEER) and Protected Area Run Time Interface Extension Services (PARTIES).[2]
- HPA can also be used to store data that is deemed illegal and is thus of interest to government and police computer forensics teams.[3]
- Some rootkits hide in the HPA to avoid being detected by anti-rootkit and antivirus software.[2]
- Some NSA exploits use the HPA for application persistence.[4]
Identification
Identification of HPA on a hard drive can be achieved by a number of tools and methods:
- ATATool by Data Synergy
- EnCase by Guidance Software
- Forensic Toolkit by Access Data
- hdparm by Mark Lord
- The Sleuth Kit (free, open software) by Brian Carrier (HPA identification is currently only supported on Linux.)
See also
- Device Configuration Overlay (DCO)
- GUID Partition Table (GPT)
- Master boot record (MBR)
References
- ↑"Host Protected Areas"(PDF). Utica.edu.
- 12Blunden, Bill (2009). The rootkit arsenal: escape and evasion in the dark corners of the system. Plano, Texas: Wordware Pub. p. 538. ISBN 978-1-59822-061-2. OCLC 297145864.
- ↑Nelson, Bill; Phillips, Amelia; Steuart, Christopher (2010). Guide to computer forensics and investigations (4th ed.). Boston: Course Technology, Cengage Learning. p. 334. ISBN 978-1-435-49883-9.
- ↑"SWAP: NSA Exploit of the Day - Schneier on Security". 6 February 2014.
External links
- The Sleuth Kit
- International Journal of Digital Evidence
- Wiki Web For ThinkPad Users
- AT Attachment
- Computer forensics
- Computer security procedures
- Information technology audit