Return-to-Non-Secure Vulnerabilities on ARM Cortex-M TrustZone: Attack and Defense

Return-to-Non-Secure Vulnerabilities on ARM Cortex-M TrustZone: Attack and Defense
复制标题

DOI:
10.1109/dac56929.2023.10247972
复制
发表时间:
2023-07
期刊:
2023 60th ACM/IEEE Design Automation Conference (DAC)
影响因子:
--
通讯作者:
Zheyuan Ma;Xi Tan;Lukasz Ziarek;Ning Zhang;Hongxin Hu;Ziming Zhao
Zheyuan Ma;Xi Tan;Lukasz Ziarek;Ning Zhang;Hongxin Hu;Ziming Zhao
中科院分区:
其他
文献类型:
--
作者:
Zheyuan Ma;Xi Tan;Lukasz Ziarek;Ning Zhang;Hongxin Hu;Ziming Zhao

文献摘要

相似文献

ARM Cortex - M是为嵌入式和物联网(IoT)应用而设计的最受欢迎的微控制器架构之一。为了促进高效执行,它具有一些独特的硬件优化。特别是,Cortex - M TrustZone具有一种快速状态切换机制,该机制允许从安全状态程序直接向非安全状态用户空间程序进行控制流转移。在本文中,我们通过引入一种新的利用技术,即返回非安全状态(ret2ns),展示了这种快速状态切换机制如何在非安全状态下被利用来以提升的权限执行任意代码。我们通过实验证实了在两个Cortex - M硬件系统上四种ret2ns攻击变体的可行性。为了防御ret2ns攻击,我们设计了两种地址净化机制,其性能开销可忽略不计。
ARM Cortex-M is one of the most popular microcontroller architectures designed for embedded and Internet of Things (IoT) applications. To facilitate efficient execution, it has some unique hardware optimization. In particular, Cortex-M TrustZone has a fast state switch mechanism that allows direct control-flow transfer from the secure state program to the non-secure state userspace program. In this paper, we demonstrate how this fast state switch mechanism can be exploited for arbitrary code execution with escalated privilege in the non-secure state by introducing a new exploitation technique, namely return-to-non-secure (ret2ns). We experimentally confirmed the feasibility of four variants of ret2ns attacks on two Cortex-M hardware systems. To defend against ret2ns attacks, we design two address sanitizing mechanisms that have negligible performance overhead.