Bypassing IOMMU Protection against I/O Attacks
Bypassing IOMMU Protection against I/O Attacks
复制标题
绕过 IOMMU 针对 I/O 攻击的保护
DOI:
10.1109/ladc.2016.31
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
M. Kaâniche
中科院分区:
文献类型:
--
作者:
Benoît Morgan;E. Alata;V. Nicomette;M. Kaâniche
Attacks targeting computer systems become more and more complex and various. Some of them, so-called I/O attacks, are performed by malicious peripherals that make read or write accesses to DRAM memory or to memory embedded in other peripherals, through DMA (Direct Memory Access) requests. Some protection mechanisms to face these attacks exist and have been implemented for several years now in modern architectures. A typical example is the IOMMU proposed by Intel. However, such mechanisms are not necessarily properly configured and used by the firmware and the operating system. This experimental paper describes a design weakness that we discovered in the configuration of an IOMMU by the Intel IOMMU Linux driver and a possible exploitation scenario that would allow a malicious peripheral to bypass the underlying protection mechanism. The exploitation scenario is implemented with a PCI Express peripheral FPGA, based on Intel specifications and Linux source code analysis.