The potential risk from source code,extension modules of Unified Extensible Firmware Interface(UEFI) and network is pointed out.The shortcomings of existing BIOS and UEFI malicious code detection methods are analyzed,UEFI attack tree and threat level are defined,a UEFI threats model database and malicious behavior character database are built together as an attack tree model with dynamic expansion,weighted minimal attack tree algorithm is designed for UEFI malicious behavior detection.The experimental resul...