Run-DMA

Run-DMA
复制标题

DOI:
--
复制
发表时间:
2015-08
期刊:
--
影响因子:
--
通讯作者:
M. Rushanan;Stephen Checkoway
M. Rushanan;Stephen Checkoway
中科院分区:
其他
文献类型:
--
作者:
M. Rushanan;Stephen Checkoway

文献摘要

被引文献

相似文献

将数据从设备存储到主存中是一项计算量很小但时间密集的任务。为了释放CPU来执行更有趣的工作,计算机使用直接存储器访问(DMA)引擎-一种专用硬件-将数据传输到主存储器或从主存储器传输数据。我们表明,这种内存传输链在一起的能力,所提供的商品硬件,是足以执行任意计算。此外,当硬件外围设备可以通过内存映射I/O访问时,它们可以被DMA程序访问。为了演示恶意行为,我们构建了一个概念验证DMA rootkit,它修改内存中的内核对象,以执行目标进程的权限提升。
Copying data from devices into main memory is a computationally-trivial, yet time-intensive, task. In order to free the CPU to perform more interesting work, computers use direct memory access (DMA) engines -- a special-purpose piece of hardware -- to transfer data into and out of main memory. We show that the ability to chain together such memory transfers, as provided by commodity hardware, is sufficient to perform arbitrary computation. Further, when hardware peripherals can be accessed via memory-mapped I/O, they are accessible to "DMA programs." To demonstrate malicious behavior, we build a proof-of-concept DMA rootkit that modifies kernel objects in memory to perform privilege escalation for target processes.