Fabrication Attacks: Zero-Overhead Malicious Modifications Enabling Modern Microprocessor Privilege Escalation

Fabrication Attacks: Zero-Overhead Malicious Modifications Enabling Modern Microprocessor Privilege Escalation
复制标题

伪造攻击:零开销恶意修改可实现现代微处理器权限升级

DOI:
--
复制
发表时间:
2014
影响因子:
5.9
通讯作者:
Michail Maniatakos
Michail Maniatakos
中科院分区:
计算机科学2区
文献类型:
--
作者:
N. G. Tsoutsos;Michail Maniatakos

文献摘要

被引文献

相似文献

通用微处理器和嵌入式微处理器的广泛部署强调了防御网络攻击的必要性。然而,由于全球化的供应链,有几个阶段可以恶意修改处理器。最有希望的阶段,也是最难注入硬件木马的阶段,是制造阶段。由于现代微处理器芯片的特点是非常密集,十亿晶体管设计,这种攻击必须非常小心。在本文中,我们展示了零开销恶意修改高性能和嵌入式微处理器。这些硬件特洛伊木马通过执行指令流来激活必要的条件以使修改出现,从而实现权限提升。然而,最小的足迹是以一个小的攻击机会窗口为代价的。实验结果表明,恶意用户可以在几百万个时钟周期内获得升级的权限。此外,在正常操作期间没有报告系统崩溃,使修改对最终用户透明。
The wide deployment of general purpose and embedded microprocessors has emphasized the need for defenses against cyber-attacks. Due to the globalized supply chain, however, there are several stages where a processor can be maliciously modified. The most promising stage, and the hardest during which to inject the hardware trojan, is the fabrication stage. As modern microprocessor chips are characterized by very dense, billion-transistor designs, such attacks must be very carefully crafted. In this paper, we demonstrate zero overhead malicious modifications on both high-performance and embedded microprocessors. These hardware trojans enable privilege escalation through execution of an instruction stream that excites the necessary conditions to make the modification appear. The minimal footprint, however, comes at the cost of a small window of attack opportunities. Experimental results show that malicious users can gain escalated privileges within a few million clock cycles. In addition, no system crashes were reported during normal operation, rendering the modifications transparent to the end user.