Revisiting ARM Debugging Features: Nailgun and its Defense

Revisiting ARM Debugging Features: Nailgun and its Defense
复制标题

DOI:
10.1109/tdsc.2021.3139840
复制
发表时间:
2023-01
影响因子:
7.3
通讯作者:
Zhenyu Ning;Chenxu Wang;Yin-Shang Chen;Fengwei Zhang;Jiannong Cao
Zhenyu Ning;Chenxu Wang;Yin-Shang Chen;Fengwei Zhang;Jiannong Cao
中科院分区:
计算机科学2区
文献类型:
--
作者:
Zhenyu Ning;Chenxu Wang;Yin-Shang Chen;Fengwei Zhang;Jiannong Cao

文献摘要

相似文献

如今的处理器都配备了调试功能,以方便程序分析。具体来说,ARM调试架构中包含了一系列CoreSight组件和调试寄存器来辅助系统调试,并设计了一组调试认证信号来限制这些组件和寄存器的使用。同时,调试功能的安全性未得到充分检查,因为在传统的调试模型中,通常需要物理访问才能使用这些功能。然而,ARM引入了一种新的调试模型,自ARMv7以来,不需要物理访问,这加剧了我们对调试功能安全性的担忧。在本文中,我们对ARM调试功能进行了全面的安全分析,并总结了安全含义。为了理解这些影响的影响,我们还调查了不同产品领域中一系列具有ARM-A架构的平台(即,开发板、IoT设备、云服务器和移动的设备)。我们认为,分析和调查揭示了一个新的攻击面,普遍存在于平台与ARM-A架构。为了验证我们的担忧,我们进一步制作了Nailgun攻击,它可以获取敏感信息(例如,AES加密密钥和指纹图像),并通过滥用调试功能从低权限模式实现高权限模式下的任意有效载荷执行。这种攻击不依赖于软件漏洞,我们的实验表明,我们调查的几乎所有平台都容易受到攻击。我们的分析还表明,ARM-R和ARM-M平台可能会遇到同样的问题。为了防御攻击,我们从ARM生态系统的不同角度讨论了潜在的缓解措施。最后,给出了一个基于ARM虚拟化技术的实用防御机制,评估结果表明,该防御机制能够在性能损失很小的情况下有效地防御Nailgun攻击。
Processors nowadays are consistently equipped with debugging features to facilitate program analysis. Specifically, the ARM debugging architecture involves a series of CoreSight components and debug registers to aid the system debugging, and a group of debug authentication signals are designed to restrict the usage of these components and registers. Meanwhile, the security of the debugging features is under-examined since it normally requires physical access to use these features in the traditional debugging model. However, ARM introduces a new debugging model that requires no physical access since ARMv7, which exacerbates our concern on the security of the debugging features. In this article, we perform a comprehensive security analysis of the ARM debugging features and summarize the security implications. To understand the impact of the implications, we also investigate a series of platforms with ARM-A architecture in different product domains (i.e., development boards, IoT devices, cloud servers, and mobile devices). We consider that the analysis and investigation expose a new attacking surface that universally exists in platforms with ARM-A architecture. To verify our concern, we further craft Nailgun attack, which obtains sensitive information (e.g., AES encryption key and fingerprint image) and achieves arbitrary payload execution in a high-privilege mode from a low-privilege mode via misusing the debugging features. This attack does not rely on software bugs, and our experiments show that almost all the platforms we investigated are vulnerable to the attack. Our analysis also indicates that ARM-R and ARM-M platforms may suffer from the same issue. To defend against the attack, we discuss potential mitigations from different perspectives in the ARM ecosystem. Finally, a practical defense mechanism based on ARM virtualization technology is presented, and the evaluation result shows that our defense can prevent Nailgun with a negligible performance penalty.